Runtime Guard is the free, local-first enforcement layer for MCP agents. It works standalone, requires no account, and controls file and shell actions before execution.
Runtime Guard sits between your AI agent and your system. Every file or shell action is evaluated against policy before it executes. Nothing slips through.
Every agent tool call goes through the same enforcement pipeline, locally, in milliseconds.
Agent tool call routed through Runtime Guard MCP controls
Policy checks command, path, and context before any action
Allow, block, simulate blast radius, or request approval
Every decision logged with full context and matched rule
All happens locally on your machine. No cloud required.
Stop destructive commands before they run. No cleanup, no recovery.
Define exactly what agents are allowed to do. Policy is yours.
See every action - allowed, blocked, or pending. Nothing is hidden.
Let agents operate freely within the boundaries you set.
Install from PyPI, run setup, connect your agent. No config files to hand-edit.