Open-source guardrail

Flag reading a .env file

AgentTrail Guard lets this run by default, and writes the match to its local decision log so you can see how often it happens.

Default action
Warn
Severity
High severity
Library version
0.2.1Sep 29, 2026

What it catches, and what it misses

Written into the rule itself, next to what it matches, so you can judge it before you trust it.

Warns when a file tool READS a dotenv file — the Read and Grep tools — at both the .env* spelling at any depth and the <name>.env spelling (production.env, secrets.env). A WRITE is deliberately NOT flagged (Edit, Write, MultiEdit, NotebookEdit, and Cursor's Delete), because creating or editing config is ordinary work and the exposure this catches is an agent reading an existing secret, so the id names the read. A committed placeholder is NOT flagged either (.env.example, .env.sample, .env.template), because warning on a file that holds no secret teaches the reader to ignore the warning. Matches file-tool access by path: reading a .env through a shell command such as cat .env is a command span and is covered by se.env-print instead. It also cannot tell whether the file actually contains a secret.

Tested on every build

The rule must match every command on the left and none on the right, or the library does not build. Catching the real thing is easy; staying quiet on the near-miss is the hard part.

Catches (4)

  • Read.env
  • Readconfig/.env.production
  • Readconfig/production.env
  • Readapps/api/.env.local

Stays quiet on (6)

  • Read.env.example
  • Read.env.sample
  • Editapps/api/.env.local
  • Write.env
  • Editsrc/index.ts
  • Editpackage.json

What "warn" means in each app

The guard runs as a hook in each app, and each app gives a hook different powers. Here is what this rule's default action does in each one.

Claude Code
The call runs, and the match is written to the local decision log.
Cursor
The call runs, and Cursor shows nothing. The match is still written to the decision log.
Codex CLI
The call runs. Codex's terminal UI shows a hook line (a codex exec run shows nothing), and the match is written to the decision log.

This rule matches file paths. In Codex CLI, reading a file fires no hook, and in Cursor, reads shown as Explored are not checked, so there it sees fewer calls than in Claude Code. Each app hands the guard a different set of calls: in a Cursor sandbox run mode, for one, some terminal commands run without reaching the guard at all. Read the notes for Cursor and for Codex CLI before you rely on a rule there.

Change what it does in one command

Turn it off, change its action, or silence it on one command shape. The narrow one is allow: the rule keeps catching everything else.

agenttrail-guard
$agenttrail-guard guardrails show block-env-file-read# everything about it
$agenttrail-guard guardrails set-action block-env-file-read ask# block, ask or warn
$agenttrail-guard guardrails allow block-env-file-read '<pattern>'# silence one shape
$agenttrail-guard guardrails disable block-env-file-read# turn it off

Put these guardrails in front of your agent.

AgentTrail Guard is free and open source. It checks every command and file change against the whole library before your agent runs it, on your machine, with no account.

bash
$npm i -g @agenttrail/guard
Read the source on GitHub