Trustgate — Security skill for Claude Code
Deterministic policy enforcement and a tamper-evident audit log for AI agents.
How to install Trustgate
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open Rushil242/trustgate and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Trustgate does
Deterministic policy enforcement and a tamper-evident audit log for AI agents. Decides what your agent may actually do — and proves what it did. Works with Claude Code.
Alternatives in Security
- OpenTag — Open-source, channel-native agent gateway for Slack 499 ★
- Node9 Proxy — The Execution Security Layer for the Agentic Era 209 ★
- Release Audit — Use right before cutting a release — it spawns ONE fresh sibling session via CCC that audits only the JUDGMENT 130 ★
README
TrustGate
Your AI agent has a shell, your prod database, and your payment API.
TrustGate decides what it's actually allowed to do, then hands you the proof.
[](https://trustgate.rushil-cv26.workers.dev) [](https://github.com/Rushil242/trustgate/actions/workflows/ci.yml) [](LICENSE) [](https://www.python.org/downloads/) [](tests/) [](redteam/) [](redteam/)
**Deterministic policy enforcement, a tamper-evident audit log, and a one-command
evidence pack for the day a customer's security team asks what your agent did.**
Works with Claude Code today. Same engine governs voice agents.
**[See an attack get stopped, live →](https://trustgate.rushil-cv26.workers.dev)**
A support agent, a prompt injection, and the same call run twice: once with a gate in front of the tool, once without.
[Live demo](https://trustgate.rushil-cv26.workers.dev) · [Quick start](#quick-start) · [Evidence pack](#evidence-pack) · [TrustGate Cloud](#trustgate-cloud) · [How it works](#how-it-works) · [Benchmarks](#benchmarks) · [Threat model](docs/THREAT_MODEL.md) · [Limitations](#what-this-does-not-do)
Watch the 77-second overview
https://github.com/user-attachments/assets/e208a8e8-d030-4069-bbc8-101ef33abf80
What TrustGate does, how the approval inbox works, how the cloud catches a rewritten log, and what the evidence pack looks like. The people and numbers in it are
Related Skills
Sanctuary Framework
Open-source security for AI agents: kernel-enforced egress control on macOS and Linux, keys only the operator
Agent Overwatch
A deterministic guard for AI coding agents — checks each tool call before it runs (allow/ask/deny) and blocks
Exploit Chain
Chain multiple findings into a single multi-step exploit. Produces a Foundry test that proves the chain works.
Email Deliverability
Email deliverability audit — why your mail lands in spam or bounces: SPF/DKIM/DMARC auth & alignment (deeper t
Memnox
See what your AI coding agents can actually do on your machine, and put the dangerous actions behind ask or de
Skills Gateway
Governed, identity-aware server for Agent Skills (SKILL.md): OIDC + default-deny policy per fetch, immutable d
Related Agents
Weavie Tester
Proves a change actually works by running the real Weavie app, exercising the scenarios a PR should cover, and
Classifier
Decides what an ambiguous document actually is, when the deterministic classifier could not. Use for documents
Ava Feature Steward
Owns two things. First, feature integrity — that every feature the product markets actually works end-to-end f