{"repo":"mayankjain0141/nixis","free":true,"listed":false,"github":"https://github.com/mayankjain0141/nixis","clone":"git clone https://github.com/mayankjain0141/nixis.git","description":"AI agent firewall that intercepts tool calls (file, shell, network) and enforces deterministic policies at sub-microsecond latency using CEL, IFC, secret scanning, and audit logging.","language":"Go","stars":39,"topics":["ai-agents","governance","policy-engine","ai-security","cel","claude-ai","claude-code","developer-tool","developer-tools-ai-agent","information-flow-control"],"license":"MIT","category":"ai-agents","readme_excerpt":"Nixis - AI Agent Firewall Real-time governance engine for AI coding agents. Built for Claude Code. Works with any agent that exposes tool calls. Nixis intercepts every tool call your AI assistant makes — file writes, shell commands, network access — and evaluates it against security policies in under 200ms. If the action violates policy, Nixis blocks it before execution. No prompt engineering. No trust assumptions. External enforcement. The Problem AI coding agents (Claude Code, Cursor, Copilot) have unrestricted tool access. They can: - Read .env and curl credentials to an external server - rm -rf your repository - Open reverse shells via nc -e /bin/sh - Install malicious packages via typosquatting - Escalate privileges with chmod 777 or sudo The only guardrail today is hoping the model says no. Nixis enforces externally — the model cannot bypass it because the hook intercepts at the tool-call boundary before execution. Install End Users One command. The installer downloads binaries, adds /.nixis to PATH, and fully configures the daemon, policies, and IDE hook automatically. After it completes, reload your shell with the printed source command and you're done. No manual nixis setup step required. From Source CLI Only (no daemon) Useful for CI pipelines and environments where you want just the CLI tools. Requirements Requirement Version When needed ------------- --------- ------------- macOS or Linux amd64 / arm64 Always Go 1.25+ Source builds only Node.js 26+ Dashboard dev (","default_branch":null,"files":null,"tree":[],"storefront":"/r/mayankjain0141","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/mayankjain0141/nixis/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}