Launching today

Squidbrake
Change control for AI agents: sign-off, undo and a record
33 followers
Change control for AI agents: sign-off, undo and a record
33 followers
Every action your AI agents take (commands, refunds, emails, database changes) goes on a tamper-evident record. Routine ones run; risky ones wait for a second person, who sees what led to it, with an undo. Claude Code, Cursor, Codex, MCP. Free, open source.
Interactive







Free
Launch Team / Built With

EneyProactive AI for Mac. Free test, 20,000 credits.
Promoted



Hi Product Hunt 👋 I'm Pulkit, the builder of Squidbrake.
It started with a near-miss: during a test, my AI agent read an "urgent" email from the CEO and tried to wire $24,800. The email came from *acrne-corp.com*, not *acme.com*.
The agent did exactly what it was told. The terrifying part? Nobody else saw it, nobody signed off, and there was no audit trail to explain how it happened.
Enter Squidbrake: Change control and human-in-the-loop authorization for AI agents.
We are giving agents the ability to do powerful things, but we need a sign-off before they touch production. Squidbrake lets you set deterministic rules for what agents can and cannot do autonomously.
Here is how it works:
🛑 Human-in-the-loop for the scary stuff: Routine actions run on their own. Risky ones (`git push --force`, `DROP TABLE`, triggering refunds) pause and wait for a second person to approve via dashboard, Slack, or one tap on your phone.
🔍 See it before it happens: The approver sees exactly what will change *before* it happens (e.g., "deletes 4,312 rows of 10,240 in orders"). Destructive changes keep an undo state.
🛡️ Deterministic prompt injection defense: If an agent tries to send data to an address that was only mentioned in a web page or email, Squidbrake holds it and flags the source.
⚡ Zero-LLM latency: No LLMs in the decision path. Just plain YAML rules, meaning it’s predictable, fast, and free to run.
🪵 Tamper-evident audit trails: A tamper-evident record of which agent took the action, what it changed, who approved it, and the context that led to it.
It acts as one unified policy across Claude Code, Cursor, Codex, Gemini CLI, VS Code Copilot, Antigravity, and any MCP tool. Best of all, it’s open-source (Apache 2.0) and self-hosted; what your agents do never leaves your machine.
Try it out:
• No install: the "Open in Codespaces" button in our README.
• One line (installs it, connects your agents, opens the dashboard):
macOS / Linux: curl -fsSL https://pilots.squidbrake.com/install.sh | SQUIDBRAKE_REF=producthunt sh
Windows: $env:SQUIDBRAKE_REF="producthunt"; irm https://pilots.squidbrake.com/install.ps1 | iex
• Or: pipx install squidbrake, then squidbrake setup
Then ask your agent to run rm -rf ~/ and watch it get blocked.
I’d love to hear from the community:
1. What is the one action you would *never* want an agent to do without asking you first?
2. If your team is running agents that touch real systems (orders, payments, data, code), I’m setting up a few pilots. Reply here or DM me!
Thanks for checking it out! 🦑 Agents propose. People approve.
Proof, not promises: we replay 10 real public agent incidents against the shipped rules in CI; 12 of 13 harmful actions are stopped, and the one that isn't is written up in the repo.
Honest limit: it isn't a sandbox. For an agent you don't trust at all, add a container.
In the age agents, an always on security layer sounds like a must have setup even for small companies. Definitely going to try this out on our platform.
@zishansami102 Thanks zishan. that's the bet - one agent with prod access and no reviewer is all it takes, and small teams feel it first. install is one pip command, run it in shadow mode first and watch what it would have held.
As a company building agents for other consumer companies, we use squidbrake to make sure we never let agents take any destructive actions
@samyakk Thanks Samyak, this means a lot 🙏
Building agents for other companies is exactly where this gets hard: the agent is yours, but the data and the customers are theirs.
Squidbrake lets AI agents run on their own in prod, while anything risky (deleting data, force-pushing, moving money) waits for a human to approve. Works with Claude Code, Cursor, Codex, MCP tools and more.
Find out more at https://squidbrake.com
@karsinha thanks karishma. one thing worth adding: every rule in the repo is tested against replays of real public incidents in CI - 12 of 13 stopped today, and we document the one that isn't. proof, not promises.