Agent Guard: Local Security Tool Prevents Secret Leaks in Claude Code and Codex
Key point
The open-source tool blocks risky file reads and scans Git commits locally using gitleaks to prevent API keys and tokens from entering AI agent transcripts or repository history.
Details
Agent Guard is a local-first guardrail designed to prevent AI coding agents like Claude Code and Codex from leaking sensitive information. It operates by blocking risky .env reads, masking secret-like output in real-time, and scanning changed files before they are committed to Git. The tool relies on gitleaks and portable shell scripts, ensuring no hosted accounts, telemetry, or external services are required.
Key Security Mechanisms
The tool implements defense-in-depth strategies across multiple integration points:
- Agent Plugin Integration: For Claude Code and Codex, the plugin scans staged added lines before
git commitorgit pushcommands execute. It blocks the command if secret-like values are detected and refuses flags like--no-verifyor--no-gpg-signto prevent agents from bypassing checks. - Native Git Hooks: A pre-commit hook scans staged changes after Git staging is complete, aborting commits on findings. This covers both human and agent commits.
- GitHub Actions: A repository backstop scans checked-out files on every push or pull request, catching secrets that might have bypassed local hooks.
- Output Masking: The tool redacts secret-like patterns in supported tool outputs, ensuring credentials do not appear in agent transcripts.
Scope and Limitations
Agent Guard is explicitly defined as a defense-in-depth boundary, not a replacement for credential management systems like vaults or DLP. It supports macOS and Linux (x64/arm64) but does not currently support Windows. Runtime dependencies include sh, awk, git, jq, and gitleaks 8.30 or newer.
The tool handles complex scenarios such as git commit -a, --patch, and shell code passed to bash -c or eval. However, it scans files as they exist when the command starts; if a command writes a file or changes directories before committing, the native hook is recommended to catch the final state. If a scan cannot run, the default behavior warns and continues, though this can be configured to block commands via AGENT_GUARD_INFRA_FAILURE_MODE=closed.
This summary was generated automatically by AI. Check the original for the author's claims and context. Copyright belongs to the original author.
Our guide explains how the AI works. Report summary errors, attribution issues, or removal requests via Contact.