Runtime Guard is a free, local-first MCP server that enforces policy on file and shell actions before execution. No account required.
"Your agent can say anything. It can only do what policy allows."
Not suggestions. Not previews. Actual commands on your actual system.
Wildcards, recursive deletes, production data - gone before you realise what happened.
Change permissions, install packages, alter config files, execute scripts with elevated access.
Credentials, private keys, environment files, database dumps - all accessible to shell commands.
And they don't always understand the consequences.
Runtime Guard works standalone, free, forever. Add cloud features when your team needs them.
Free, open source, no account required. Works with any MCP client.