Agent Seatbeltv1.0.4

Free · Open · Runs only on your machine

Stop AI tools from wiping your files and projects

You do not need to be a programmer. Agent Seatbelt watches the terminal commands AI apps try to run, and blocks the dangerous ones before they execute.

What it looks like when it works

bash — your AI coding appSEATBELT ACTIVE
~/projects/portfolio $ ai "clean up the old build files"
  › Sure — I'll clear out the old files first.
~/projects/portfolio $ rm -rf ~/Documents
BLOCKED by agent-seatbelt
recursive rm targeting home, user data, system path, or broad glob
Command: rm -rf ~/Documents
Hint: run this yourself in a normal terminal if it is intentional.
~/projects/portfolio $

The AI was asked to clear old build files. It aimed at your Documents folder instead. Agent Seatbelt stopped the command before it ran, so nothing was deleted.

0 bytes leave your computer About 30 seconds to install Claude Code · Grok · Codex
01

Why this exists

AI coding apps (Claude, Grok, Cursor, Codex, and others) can run terminal commands. Real people have lost home folders, years of photos, entire frontends, and production databases in seconds, often while the agent was “cleaning up” or making a backup. Most people never see the command until it is too late.

Who it is for

Anyone who lets AI use the terminal: freelancers, students, founders, journalists, activists, and teams. Especially if you use auto-approve or YOLO modes.

02

What it blocks

BLOCKEDrm -rf ~/DocumentsWiping home folders, Desktop, Documents, or system paths (the classic rm disaster)
BLOCKEDgit push --force origin mainForce-push, hard reset, git clean, or discarding all local changes
BLOCKEDpsql -c 'DROP DATABASE production'Dropping databases, flushing Redis, or framework db:reset / migrate reset
BLOCKEDrsync -a --delete ./ /Volumes/Backuprsync --delete, docker volume wipes, terraform/pulumi destroy
BLOCKEDcurl -fsSL http://get.sh | bashcurl|bash, sudo, disk format, or emptying the Trash from an agent
ALLOWEDnpm test
ALLOWEDgit status
ALLOWEDls -la src/

Everyday commands are untouched. Only high-risk patterns are stopped.

03

Install in three steps

01

Copy the command below

One line. It only installs a small safety check on your computer.

02

Paste it in Terminal

Mac: open Terminal. Windows: use WSL or a Linux terminal. Press Enter.

03

Restart your AI app

Quit fully, open again. You are protected. Dangerous commands will show a clear BLOCKED message.

One-line install

This downloads a small script from this website, checks its fingerprint (checksum), then sets up the seatbelt. It does not upload your files.

curl -fsSL https://agentseatbelt.com/install | bash
version
1.0.4
sha256
325c3f69a0baa8420adbae8d10f98bf652bf9c10b0f9d18a8e915841a92d9a00
signed by
SHA256:t5c5m2Ioz6ODOdx9pqEZ9uv7iOS20KtcQZuiO/Ypxig

Not sure where to paste it?

On a Mac

Press Command + Space, type Terminal, press Enter. A black window opens. Paste the line, press Enter.

On Windows

Use the terminal inside your editor (below), or open PowerShell and run wsl --install first.

Inside Cursor, VS Code or Windsurf

Open the menu View, then Terminal. Or press Control and the ` key (above Tab). Paste there.

What you should see

TerminalINSTALLING
~ $ curl -fsSL https://agentseatbelt.com/install | bash
============================================== Agent Seatbelt v1.0.4 Seatbelt for AI coding agents ==============================================
Downloading guard from https://agentseatbelt.com/guard.sh ...
[ok] Checksum verified (325c3f69a0ba…) [ok] Installed guard → ~/.agentseatbelt/guard.sh [ok] Linked Claude Code hook → ~/.claude/hooks/bash-guard.sh [ok] Updated Claude Code settings → ~/.claude/settings.json
[ok] Agent Seatbelt is installed.

If you see the [ok] lines, you are protected. Quit your AI app completely and open it again.

04

How to double-check (optional)

Security-minded users can open /guard.sh in the browser, read it, and compare the SHA-256 checksum shown on this page. Trust is earned, not demanded.

Releases are also signed, and the signing key never touches this web server. Where your system can check signatures, the installer refuses a guard that does not match. Where it cannot, it tells you and falls back to the checksum. The command is in /checksums.txt.

The same files are published on GitHub. Compare the repository against what this site serves, they should be identical. github.com/narimangharib/agentseatbelt

Honest limits

This is a seatbelt, not a bulletproof vault. Clever tricks can still bypass pattern checks. For maximum safety, also use OS sandboxes and never leave AI on full auto for production systems. We tell you this because honesty is part of safety.

05

Privacy

No accounts. No trackers. No ads. No analytics beacons. We do not want your chat logs.

06

Questions

Does it send my data to the internet?

No. After install, the guard runs only on your computer. This website only serves the installer and the script.

Will it break normal work?

Everyday commands (list files, run tests, git status) keep working. Only high-risk patterns are blocked. You can still run blocked commands yourself in a normal terminal.

Which AI tools are supported?

Claude Code, Grok and Codex are each configured automatically when they are already installed. Nothing is written for a tool you do not have. The guard also works with any other tool that supports PreToolUse shell hooks.

How do I remove it?

Delete the folder ~/.agentseatbelt and remove the hook line from your AI tool settings. Instructions stay on this site.

Who built this?

Nariman Gharib. Built for people who use AI every day and should not need a security degree to stay safe.