real talk: I started this after my own coding agent escaped its "sandbox" and leaked an API key. I had given it clear instructions. Didn't matter.
so we built Grimdall. it sits between your agent and your tools and checks every single call before it runs:
- rm -rf / blocked, with a safer alternative suggested
- API keys in arguments masked before they leave your machine