Copy the command below
One line. It only installs a small safety check on your computer.
Free · Open · Runs only on your machine
You do not need to be a programmer. Agent Seatbelt watches the terminal commands AI apps try to run, and blocks the dangerous ones before they execute.
What it looks like when it works
The AI was asked to clear old build files. It aimed at your Documents folder instead. Agent Seatbelt stopped the command before it ran, so nothing was deleted.
AI coding apps (Claude, Grok, Cursor, Codex, and others) can run terminal commands. Real people have lost home folders, years of photos, entire frontends, and production databases in seconds, often while the agent was “cleaning up” or making a backup. Most people never see the command until it is too late.
Anyone who lets AI use the terminal: freelancers, students, founders, journalists, activists, and teams. Especially if you use auto-approve or YOLO modes.
rm -rf ~/DocumentsWiping home folders, Desktop, Documents, or system paths (the classic rm disaster)git push --force origin mainForce-push, hard reset, git clean, or discarding all local changespsql -c 'DROP DATABASE production'Dropping databases, flushing Redis, or framework db:reset / migrate resetrsync -a --delete ./ /Volumes/Backuprsync --delete, docker volume wipes, terraform/pulumi destroycurl -fsSL http://get.sh | bashcurl|bash, sudo, disk format, or emptying the Trash from an agentnpm testgit statusls -la src/Everyday commands are untouched. Only high-risk patterns are stopped.
One line. It only installs a small safety check on your computer.
Mac: open Terminal. Windows: use WSL or a Linux terminal. Press Enter.
Quit fully, open again. You are protected. Dangerous commands will show a clear BLOCKED message.
This downloads a small script from this website, checks its fingerprint (checksum), then sets up the seatbelt. It does not upload your files.
curl -fsSL https://agentseatbelt.com/install | bash
guard.shguard.sh.sigallowed_signersinstall.shchecksums.txtgithub
Press Command + Space, type Terminal, press Enter. A black window opens. Paste the line, press Enter.
Use the terminal inside your editor (below), or open PowerShell and run wsl --install first.
Open the menu View, then Terminal. Or press Control and the ` key (above Tab). Paste there.
What you should see
If you see the [ok] lines, you are protected. Quit your AI app completely and open it again.
Security-minded users can open /guard.sh in the browser, read it, and compare the SHA-256 checksum shown on this page. Trust is earned, not demanded.
Releases are also signed, and the signing key never touches this web server. Where your system can check signatures, the installer refuses a guard that does not match. Where it cannot, it tells you and falls back to the checksum. The command is in /checksums.txt.
The same files are published on GitHub. Compare the repository against what this site serves, they should be identical. github.com/narimangharib/agentseatbelt
This is a seatbelt, not a bulletproof vault. Clever tricks can still bypass pattern checks. For maximum safety, also use OS sandboxes and never leave AI on full auto for production systems. We tell you this because honesty is part of safety.
No accounts. No trackers. No ads. No analytics beacons. We do not want your chat logs.
No. After install, the guard runs only on your computer. This website only serves the installer and the script.
Everyday commands (list files, run tests, git status) keep working. Only high-risk patterns are blocked. You can still run blocked commands yourself in a normal terminal.
Claude Code, Grok and Codex are each configured automatically when they are already installed. Nothing is written for a tool you do not have. The guard also works with any other tool that supports PreToolUse shell hooks.
Delete the folder ~/.agentseatbelt and remove the hook line from your AI tool settings. Instructions stay on this site.
Nariman Gharib. Built for people who use AI every day and should not need a security degree to stay safe.