A guard for AI agent tool calls, with three heads.
cerberus is a Rust CLI that judges every state-changing tool call before
an agent executes it, regardless of which harness is asking. cerberus guard runs a fail-closed gate and then up to three independent heads:
| Head | Catches | How |
|---|---|---|
risk |
commands that are dangerous no matter who's running them or why (general risk avoidance) | command-pattern scanning via tirith |
policy |
calls that break a rule the org has decided on (governance policy) | policy evaluation via cupcake |
judgement |
calls that are only bad because of state nothing in the payload reveals: git state, kubectl/terraform context, the hook payload itself (contextual bad decisions) | Rhai-scripted situational checks |
All three run by default and can be disabled individually.
git clone https://github.com/ahokinson/cerberus
cd cerberus
cargo install --path crates/cerberus
cerberus init # writes rules, policies, config, and hook wiring
cerberus doctor # confirms every head is actually enforcingIt works with Claude Code, Codex CLI, Cursor, Hermes Agent and opencode. Each harness keeps its own hook mechanism; cerberus normalizes them at the edge.
If a head's binary goes missing, the guard fails closed and says why in the
next session. cerberus doctor diagnoses it and retests.
- Installing: requirements, what
cerberus initdoes - Harnesses: supported agents and which tools are guarded
- Usage: commands and the hook wiring
- Configuration:
config.toml - Heads and rules: the shipped rules, policies and tirith overlay
- Layered policy sources: team rule repos
- Audit log: the optional local decision log
- Diagnosing a degraded guard:
cerberus doctor - Design notes: fail-open heads, fail-closed system
- Development: checks, coverage, fuzzing, CI
See CONTRIBUTING.md for the rule-script API and how to add a rule or a policy, and docs/development.md for build and test tooling. Security issues: SECURITY.md.
MIT. See LICENSE.