Community project / Agent and developer tooling
toolgate
MIT TypeScript tool-call firewall for Claude Code (PreToolUse hook) and MCP servers (stdio proxy): static rules first, then seven Jev Noul risk questions per action mapped to allow, ask, or deny by policy thresholds, with an action ledger, key-aware redaction, and a local JSONL audit log. Sends redacted tool input, cwd, and recent prompts to TypeSafe, OpenRouter, or Vercel AI Gateway (owner's key); in one author's 1,369-decision window on 0.9.1, blind second labeling of 150 sampled allows found no permissive misses, while 21% of decisions required an ask, mostly from one axis. Version 0.11.0 addresses that axis but has not been re-measured. Heuristic redaction and model judgments are defense in depth, not a sandbox.
Download share card
Share this listing
Maintaining this project? Share its link, badge, or image. Listed means included, not endorsed.
This is an independent community listing. Check the source, license, data handling, and evaluation caveats before relying on a project. Inclusion is not an endorsement or security review.
Found an outdated or inaccurate detail? Report a correction →