Rushil242

Trustgate — Security skill for Claude Code

Security community

Deterministic policy enforcement and a tamper-evident audit log for AI agents.

How to install Trustgate

This entry records only its repository, not the path inside it, so there is no exact command to give. Open Rushil242/trustgate and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Trustgate does

Deterministic policy enforcement and a tamper-evident audit log for AI agents. Decides what your agent may actually do — and proves what it did. Works with Claude Code.

Alternatives in Security

  • OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
  • Node9 Proxy — The Execution Security Layer for the Agentic Era 209 ★
  • Release Audit — Use right before cutting a release — it spawns ONE fresh sibling session via CCC that audits only the JUDGMENT 130 ★

README

TrustGate

Your AI agent has a shell, your prod database, and your payment API.
TrustGate decides what it's actually allowed to do, then hands you the proof.

[![Live demo](https://img.shields.io/badge/live%20demo-trustgate.rushil--cv26.workers.dev-16181c)](https://trustgate.rushil-cv26.workers.dev) [![CI](https://github.com/Rushil242/trustgate/actions/workflows/ci.yml/badge.svg)](https://github.com/Rushil242/trustgate/actions/workflows/ci.yml) [![License: MIT](https://img.shields.io/badge/license-MIT-blue.svg)](LICENSE) [![Python 3.11+](https://img.shields.io/badge/python-3.11%2B-blue.svg)](https://www.python.org/downloads/) [![Tests](https://img.shields.io/badge/tests-389%20passing-brightgreen.svg)](tests/) [![Attacks blocked](https://img.shields.io/badge/red--team-41%2F41%20handled-brightgreen.svg)](redteam/) [![False positives](https://img.shields.io/badge/false%20positives-0%2F24-brightgreen.svg)](redteam/)

**Deterministic policy enforcement, a tamper-evident audit log, and a one-command evidence pack for the day a customer's security team asks what your agent did.**
Works with Claude Code today. Same engine governs voice agents.

**[See an attack get stopped, live →](https://trustgate.rushil-cv26.workers.dev)**
A support agent, a prompt injection, and the same call run twice: once with a gate in front of the tool, once without.

[Live demo](https://trustgate.rushil-cv26.workers.dev) · [Quick start](#quick-start) · [Evidence pack](#evidence-pack) · [TrustGate Cloud](#trustgate-cloud) · [How it works](#how-it-works) · [Benchmarks](#benchmarks) · [Threat model](docs/THREAT_MODEL.md) · [Limitations](#what-this-does-not-do)

Watch the 77-second overview

https://github.com/user-attachments/assets/e208a8e8-d030-4069-bbc8-101ef33abf80

What TrustGate does, how the approval inbox works, how the cloud catches a rewritten log, and what the evidence pack looks like. The people and numbers in it are