Open-source guardrails for AI coding agents: rules the agent reads, checks that run as it writes, and gates at commit and in CI. This template is the wiring chock init leaves behind, ready for your first guards.
chock · chock-catalog · chock-example · chock.sh (launching soon)
chock-quickstart is a GitHub template repository: the exact tree that chock init . writes into an empty repo, with no policies installed. Chock is open-source application security for code written by AI coding agents. Each check is a deterministic local script, with no model and no upload, and it refuses known vulnerability classes before they are committed. This is a demo repository, a frozen exhibit of chock init; questions and issues belong on the framework repo.
Coding agents already ask before they run a shell command. What they do not check is the code they write: SQL injection in a Spring repository, an IAM grant on *, an MCP server at @latest, a bidi override hiding in a source file, a secret written into agent memory. Chock checks that code as the agent writes it, at commit and in CI. The catalog holds the policies; this repo is where you start installing them.
| Area | What gets refused | Policy | Tier |
|---|---|---|---|
| Java & Kotlin | injection, XXE, SSRF, unsafe deserialization, weak crypto, dependencies below a known fix | java-security |
commit |
| Unsafe code, IAM | eval, shell=True, os.system, pickle; IAM Action: * |
block-unsafe-code-execution, block-wildcard-iam |
commit |
| Supply chain | dependencies off an allowlist, Actions on a mutable tag, MCP servers and images at @latest |
verify-dependency-exists, pin-github-actions, block-unpinned-agent-components |
commit |
| Agent code | host execution, approvals switched off, credential leaks | agentic-code-security |
commit |
| Accessibility | a stripped alt, aria-label, label or lang |
no-a11y-regression |
commit |
| Prompt injection, memory | bidi and tag characters; secrets written into agent memory | block-invisible-unicode, guard-memory-writes |
commit |
| Test integrity | deleted tests, lost assertions, new skips | protect-test-integrity |
commit |
| Also included | secrets, destructive commands, agent self-protection | scan-secrets, block-destructive-commands, protect-agent-config |
commit, in-agent |
Tiers: commit is a git hook or CI gate that exits non-zero. in-agent is the agent's pre-tool hook: best-effort, and it fails open. advisory is rule text the agent reads. No agent reaches enforced today.
chock is on PyPI, but the release there (0.15.2, 30 Sep 2026) is older than the engine this page describes. Install the frozen engine from its commit (Python 3.11 or newer):
pip install "chock @ git+https://github.com/open-coder-ai/chock@992711af4cf8d4fd9c4c861f10ef6e53374d75d7"- In your repository, for teams. Run
chock init ., thenchock add <id> --ref <catalog commit> --verify-sha <sha256> --skip-compilefor each policy, thenchock sync --repo . --ci. Commit the result. Every clone runschock sync --repo .once, because git never clones hooks. The commit gates are enforced at commit and in CI. - In your coding agent, as plugins. Best-effort, and they fail open. One repo per client: Claude Code, Cursor, Copilot, Codex, Devin. Each README has the install line for its client.
- One Claude Code plugin from a selection. The chock.sh builder (launching soon) gives a
chock install --selection '…' --applycommand.
| In your repository (for teams) | In your coding agent, as plugins | |
|---|---|---|
| Where it runs | Your agent's hook where its client has one, at commit, and in CI | The client's pre-tool hook only |
| Strength | The commit gates are enforced at commit and in CI | Best-effort: the client's hook fails open, and it does not run in CI |
Commit the result of the repo route. Every clone then runs chock sync --repo . once. chock add prints the pack's sha256 on install, and --ref takes a full 40-character commit of the catalog.
Click Use this template on GitHub, then in your new repo:
git clone <your-new-repo-url> && cd <your-new-repo>
chock sync --repo . # git never clones hooks, so every clone runs this onceA policy is a folder of plain files. chock sync compiles it into the form each layer can use: rule text in AGENTS.md, a pre-tool guard in the agent's own hook where the client has one, git hooks, and a CI gate. A check costs no tokens: it is a script, not a model. A passing check adds nothing to the agent's context, and a refusal adds one short reason naming the fix. The known classes are fixed in the agent's turn rather than in review. Chock adds no new place your code goes: checks run where the agent writes. The agent still sends its context to its own model provider; installing fetches policies once.
This template installs no policy. The recording below shows a refusal and its fix once one is installed.
| Path | What it is |
|---|---|
AGENTS.md, CLAUDE.md |
The one rules file every agent reads, directly or through a thin wrapper |
chock.lock |
Hash-pinned record of installed content, empty until you install some |
.agents/policies/, .agents/skills/ |
Where policies live, plus the bundled authoring skills (eval, optimize, policy-init, validate) |
.chock/ |
Engine state: config.yaml (yours to edit), registry.json, coverage.json, dependency-allowlist.txt, the vendored hook adapter in bin/ |
.claude/, .gemini/, .github/ |
Thin per-agent wrappers that delegate to AGENTS.md |
.gitattributes, .gitignore |
LF pinning for generated, hash-attested files; ignores |
docs/ |
A short guide to the layout: docs/README.md |
Each row is from the catalog's registry.yaml at commit f25f5a3 (policies unchanged since 9a64623). "Run automatically" counts eval cases with a replayable execute: block.
| Policy | Refuses | Tier | Eval cases (run automatically) |
|---|---|---|---|
scan-secrets |
credentials written into files | enforced at commit | 55 (55) |
block-destructive-commands |
destructive shell and git commands | enforced at commit | 170 (170) |
protect-main-branch |
direct commits and pushes to main |
enforced at commit | 4 (4) |
block-unpinned-agent-components |
agent components at @latest or :latest |
enforced at commit | 54 (54) |
java-security |
Java and Kotlin injection, deserialization and related classes | enforced at commit | 177 (167) |
no-a11y-regression |
accessibility regressions in front-end code | enforced at commit | 20 (7) |
chock add protect-main-branch # install a guardrail from the catalog
chock status # see what's installed and what it enforces
chock check # is this repo sound?Added by the policies you install, not by this template: secrets, destructive commands, unpinned agent components, Java and Kotlin vulnerability classes, accessibility regressions and more. The area-by-area table is in Application security above and in the catalog README. For a repo with two policies already installed, see chock-example.
The whole catalog is 71 policies: 35 enforced at commit, 11 in the agent (best-effort), 25 advisory (registry.yaml in chock-catalog at f25f5a3). No agent reaches enforced today, and every OWASP mapping is partial.
Tiers: commit is a git hook or CI gate that exits non-zero. in-agent is the agent's pre-tool hook: best-effort, and it fails open. advisory is rule text the agent reads. No agent reaches enforced today. OWASP mappings are partial and the engine is frozen at the commit above. Chock does not stop every attack: it closes common, known entry points before they ship.
Does Chock use an LLM? No. Each check is a deterministic script. A check costs no tokens; a refusal adds one short reason to the agent's context.
Does my code leave my machine? Chock adds no new place your code goes. The agent still sends context to its own model provider. chock add fetches policies from the catalog once.
Which agents does it work with? In the repo route, whichever agents read AGENTS.md, plus native hooks where the client has them. Plugins cover Claude Code, Copilot, Cursor, Codex and Devin.
How do I install it? The repository route or the plugin route, both in Install.
What does it cost? Free and open source (Apache-2.0).
Does it replace SAST or code review? No. It refuses known classes while the agent writes, so they are fixed before review; keep SAST and review.
Which OWASP items does it cover? Every OWASP Agentic (ASI01–ASI10) risk has at least one catalog policy mapped to it, and every mapping is partial: docs/coverage.md.
Machine-readable sources:
registry.yaml: every policy, its tier and eval counts- Policy manifests, with
compliancemappings:base/*/manifest.yaml docs/coverage.md: OWASP coverage- Plugin
marketplace.jsonin each plugin repo above - chock.sh
/llms.txtand/api/index.json: launching soon
The 13 public repositories:
| Repository | What it is |
|---|---|
| agentseam | Core: One handler API over every coding agent. |
| chock | Core: Author a policy once, enforce it on every agent. |
| chock-catalog | Policies: The policies, each labelled by what it enforces, with replayed evals. |
| context-report | Evidence: A signed report of whether an agent artifact works. |
| chock-threat-intel | Evidence: A weekly threat ledger, each entry scored against the catalog. |
| chock-claude-plugins | Plugins: The catalog as Claude Code plugins (generated). |
| chock-copilot-plugins | Plugins: The catalog as Copilot CLI and VS Code plugins (generated). |
| chock-cursor-plugins | Plugins: The catalog as Cursor plugins (generated). |
| chock-codex-plugins | Plugins: The catalog as Codex plugins (generated). |
| chock-devin-plugins | Plugins: The catalog as Devin plugins (generated). |
| chock-quickstart | Template: What chock init leaves behind. |
| chock-example | Template: A working adoption, one policy per layer. |
| .github | Community: Org profile and community health files. |
Issues about this exhibit go to the framework repo, because the tree is generated by chock init. Policies go to the catalog: a policy claims only what it can do, and evals are the argument. The threat ledger lists open gaps. Sign commits with git commit -s.
Apache-2.0, see LICENSE.

