Govern Codex's agent the way you govern production agents. This plugin blocks the things you do not want an autonomous agent doing on your machine, locally and offline, and (optionally) mints a signed, offline-verifiable proof that the session was governed.
It blocks, before the action runs:
- Destructive commands (
rm -rf,git push --force,DROP TABLE,curl ... | sh) - Secret exfiltration (a command or file write that ships an API key, token, or
.env) - Prompt-injected tool results (a poisoned MCP reply or fetched page steering the agent)
Local blocking runs fully offline with no account and no API key. It is a thin,
self-contained wrapper around the published @axiorank/coding-guard,
which bundles the zero-dependency AxioRank detection engine.
| Component | What it does |
|---|---|
hooks/hooks.json |
Runs the guard on PreToolUse, PostToolUse, and Stop. |
scripts/guard.sh |
Shim that prefers the vendored bin/guard.mjs (offline) and falls back to npx @axiorank/coding-guard; passes --agent codex. Fail-open. |
bin/guard.mjs |
Vendored coding-guard CLI (zero deps; runs on node). |
.mcp.json |
Registers AxioRank's remote MCP server (optional; needs AXIORANK_API_KEY). |
skills/coding-guard/SKILL.md |
Reference for what the guard blocks and how sealing/verification work. |
Set an API key and each session is reported to your AxioRank workspace and sealed at the end:
export AXIORANK_API_KEY="axr_live_..."Sessions then appear under Coding Sessions,
and a signed seal lands in <repo>/.axiorank/session-<id>.seal.json. Verify it offline,
with no trust in AxioRank:
npx -y @axiorank/audit-verify coding-seal .axiorank/session-*.seal.jsonLocal blocking and central audit are free (audit counts against your plan's normal event quota). The signed Coding Session Seal is a Team-plan feature.
MIT licensed. Part of AxioRank.