Skip to content

Repository files navigation

rv — shell guard for coding agents

Release Apache 2.0 Stars Discord macOS 15 or newer, Apple Silicon, and Linux Hosts

rv (Rykan V)

Control what your agent can do. rv's hook-grade guard blocks destructive shell (and Read / Edit / Write secret-path on Grok, Claude, and Cursor) when the host calls rv. Hook evaluation requires the host to invoke it.

rv opencode runs OpenCode in a host-owned terminal on the persistent per-project workspace host, under a macOS Seatbelt that starts from deny-default. The process may read and write the workspace, and it may read the system locations needed to execute programs. Public HTTPS goes through the RV proxy and loopback networking (including local servers) is allowed; direct public, LAN, and metadata connections are denied, as are Unix-socket connections to host sockets. Seatbelt cannot restrict an allowed TCP listener to loopback addresses, so a runtime with server capability can bind wildcard/LAN interfaces. It can signal processes inside its sandbox, not other host processes. Mach lookup is deny-by-default, Mach registration is denied, and the Keychain is unreachable. A workspace that already contains a hard link is refused. The host mounts the workspace path on a fresh volume so a later hard link to an outside file fails with a cross-device error. The volume belongs to the workspace for its whole life, across every runtime the host launches; each runtime has its own process group and admission capability. A same-user force-unmount of that volume is not covered. Closing a runtime or the workspace kills the owned process group. Linux refuses the launch instead of applying a weaker sandbox. This is not a finished agent isolation boundary. See the release acceptance audit.

Site: rykanv.com · Docs: rykanv.com/docs/introduction · Discord: discord.gg/uZn9MDUYKx

Why this exists

Agents delete the wrong tree. rv sits on the host's pre-tool hook and denies the command before the host runs it. Install is one curl; rv setup writes adapters for hosts it can see.

Quick start

curl -fsSL https://rykanv.com/install | sh

To launch the currently supported agent from a writable workspace:

rv opencode --workspace /absolute/repo -- run 'describe this project'

RV searches absolute PATH directories for OpenCode, or accepts --executable /absolute/opencode. The command attaches to the persistent workspace host for the project and streams one host-owned terminal, exactly like rv workspace run. The runtime receives the productive workspace environment: an RV-managed HOME/cache/tmp, a sanitized PATH covering installed toolchains, and secret-bearing variables stripped. On macOS the process and its children may read and write only that workspace, plus the system locations needed to execute programs. Public HTTPS goes through the RV proxy and loopback networking is allowed; direct public, LAN, and metadata connections are denied, as are Unix-socket connections to host sockets. Signals to processes outside the sandbox are denied. A workspace that already contains a hard link to another file is refused, and the running workspace path is a separate volume so a new hard link cannot name an outside inode. Linux refuses this launch until its backend enforces the same limits; a write-only sandbox is not used instead. Other host integrations remain hook based.

What it does

Destructive git reset --hard, checkout --, clean -fd, push --force, stash clear
Destructive fs rm -rf, find -delete, and similar
Secret paths .env, SSH keys, and other known credential files
Allow once Redeem the code from a block; the next matching call in this working directory runs once
Explain rv explain shows which pack would fire
Hosts Grok, Pi, OpenCode, Claude, OpenClaw, Hermes, Codex, Cursor. rv setup writes a host only when that host is already on the machine.
Platform macOS 15 or newer, Apple Silicon. Linux aarch64/x86_64. Foundation Models on macOS 26 or newer. PR CI builds Swift on macos-26 and smokes the binaries on macos-15. Linux PR CI is ubuntu-24.04 x86_64; aarch64 is a supported install, not a PR job.

Supported hosts

Host After rv setup (if detected) File-tool Read / Edit / Write
Grok ~/.grok/hooks/rv.json yes
Pi ~/.pi/agent/extensions/rv-guard.ts shell only
OpenCode ~/.config/opencode/plugins/rv-guard.js shell only
Claude settings merge yes
OpenClaw ~/.openclaw/extensions/rv-guard/ shell only
Hermes ~/.hermes/plugins/rv-guard/ shell only
Codex ~/.codex/hooks/rv-guard.py shell only
Cursor ~/.cursor/hooks/rv-guard.py yes

Commands

rv setup                         # wire hosts
rv test 'git reset --hard'       # evaluate, do not run
rv explain 'git reset --hard'    # which pack would fire
rv scan                          # session forensics (deny-only findings)
rv allow-once a1b2c3             # redeem the code from a hook deny
rv packs                         # catalog
rv packs enable <pack>           # enable an extra pack (day-one always compiled)
rv policy show                   # typed rules
rv allowlist list                # permanent exceptions
rv doctor                        # health
rv uninstall                     # remove rv-owned files

Anonymous usage is on by default. Turn it off with "analytics.enabled": false in ~/.config/rv/config.json. Setup does not print a notice.

License

Apache 2.0. See LICENSE.

About

A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs.

Resources

Stars

4 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages