Auto-Guard for Coding Agent Tool Calls
这是 Roshan Chandna 公开的项目资料。本站按原始来源展示项目信息,用中文说明适用场景和阅读边界;项目名、源帖与代码保持原样,便于逐项核对。
这条案例记录了什么
安全与权限门禁、编码 Agent
提供风险或支持程度的判断信号;执行权限仍归应用规则。
社区公开项目或作者演示
原始来源:Original X post by @roshanchandna and public project repository。作者自述,本站未独立复现。
Roshan Chandna
记录日期:2026-09-19。日期与身份应以原始资料为准。
原始演示视频
视频来自此案例记录的原始媒体;播放内容和作者声明不等于本站复现。
怎样核对这个项目
- 先打开原始来源,确认作者、日期与 Jev 在项目中的具体用途。
- 如果提供仓库,再检查代码、运行要求和许可证;仓库存在不代表本站已经运行成功。
- 对速度、成本、准确率和规模数字,查看原文的任务、环境和计算口径。
- 高风险动作是否单独授权。
- 误判后的阻断和恢复。
- 规则是否由程序执行。
- 仓库状态和测试是否完整。
原始文字与技术细节
以下内容保留原语言,供核对事实。中文页的场景说明是阅读提示,不是逐句翻译或实测结论。
展开英文项目摘要与原帖
项目摘要
Roshan Chandna's open-source Auto-Guard sends proposed coding-agent tool calls and the user request to Jev; code maps typed risk, scope and sensitivity answers into allow, human approval or block.
来源原文
Your coding agent is one bad instruction away from running rm -rf ~/.aws. I built Auto-Guard with Jev (@typesafeai) to check every tool call before it runs. Here it stops a credentials delete but lets the build cleanup through. It's open source! Install in the replies 👇 https://t.co/lgcdoEZopv
原记录的限制
- Author-run holdout tests are small and not independently reproduced here.
- The repository states Auto-Guard is a filter, not a sandbox, and can miss a risky action.
- The guard cannot control a command after its pre-execution check.