Failproof AI
A CLI with policies that intercepts dangerous AI agent commands like rm -rf, force push or reading .env before they run
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- It intercepts and can block tool calls across all connected agents
- Some features tie into a cloud dashboard and the Python SDK
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/failproof-aiDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
npm install -g failproofaiInstall and set up: npm install -g failproofai, then failproofai config to wire up agents, and failproofai policies add FailproofAI/policies for the baseline policy pack.
Other ways from the author
npm install -g failproofai
failproofai config
failproofai policies add FailproofAI/policies
failproofaiThe last command opens the dashboard at localhost:8020.
This is third-party code. Review the repository files before installing.
What it does
Failproof hooks into agent harnesses, including Claude Code, Codex, Cursor Agent CLI, OpenCode and GitHub Copilot CLI, and intercepts every tool call before it runs. It ships with 39 built-in policies: blocking reads of secret files, recursive deletion, sudo, force pushes and direct pushes to the main branch, plus warnings for repeated calls and dangerous SQL. Custom policies are JS files dropped into .failproofai/policies and picked up automatically; a local dashboard at localhost:8020 shows the run history.
Who it is for. For developers and devops engineers who give AI agents terminal access and want a safety net against destructive commands.
Good fit when
- The agent works on a production repo or infrastructure and needs a guard before dangerous commands
- The team wants a shared policy set applied the same way for everyone via a committed .failproofai folder
- You need one run history across agents for incident review
Not a fit when
- The agent runs in a disposable isolated sandbox with nothing to protect
- The harness in use is not among the twelve supported ones
Example request
Set up failproofai for Claude Code and enable the policy blocking force push and rm -rfLimitations
Blocking a tool call before it runs is guaranteed on all twelve harnesses, while end-of-turn gates work on only eight of them. Custom agents outside the list connect via a separate Python SDK and need a hook in their own runtime to be intercepted.
How to disable. Remove the package with npm uninstall -g failproofai. The base block-failproofai-commands policy cannot be disabled while the package is installed; that is intentional.
Security check
- It intercepts and can block tool calls across all connected agents
- Some features tie into a cloud dashboard and the Python SDK
README in short
The README describes failproofai as observability and enforcement across twelve AI agent harnesses: ten coding CLIs and two chat gateways. It highlights one policy API and one session history across all harnesses, while blocking capability varies by harness. It lists built-in policies like block-rm-rf, block-sudo, block-force-push and warn-destructive-sql, and shows a custom-policy example via a JS deny/allow function.
FAQ
What happens right after install?
The hooks are wired up, but no policy is selected besides the non-disableable block on failproofai's own commands. Policies must be added with a separate command.
How do I add a custom policy?
Drop a JS file into .failproofai/policies; it is picked up automatically and ships with the repo on commit.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents