laya-guard: local guardrail for coding agents blocks 25/27 AgentDojo attacks at ~90ms
Extreme_Ad5709 · reddit · 2026-10-11
A developer open-sourced laya-guard, a fully local guardrail that inspects every tool call made by coding agents and decides to allow, review, or block it.
- No API key needed; 90ms per command on CPU
- Regex rules catch obvious risks (rm -rf /, curl … | sh, leaked API keys); benign commands like ls and npm test skip the model entirely
- Everything else is judged by Laya, a 322M local model
- Supports Claude Code, Codex CLI, Cursor, Gemini CLI, Copilot CLI and 6 other agents
- Self-tested on AgentDojo at the judge level: blocked 25 of 27 attacks while allowing 92 of 97 benign tasks
MIT-licensed, install with pip install laya-guardrail.
Related event: Open-Source laya-guard Screens Coding Agent Commands Locally(2 posts)→
More from coding & agent
- Synthesia launches Syren Video: prompt-to-video agent powered by Opus 5.5, free to try — heyshrutimishra · 2026-10-11
- Codex lead jokes 'the day we reach perfection it will be resets from there onwards' — xiaohu · 2026-10-11
- One MCP server for X, Instagram, WhatsApp, Telegram and Gmail with per-action approvals — gauthi3r_XBorg · 2026-10-11
- Dev ports Sega MegaDrive game natively in under a day with single Codex/Claude session — ssh4net · 2026-10-11
- Grok Bot Negotiated His Internet Bill Down $15/Month Over Live Chat — jarrodwatts · 2026-10-11
- banteg surprised Codex cloud auto-configures its environment just by reading the repo — banteg · 2026-10-11