
a guard that blocks catastrophic agent actions
expensive mistakes stop here
a guard that blocks catastrophic agent actions
nahguard.ai • what it blocks • how it compares • how it decides • install • extend • threat model
claude code · codex · cursor · pi · + 11 more
nah is a guard that sits in your coding agent's hook path and reads tool calls before they run. It blocks the calls it can prove are disasters and never approves anything: everything else goes to your runtime's normal permissions.
nah is just one Rust binary: a verdict is deterministic and needs no LLM. Extensions are just programs. Point your agent to nah's docs and ask it to build a custom nah guard.
47 guards, 29 on by default, covering seven classes of disaster: execution hijacks, secret theft, filesystem destruction, git disasters, infrastructure, storage, and backup teardown, package-registry operations, and host power and service-stop actions.
| Guard | Blocks |
|---|---|
exec-remote | Execution of a payload visibly obtained from the network. |
exec-decoded | Execution reached from a visible decode stage. |
exec-obfuscated | Encoded, pattern-selected, or unresolved execution. |
exec-network-shell | Shells attached to a network connection, including netcat, socat, and shell redirection. |
secrets-env | Reads of .env files and sensitive basenames, including contents from Git history, plus direct output of catalogued credential environment variables. |
secrets-credentials | Reads or writes of private-key and credential-store paths, including content reads from Git history; deleting or moving away private keys; metadata or value reads of the macOS keychain. |
secrets-exfil | A visible flow from a sensitive source to a network stage. |
secrets-store-delete | Remaining reviewed secret-store deletion with recoverable or context-dependent semantics. Off by default. |
secrets-store-destroy | Proven permanent secret-store destruction: Vault version/metadata/engine removal, AWS force and SSM deletion, Google whole-secret deletion, Azure purge, Doppler project/configuration deletion, and 1Password vault deletion. |
secrets-store-read | Reviewed value reads across common secret-manager CLIs. |
fs-system-tree | Deletion, proven root-entry relocation, or recursive permission changes selecting the filesystem root or a system tree. |
fs-home | Deletion or recursive permission changes selecting the home root. |
fs-outside-workspace-delete | Recursive deletion outside the active project, except under reviewed temporary roots. Off by default. |
fs-permission-weaken | chmod modes that provably grant world-write or setuid/setgid permission. Off by default. |
fs-project-root | Concrete Project-scoped recursive deletion or known recursive permission changes selecting the exact project root or its exact *, .*, or {*,.*} root-wide patterns. find -delete without an explicit start path has no modeled target. |
fs-raw-device | Visible writes to, and whole-device destruction of, raw storage devices, and the sysrq trigger. |
fs-volume-destroy | Definite logical-volume, storage-pool, and live ZFS dataset destruction. |
fs-forkbomb | Structurally recognized shell fork-bomb patterns. |
fs-auth-identity | Modification or deletion of reviewed host authentication, identity, and privilege-policy files, including recursive deletion of their parent directories. |
fs-shell-profile | Changes to reviewed user shell profile paths. Off by default. |
fs-startup-management | Reviewed persistent systemctl, launchctl, and crontab management commands. Off by default. |
fs-startup-persistence | Changes to reviewed service, schedule, login, autostart, and loader startup paths. |
git-clean-force | An effective forced Git clean selecting the project root. |
git-force-push | Git force pushes without lease protection and leased force pushes explicitly targeting main or master. |
git-hard-reset | Git hard resets. |
git-history-rewrite | Selected unforced Git history rewrites, including rebases, filtering, recovery expiry, aggressive or pruning garbage collection, and leased force pushes, including explicit static refspecs targeting main or master. Off by default. |
git-rewrite-force | History rewriting that explicitly bypasses safety or backup checks. |
git-metadata | Destructive writes or deletion selecting durable Git history metadata. |
git-path-discard | Definite named-path checkout, restore, and same-path git show overwrites. Off by default. |
git-protected-push | Pushes whose explicit static refspec targets main or master. Bare pushes remain outside this guard. Off by default. |
git-recovery-destroy | Clearing the full stash collection or immediate repository-wide destruction of Git recovery history. |
git-ref-delete | Reviewed local and remote ref, stash entry, worktree, and submodule worktree deletion. Off by default. |
git-remote-repo-delete | Exact GitHub and GitLab whole-repository deletion through their CLIs and REST routes. |
git-remote-resource-delete | Statically targeted GitHub and GitLab hosted-resource deletion through reviewed CLI commands and REST routes. Off by default. |
git-worktree-discard | Project-wide checkout or restore, proven forced branch changes, and forced worktree removal or submodule deinitialization. |
db-destroy | Dropping, truncating, flushing, resetting, or overwriting live database data, and deleting managed databases. Off by default. |
infra-container-reset | Podman commands that reset the complete local or selected runtime state. |
infra-container-volume-delete | Broad unused-volume cleanup through reviewed Docker and Podman prune commands, and Compose down -v/rm -v volume removal. Off by default. |
infra-iac-destroy | Fully visible Terraform, OpenTofu, and Pulumi whole-stack destruction. Off by default. |
infra-k8s-delete | Static namespace, reviewed cluster-resource, and bulk reviewed namespaced-resource deletion through kubectl. Off by default. |
storage-backup-destroy | Complete backup-repository or all-backup deletion through reviewed Borg, Restic, and Velero commands. |
storage-recursive-delete | Broad remote deletion and destination-deleting synchronization through reviewed cloud and sync CLIs. Off by default. |
storage-snapshot-delete | Reviewed snapshot, archive, volume, and retention deletion. Off by default. |
registry-publish | Reviewed package publication commands. Off by default. |
registry-unpublish | Reviewed package unpublish, irreversible RubyGems yank, and published-name owner changes. |
sys-power | Fully visible local host shutdown, reboot, halt, and suspend actions. |
sys-service-stop | Reviewed service shutdown, target isolation, Podman stop-all or kill-all, and docker stop or docker kill of every listed container. Off by default. |
Run nah docs guards to see the full built-in catalog, with each guard's
exact scope and three tested examples, plus current custom guard status.
nah is the most complete coding agent guard, and stacks well with Auto modes