What it does
Agent Guard is a local guardrail that blocks risky .env reads, masks secret-like output and scans changed files for leaked secrets before they reach Git. It works with Claude Code, Codex, Git hooks, GitHub Actions and the shell, and uses gitleaks. It sends no telemetry and does not replace existing secret scanning.
Use cases
- 01Blocking agents from reading .env files
- 02Masking secrets in terminal output from coding agents
- 03Scanning changes for leaked keys before a commit