{"repo":"varmabudharaju/agent-pd","free":true,"listed":false,"github":"https://github.com/varmabudharaju/agent-pd","clone":"git clone https://github.com/varmabudharaju/agent-pd.git","description":"A police department for your Claude Code agents — a logging-only hook + CLI that audits the main agent and every subagent and reports rule offenses (permission bypass, out-of-scope & credential access, self-permissioning, disallowed tools, redundant, off-task) with quoted evidence. Catch-and-report, never blocks.","language":"Python","stars":19,"topics":["agent-monitoring","ai-agents","ai-safety","audit-log","claude-code","cli","developer-tools","llm","observability","python"],"license":"Apache-2.0","category":"ai-agents","readme_excerpt":"agent-pd A police department for your Claude Code agents A logging-only hook records every tool &amp; permission event from the main agent and its subagents; the pd CLI replays that log through six detectors and reports rule offenses with quoted evidence. Catch-and-report — it never blocks. Quickstart · How it works · Detectors · Architecture · Security Caught on camera The department's body-cam. agent-pd won't stop the heist — but every move your agents make ends up on the record. ▶ Watch the full clip with sound Flight recorder + police scanner, not a firewall. If you need to stop an action, that stays with Claude Code's permission prompts or an OS sandbox. agent-pd tells you what an agent did — faithfully, after the fact or live as it happens. Highlights - Covers the main agent + every subagent , including those spawned by Claude Code's new dynamic Workflow tool (verified against recorded workflow-subagent hook events). - Six deterministic detectors at zero token cost — denied calls, out-of-scope &amp; credential access, permission bypass, self-permissioning, disallowed tools, off-task work. - Tamper-evident audit log (hash-chained) with an optional off-host append-only sink . - Sessions are named, not UUIDs — pd list and pd watch show each session's project directory and first user prompt, derived from data already in the logs (works retroactively). - Honest by design — it raises the bar; it is not a sandbox. See SECURITY.md. What it looks like — pd watch --all across thr","default_branch":null,"files":null,"tree":[],"storefront":"/r/varmabudharaju","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/varmabudharaju/agent-pd/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}