Skip to content
Back to skills

Squidbrake

BSecurity

Set up Squidbrake, which checks every command and tool call an AI agent makes against rules (risky ones wait for a person, rm -rf ~/ never runs), and respond correctly when Squidbrake blocks or holds an action. Use when the user wants guardrails, approvals or an audit trail for their coding agents, or when a tool call comes back blocked or waiting for approval from Squidbrake.

  • 12 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added October 1, 2026
ai-agentsrailsgit

Works with

  • claude code
  • cursor
  • cli
  • mcp

Security analysis

B77/100
  • highPerforms destructive filesystem operations
  • mediumInstalls packages at runtime which could introduce malicious dependencies

Pro shows the line behind each finding and how to fix it

Scanned October 1, 2026

npx -y skills add batrapulkit/squidbrake --skill squidbrake --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Squidbrake?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Squidbrake
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/batrapulkit-squidbrake/badge)](https://www.skillsdirectory.com/skills/batrapulkit-squidbrake)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: squidbrake
description: Set up Squidbrake, which checks every command and tool call an AI agent makes against rules (risky ones wait for a person, rm -rf ~/ never runs), and respond correctly when Squidbrake blocks or holds an action. Use when the user wants guardrails, approvals or an audit trail for their coding agents, or when a tool call comes back blocked or waiting for approval from Squidbrake.
---

# Squidbrake

Squidbrake is a gateway between AI agents and the machine. Every command, file edit, read and MCP tool call is
checked against `rules.yaml` before it runs: safe ones run, dangerous ones are blocked, and risky ones wait until
a person approves them in the dashboard, on their phone or in Slack. Everything is recorded in a tamper-evident
audit trail. Source: https://github.com/batrapulkit/squidbrake

## Setting it up for the user

Ask before running these: `connect all` changes the user's agent configs (each one is backed up first).

1. Install: `pipx install squidbrake` (or `pip install squidbrake`).
2. Connect every agent on this computer: `squidbrake connect all`. It finds Claude Code, Cursor, Codex, Gemini CLI,
   VS Code Copilot and Antigravity, plus the MCP servers they use. The first time, it prints the dashboard's admin
   key. Tell the user to save it, and don't repeat the key back in chat.
3. Start the gateway: `squidbrake` (opens `http://localhost:8080/dashboard`). For it to keep protecting them it must
   stay running. A 24/7 server option is in the README.
4. Tell the user to restart their agents. Codex also needs the hook approved once with `/hooks`.
5. Check: an agent asked to run `rm -rf ~/` should be refused with the reason.

Undo: `squidbrake connect all --remove`. Rules live in `~/.squidbrake/rules.yaml` and changes apply at once.
To guard one app's MCP server: `squidbrake proxy --app NAME --url URL` (or `-- COMMAND`).

## When Squidbrake blocks or holds one of your actions

- **Blocked:** the reason says why. Don't retry the same action, and don't reach the same result another way
  (a different command, a script, another tool, encoding it). Tell the user what was blocked and why, and ask how
  they want to proceed. Only the user can change the rules.
- **Waiting for approval:** a person is deciding. Wait for the decision; don't start a workaround meanwhile.
- **Rejected with a note:** the note is from the person. Follow it.
- **"Squidbrake can't be reached":** it fails closed on purpose. Ask the user to start it (`squidbrake`). Don't
  remove the hook to get around it.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…