gate.cat blocks dangerous AI agent shell commands before execution, not after
A new open-source tool called gate.cat intercepts and vetoes harmful shell commands — such as rm -rf, DROP TABLE, and secret exfiltration attempts — before AI coding agents can execute them. Unlike most guardrails that log damage after it occurs, gate.cat uses deterministic string and path analysis with no AI model in its veto path, making it resistant to prompt injection attacks. The tool was tested against over one million real agent commands from five public datasets, recording zero missed dangerous commands after adjudication. It integrates with popular AI coding tools including Claude Code, Codex, and aider, and can also function as a local proxy for OpenAI-compatible APIs. Released under the Apache-2.0 license with a zero-dependency core, gate.cat is free to use and its developers openly publish known bypasses and false positives rather than concealing them.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.
Discussion (0)
Log in to join the discussion and vote.
Log in