Squidbrake Adds Rule-Based Approval and Auditing for AI Agent Actions
Summary
Squidbrake is an open-source, Apache 2.0 gateway for controlling actions taken by AI agents. It checks tool calls against a rules.yaml policy, allows routine actions, blocks prohibited ones, and sends risky calls to a human approval queue. Decisions do not use an LLM; the system relies on deterministic rules, history checks, and a tamper-evident audit trail. The project can run on a laptop or self-hosted server, keeps data in the operator’s environment, and fails closed when the gateway is unavailable. It supports Claude Code through hooks and can wrap MCP clients and tools used with applications such as Claude Desktop, Cursor, Antigravity, Stripe, GitHub, Slack, and databases. Its examples include blocking a $24,800 wire attempt that followed an email from a look-alike domain, pausing refunds for review, and rejecting dangerous database operations such as DROP or TRUNCATE. Teams can issue separate keys to people and agents, assign approver roles, stop the system in an emergency, inspect event records, export CSV reports, and approve requests from a dashboard, phone links, or Slack-style notifications. The repository also exposes Python and HTTP interfaces, a proxy mode, Docker deployment, a live demo, and tests. Its stated security limitation is that tools not connected to Squidbrake can still be used outside its controls.