Sandbox
@FailproofAI/failproofai

Policy enforcement and traces for agent harnesses

FailproofAI adds tracing, audits, and policy enforcement around agent harnesses. It watches runs from supported CLIs and gateways, records model and tool activity, and can deny dangerous actions before they execute.

2,690 stars455 forksMDXUpdated 6d ago
Who it's for

Builders who want their agent runs to be recorded, reviewed, and blocked when they cross policy lines.

What it delivers

You can keep agent work visible and stop risky tool calls before they happen.

What it does

Supported harness hooks

Connects to Claude Code, Codex, Cursor, Copilot CLI, OpenCode, Pi, Hermes, OpenClaw, Factory Droid, Devin CLI, Antigravity CLI, and Goose.

Built-in policy enforcement

Ships with built-in rules for things like secret reads, sudo, destructive SQL, force pushes, and risky infrastructure changes.

Custom policies

Loads policy files from `.failproofai/policies/` and lets you return `allow()`, `deny()`, or `instruct()`.

Local dashboard

Serves a dashboard on `localhost:8020` that reads run history from your machine without an account.

Audits and traces

Provides session traces, execution graphs, and offline audits that surface repeated failure patterns.

How to get it

  1. 1Run
    npm install -g failproofai
    failproofai policies --install   # or just run `failproofai` and accept the first-run prompt
    failproofai

README

failproof ai

FailproofAI%2Ffailproofai | Trendshift

npm CI Supply Chain Discord Reddit Docs License

Translations: 简体中文 · 日本語 · 한국어 · Español · Português · Deutsch · Français · Русский · हिन्दी · Türkçe · Tiếng Việt · Italiano · العربية · עברית

Observability and enforcement for every harness your agents run in. Wherever your agents run, we see it — and we can say no. Failproof hooks 12 agent harnesses — coding CLIs like Claude Code and Codex, chat gateways like Hermes, self-hosted assistants like OpenClaw — capturing every run and blocking dangerous tool calls before they execute. 39 built-in policies. Zero latency. Runs locally.

Failproof AI in action


Supported harnesses

Twelve harnesses in two classes — ten coding CLIs, and two chat and assistant gateways (Hermes, OpenClaw). Same events, same policies, same session history, whichever one your agent runs in.

Agents that run in none of them report through the Python SDK, which gives you tracing, sessions and audits. Enforcement there needs a hook in your own runtime — talk to us and we'll map it.

Claude Code OpenAI CodexOpenAI Codex GitHub CopilotGitHub Copilot Cursor AgentCursor Agent OpenCodeOpenCode PiPi
HermesHermes OpenClaw Factory DroidFactory Droid Devin CLI Antigravity CLI GooseGoose

Install

npm install -g failproofai
failproofai policies --install   # or just run `failproofai` and accept the first-run prompt
failproofai

39 built-in policies activate immediately. Dashboard at localhost:8020. Disable the first-run prompt with FAILPROOFAI_NO_FIRST_RUN=1.


What it stops

PolicyWhat it blocks
sanitize-api-keysAPI keys leaking into the agent's context
block-env-filesReads of .env and other secret files
warn-repeated-tool-callsThe agent looping on the same call
block-sudoPrivilege escalation
warn-destructive-sqlDROP, TRUNCATE, unbounded DELETE
block-terraform / block-kubectlUnreviewed changes to live infrastructure
block-rm-rfRecursive file deletion
block-force-push / block-push-mastergit push --force, direct pushes to main

The first five apply to any agent that can call a tool. The last three are the developer favourites — coding CLIs are the harness class we cover deepest.

All 39 built-in policies


Your own policies

Drop a file into .failproofai/policies/ — it loads automatically, no flags needed. Commit it and the whole team gets it on next pull.

import { customPolicies, deny, allow } from "failproofai";

customPolicies.add({
  name: "no-production-writes",
  match: { events: ["PreToolUse"] },
  fn: async (ctx) => {
    if (ctx.toolInput?.file_path?.includes("production"))
      return deny("Writes to production paths are blocked.");
    return allow();
  },
});

Three decisions available to every policy:

DecisionEffect
allow()Permit the operation
deny(message)Block it — message goes back to the agent
instruct(message)Let it through, but add context to the agent's next prompt

Custom policies guide


Observability

Enforcement is one half. The other half is seeing what the agent actually did.

Run failproofai with no arguments and it serves a dashboard on localhost:8020 reading the run history already on your machine — no account, no signup, nothing leaving the box. You get the session list, the sequence of model calls, tool calls and hook decisions inside each run, what was blocked and what the policy told the agent, and an offline audit (failproofai audit) that scans your history for risky patterns and suggests policies to stop them.

Local dashboard · Read a trace · Local audit

Failproof AI Observability is the hosted side of the same data model, for teams running agents across a fleet: every run from every harness in one place, an execution graph with parallel sub-agents on their own lanes, p50/p95/p99 latency for models, tools and hooks, per-model cost and context-window tracking, error tracking, SQL over your own traces with shareable dashboards, evaluations scored by your own service, scheduled audits that turn recurring failures into evidence-backed findings, and alerts routed to Slack, email or a signed webhook. Self-hosting in your own cluster is available on the Enterprise plan.

Sessions · Audits · Book a demo


Documentation

Start
QuickstartInstall, connect a harness, see the first run
ConceptsHow the hook system works
Supported harnessesAll 12, and what each one can enforce
Observe
SessionsFollow a run: models, tools, errors, latency
Read a traceWhat the execution graph is telling you
AuditsFind failure patterns across many sessions
Local dashboardlocalhost:8020, no account needed
Enforce
Built-in policiesAll 39 policies with parameters
Custom policiesWrite your own
ConfigurationConfig scopes and merge rules
Instrument your own agent
Python SDKReport runs from an agent with no harness
Policy SDKallow / deny / instruct reference

License

MIT with Commons Clause — free for internal and personal use; commercial resale of failproofai itself requires a separate agreement. See LICENSE for the full text.


Contributing

See CONTRIBUTING.md. New policies, edge cases, and translations all welcome.

Build before you start. Run bun install && bun run build first. This repo runs failproofai's own hooks on itself, and they resolve the failproofai import against the compiled dist/ bundle — without a build you'll hit Cannot find package 'failproofai' hook errors. Rebuild after changing src/. See Build before the in-repo dev hooks will work.


Built with ❤️ by befailproof.ai in SF and Bengaluru.

Files in the repo

Repository payload63 top-level entries
  • __tests__
  • .agents
  • .claude
  • .codex
  • .cursor
  • .devin
  • .factory
  • .failproofai
  • .github
  • .opencode
  • .pi
  • app
  • assets
  • bin
  • components
  • contexts
  • crates
  • docker-hook-sync
  • docs
  • docs-old
  • examples
  • fp-cloud-cli
  • integration-suite
  • lib
  • openclaw-plugin
  • pi-extension
  • public
  • scripts
  • sdk
  • src
  • templates
  • .bunfig.toml
  • .dockerignore
  • .gitignore
  • .gitmodules
  • AGENTS.md
  • bun.lock
  • Cargo.lock
  • Cargo.toml
  • CHANGELOG.md
  • CLAUDE.md
  • components.json
  • CONTRIBUTING.md
  • Dockerfile.docs
  • eslint.config.mjs
  • instrumentation.node.ts
  • instrumentation.ts
  • LICENSE
  • next.config.ts
  • osv-scanner.toml
  • package.json
  • postcss.config.mjs
  • proxy.ts
  • readme-arch-hq.gif
  • README.md
  • rust-toolchain.toml
  • SECURITY.md
  • skills
  • skills-lock.json
  • tailwind.config.ts
  • tsconfig.json
  • vitest.config.e2e.mts
  • vitest.config.mts

Discussion (0)

Ask about usage, or say what you built with it

Sign in to join the discussion.

No comments yet. Be the first to say what this is good for.

More harnesses

affaan-m/
ECC
affaan-m/ECCHarnesses

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

258k
ruvnet/rufloHarnesses

🌊 The original agent meta-harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, RAG integration, and native Claude Code / Codex / Hermes and many more Integrated

72k

Practical patterns, starters & CLI tools for loop engineering with AI coding agents. Design systems that prompt and orchestrate agents (inspired by Addy Osmani and Boris Cherny). Includes loop-audit, loop-init, loop-cost.

11k