writ-agent

Provio — AI skill for Claude Code

AI community

A safety floor your AI agents can't get under: one policy for Claude Code, Codex, Gemini CLI, Cursor, Windsurf and MCP, judged by what each call will run, backstopped by the kernel, with a signed, tam.

How to install Provio

This entry records only its repository, not the path inside it, so there is no exact command to give. Open writ-agent/provio and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Provio does

A safety floor your AI agents can't get under: one policy for Claude Code, Codex, Gemini CLI, Cursor, Windsurf and MCP, judged by what each call will run, backstopped by the kernel, with a signed, tamper-evident ledger.

Alternatives in AI

  • Codeseek — Rust-powered code intelligence CLI for AI coding agents 764 ★
  • Metaharness — 🛠️ The meta-harness for AI agents — scaffold your own focused, branded agent harness with its own npx CLI, MC 616 ★
  • Skilldock — SkillDock is an AI skill manager and skill management desktop app for Claude Code, Cursor, Codex, Windsurf, Ge 490 ★

README

provio: a safety floor your AI agents can't get under. A tool call passes a policy gate (allow, deny, ask, redact) and is recorded in a hash-chained ledger.

Your agent asks. Your policy decides. The ledger remembers.

[![ci](https://github.com/writ-agent/provio/actions/workflows/ci.yml/badge.svg)](https://github.com/writ-agent/provio/actions/workflows/ci.yml) [![license](https://img.shields.io/badge/license-Apache--2.0-1f6feb)](LICENSE) [![rust](https://img.shields.io/badge/rust-stable-b7410e)](rust-toolchain.toml) [![status](https://img.shields.io/badge/status-pre--release-d29922)](#status) [![PyPI](https://img.shields.io/pypi/v/provio-sdk?label=pypi%20provio-sdk&color=4ec9a5)](https://pypi.org/project/provio-sdk/) [![npm](https://img.shields.io/npm/v/provio-sdk?label=npm%20provio-sdk&color=4ec9a5)](https://www.npmjs.com/package/provio-sdk)

[Website](https://getprovio.vercel.app) · [**Playground**](https://getprovio.vercel.app/playground.html) · [Docs](docs/README.md) · [Compare](docs/comparison.md) · [Threat model](docs/THREAT_MODEL.md) · [Changelog](CHANGELOG.md)

**Watch it catch what command checks miss.** [claude-code#88462](https://github.com/anthropics/claude-code/issues/88462): an agent's cleanup script ran `rm -rf "$HOME"`. provio refuses the script when it is written, refuses `bash cleanup.sh` by reading the script, and when the delete is obfuscated past every rule, the kernel boundary refuses it anyway. Reproduce it: [examples/incident-88462](examples/incident-88462/).

claude-code#88462 replayed: provio denies writing cleanup.sh because line 3 runs trap rm -rf $HOME; denies bash cleanup.sh by reading the script; the base64-obfuscated delete is allowed by the rules but the kernel write boundary refuses it with Permission denied and the home directory stays intact

"provio