
gate.cat
Blocks rm -rf before your AI agent can run it
16 followers
Blocks rm -rf before your AI agent can run it
16 followers
Your AI coding agent doesn't have to be malicious to end your week — just shell access and one confident mistake. gate.cat is a deterministic, fail-closed veto that inspects the tool call at the boundary and refuses the irreversible class (rm -rf, DROP TABLE, terraform destroy) before it runs. Claude Code hook, gated shell, or OpenAI-API proxy. Free forever, Apache 2.0. We replayed 826,644 real agent commands (re-counted 28 Jul, lower bound): 0 real misses — and we publish our own bypass map.



Correcting my own comment on launch day, because the gap map is the exact thing I asked for feedback on and I stated it in my own favour. It is not one named gap. It is three, and two of them slip the whole product: a Unicode homoglyph rm and a printf-hex assembled rm. Only the third (runtime assembly) is still caught by the delete analyzer. Separately, the description above originally said 1,085,159 replayed commands. That number is retired - it double-counted one HuggingFace dataset and was inflated by 23.8%. The re-measured figure is 826,644 (28 Jul, one global dedup set, and a lower bound: two SWE-Gym sets dropped out after an upstream split rename). I have updated the description. 0 real misses after adjudication is unchanged. Both are pinned in FACTS.md, which now carries a retired-numbers table naming the old figure and why it died. So, an answer to my own question about whether publishing a gap map builds trust or reads as weakness: it is only worth anything if you also publish it on the day it gets worse. Today it got worse.