Rampart — AI skill for Claude Code
Open-source firewall for AI agents.
How to install Rampart
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open peg/rampart and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Rampart does
Open-source firewall for AI agents. Policy engine that audits and controls what OpenClaw, Claude Code, Cursor, Codex, and any AI tool can do on your machine.
Alternatives in AI
- Invisible Dots — Open-source, self-hosted alternative to OpenAI Dots, Meta Muse, Grok Bot, Manus Cue and Claude Cowork 31.8k ★
- SEO Geo Claude Skills — 20 SEO & GEO skills for Claude Code, Cursor, Codex, and 35+ AI agents 888 ★
- Iai Personal Memory Engine — A cyber brain for your AI 866 ★
README
Rampart
**Open-source policy and approval control for AI agents.**
[](https://go.dev) [](LICENSE) [](https://github.com/peg/rampart/actions/workflows/ci.yml) [](https://github.com/peg/rampart/releases) [](https://docs.rampart.sh)
[Install](#install) · [How it works](#how-it-works) · [Integrations](#integrations) · [Policies](#a-policy-you-can-read) · [Documentation](https://docs.rampart.sh)
AI agents can edit files, run commands, call APIs, and ship code at machine speed. Their permission systems usually ask a different question: **can this tool run?**
Rampart asks: **should this action run?**
It sits at supported hooks, plugins, proxies, and process boundaries; evaluates the action against local policy; and returns `allow`, `ask`, or `deny` before the host executes it. Decisions are visible, approvals stay human-owned, and the result becomes part of a hash-chained audit trail.
Agent proposes an action
│
▼
┌─────────────┐
│ Rampart │ policy · approval · audit
└──────┬──────┘
│
allow / ask / deny
│
▼
Host executes — or does not
Rampart is a security boundary, **not a sandbox**. It sees actions exposed by the configured integration; it does not see arbitrary syscalls or network traffic inside a process you already allowed. Start with the [threat model](docs/THREAT-MODEL.md) when deciding where to rely on it.
Install
brew install peg/tap/rampart
rampart protect
Related Skills
Lunavect
Claude Code & Codex status bar for macOS. Track AI coding sessions, usage limits and activity with native menu
Skillnote
The open-source skill registry for AI coding agents. Create, manage, and distribute SKILL.md files across Open
Scopebond
Scopebond is an open-source checkpoint for AI coding agents (Claude Code, Cursor, MCP, GitHub) that blocks out
Effortlane
Effortlane: open-source model and reasoning-effort routing for coding agents. Native Codex auth, Shadow evalua
Sunglasses
Open source input firewall for AI agents, beta. A local scanner checks text, code, PDFs, images, QR codes, aud
Vibestrate
Open-source supervised flow for AI coding. Run Claude Code, Codex, Gemini, Aider or local models as one crew,
Related Agents
Privacy Policy
Last updated: 2026-02-28 nWave is an open-source AI workflow framework that runs inside Claude Code and stores
Claudable
by Ethan Park - Claudable is an open-source web builder that leverages local CLI agents, such as Claude Code a
Audit Legal
Use this agent to conduct a legal and compliance audit (Head of Legal perspective): missing legal documents, p