Agent Guard uses CEL policies to block coding agents' risky dependency installs

HowDevelop · x · 2026-10-04

Coding agents can autonomously run npm install or pip install, turning bug fixes into supply-chain decisions with potentially hallucinated package names. Jozu AI's Agent Guard addresses this: apply a ToolPolicy to the agent's shell tool (e.g. Bash), evaluate command arguments against CEL rules, and set action to Enforce so failed assertions block the tool call before execution. The author warns that command matching needs care — rules targeting pip install may miss python -m pip, uv pip, or other wrappers.

Related event: Agent Guard Uses CEL Policies to Block Risky Dependency Installs by Coding Agents(3 posts)→

Original post →

More from coding & agent

coding & agent channel →