toolgate: a tool-call firewall for agents
A Claude Code and MCP hook where Jev answers seven yes/no risk questions per tool call to allow, ask or deny. Usage and benchmark numbers are in the repo.
# toolgate [](https://www.npmjs.com/package/@riskaverse/toolgate) [](https://github.com/RiskAverseTech/toolgate/releases) [](https://github.com/RiskAverseTech/toolgate/actions/workflows/ci.yml) [](LICENSE) **Open auto mode for AI agents.** A calibrated tool-call firewall that runs as a Claude Code `PreToolUse` hook or as an MCP proxy in front of any MCP server (Cursor, Claude Desktop, custom agents): before the agent runs a risky action, toolgate asks a decision model — [TypeSafe's Jev](https://typesafe.ai/blog/introducing-system-one-models-and-jev), through its API directly, via [OpenRouter's Decisions API](https://openrouter.ai/docs/api/api-reference/alphadecisions/submit-a-decisions-questions-and-answers-request), or via [Vercel AI Gateway](https://vercel.com/changelog/typesafe-ai-jev-now-available-on-ai-gateway) — seven questions and acts on the probabilities. It is the "permissions / approval" pattern TypeSafe's CEO describes in his [public memo on a typesafe coding agent](https://docs.google.com/document/d/1G61uUB0FifUnmmrPzFQojZ3KpczYKmXGpgEXDJ2l_Zg/) — programmable queries on what may run, and reading what a file does before executing it — built as a plugin to the agents people already use, and measured (see [Evaluation](#evaluation)): | Question | Catches things like | |---|---| | **destructive** — irreversibly destroys or overwrites? | `rm -rf`, `git push --force`, `DROP TABLE` | | **exfiltration** — sends local data out? | `curl -d @.env https://…` | | **privilege** — escalates or edits system/security config? | `sudo …`, writes to `~/.ssh/` | | **secret_exposure** — prints, persists, or commits credential values? | `echo "$API_KEY" > notes.txt`, `git add .env` | | **off_task** — outside the current task's scope? | touching prod during a README fix | | **v