A security layer for AI coding agents. It records every read, write and command, and checks your policy before any of them runs.
GryphOSS · v0.9.0
Everyone runs YOLO mode. Gryph keeps the receipts.
Actions. Enforcement. Live.
gryph logs --live streams every action as your agent works, allowed or blocked.
gryph logs --live
ALLOWwritereadme.txt
BLOCKexecrm -rf /
policy: no-destructive · claude-code
ALLOWreadsrc/main.go
A developer asks Claude Code to refactor a module. It runs 47 tool calls in 90 seconds. Then the tests fail.
Which files did it read before making changes?
Did it run commands that were not expected?
Did it touch secrets, config or CI pipelines?
What did the file look like before and after?
Without Gryph, you're guessing. With Gryph, gryph logs shows everything.
Pipe it anywhere.
JSON Lines exports flow into your dashboards and internal tools.
gryph export --since 1wLives in SQLite by default. Pipe it into your own tools, or OpenSearch for centralized review.
Block, Warn
Custom Policies
A YAML rule, checked before the action runs.
version: "1"
rules:
- id: no-force-push
action: block
match:
action_types: [command_exec]
command_patterns: ['git push .*--force']
message: Force push needs a human.
- id: warn-session-write-volume
action: warn
condition: context.files_written >= 25A blocked action never reaches the agent's tool. Guidance goes back to it as plain text. Gryph records every decision.
Works with the agent you already run.

Claude Code

Codex

Cursor
Windsurf

Gemini CLI

OpenCode

Pi Agent

Devin CLI

Command Code
One command hooks every agent it finds. No per-agent setup.
Protect your agents.
Install Gryph, then hook every agent it finds.
curl -fsSL https://raw.githubusercontent.com/safedep/gryph/main/install.sh | shgryph install && gryph status