SolonGate Agent Security is SolonGate's open source, local first security gateway for AI coding agents. It checks tool calls against your policies before they run, with secret detection, rate limits and a local audit trail.
This repository is the Agent Security gateway. The rest of the portfolio is at solongate.com.
Everything stays on the machine. The policy is a file, the audit trail is a file, and the guard contains no code that can open a socket. No account, no telemetry.
Agents: Claude Code, Codex, OpenCode, Antigravity.
git clone https://github.com/solongate/agent-security.git
cd agent-security
./install.shThen open a new terminal: hooks load when a session starts, so an already open
one is not guarded yet. solongate update pulls and reinstalls later.
The installer refuses to run from an agent, by design.
A real Claude Code session: the agent reaches for a .env, the guard refuses it,
and the agent says so rather than quietly working around it.
| Layer | What it does |
|---|---|
| Policy rules | Allow or deny by path, command, filename or URL, scoped to READ, WRITE, EXECUTE or NETWORK. |
| DLP | 70 built in secret patterns plus your own, in four modes: observe, detect, redact, block. |
| Egress | Refuses an upload whose file holds a secret, which pattern matching alone cannot see. |
| Rate limits | A cap per minute, hour or day. |
| The prompt | A shim masks the outbound request body on Claude Code, which no tool call hook can reach. |
| Tamper protection | The guard's own state is unreachable from a tool call, and a policy in a repository cannot switch it off. |
Every decision lands in ~/.solongate/local-logs/solongate-audit.jsonl, owner
only, one JSON object per line.
solongate the dataroom: policies, audit, settings
solongate policy list, create and edit the policy
solongate dlp secret detection
solongate ratelimit the rate limit
solongate audit browse the audit trail
solongate watch live tail tool calls
solongate trace what the guard saw in this directory
solongate doctor health check
solongate repair restore the guard, hooks and settings
solongate update pull the newest version and reinstall
Each one reads or changes a security posture, so they require a real terminal
and the guard refuses a tool call that invokes them. solongate --help is the
full tree.
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
![]() |
Go 1.26 and Node 22+.
pnpm install
pnpm buildThere are two implementations of the guard, in Go and in bundled JavaScript, and which one decides a call depends only on whether a machine has the binary. They have to agree, so a change to the decision path lands in both. Nothing in the repository checks that they still do: there is no test suite here, and a change to the guard is only as good as what you ran it against by hand. CONTRIBUTING.md is the rest.
Reporting a vulnerability: SECURITY.md, privately, never a public issue. CODE_OF_CONDUCT.md applies everywhere.
Apache License 2.0. See LICENSE.










