Skip to content

snitilf/Leash

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

76 Commits
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

Leash

A command-line tool, written in Rust for Linux, that wraps an AI coding agent and mediates everything it does at the operating-system boundary.

AI coding agents run with your full user permissions: they can read any file, run any program, and reach any host, and the only record of what they did is their own summary. Leash sits between the agent and the machine. Using seccomp user-notification and Landlock, the kernel pauses every file open, process spawn, and network connection in the agent's process tree and asks Leash first. That yields three capabilities in one tool:

  • Record. A complete, append-only trace of what the agent actually did: ground truth, not the agent's self-report.
  • Enforce. A declarative policy over paths, hosts, and binaries. Actions are allowed, denied, or held for human approval; any supervisor error resolves to deny.
  • Rewind. Workspace snapshots at step boundaries, so a run can be rewound, or two runs diffed by their actual effects.

Because Leash works at the syscall layer, it is agent-agnostic and vendor-agnostic: no SDK integration, nothing the supervised process can reason around. Requires Linux 5.19 or later on x86-64.

Documentation

The project is documentation-driven: every decision is recorded before it is implemented. Start at docs/README.md for the document hierarchy. The specification is docs/spec/SPEC.md, the design (how it is built) is in docs/design/, the decision records are in docs/adr/, and the project vocabulary is docs/CONTEXT.md.

About

Put your AI coding agent on a leash: every file, process, and connection recorded, policed, and reversible

Topics

Resources

Stars

Watchers

Forks

Releases

Packages

Contributors

Languages