Agent Guard uses CEL policies to block coding agents' risky dependency installs
HowDevelop · x · 2026-10-04
Coding agents can autonomously run npm install or pip install, turning bug fixes into supply-chain decisions with potentially hallucinated package names. Jozu AI's Agent Guard addresses this: apply a ToolPolicy to the agent's shell tool (e.g. Bash), evaluate command arguments against CEL rules, and set action to Enforce so failed assertions block the tool call before execution. The author warns that command matching needs care — rules targeting pip install may miss python -m pip, uv pip, or other wrappers.
More from coding & agent
- Fortnox Doc MCP serves 377 API endpoints' docs straight into your AI assistant — modelcontextprotocol · 2026-10-04
- Teams are consolidating into monorepos to make them easier for AI agents to work with — neal_lathia · 2026-10-04
- Using Skills and Memory to audit spreadsheets with traceable findings and saved preferences — FellMentKE · 2026-10-04
- Project-based iteration keeps what landed in AI video, with Codex and Dreamina CLI automating the loop — FellMentKE · 2026-10-04
- Turning research notes into structured, editable proposals and reports with tone control for the audience — FellMentKE · 2026-10-04
- Global Macro Database update brings hundreds of years of macro data to Claude Code and Codex agents — SchoeneggerPhil · 2026-10-04