Saboteur777/crust

๐ŸŒŸ Open Source AI Agent Security Infrastructure โ€” intercepts and blocks dangerous agent behaviors before they happen. Just one command! Join us to build safer Human-AI Symbiosis!

โ˜… 0Forks 0GitHub โ†—Compare

Project website โ†—

README

Crust Banner

Crust

Your agents should never (try to) read your secrets.

Website โ€ข Quick Start โ€ข How It Works โ€ข Issues โ€ข Discussions

CI Go Report Card Release Go Version License Platform

Crust in action

What is Crust?

Crust is a transparent, local gateway between your AI agents and LLM providers. It intercepts every tool call โ€” file reads, shell commands, network requests โ€” and blocks dangerous actions before they execute. No code changes required.

100% local. Your data never leaves your machine.

Quick Start

macOS / Linux:

/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/BakeLens/crust/main/install.sh)"

Windows (PowerShell):

irm https://raw.githubusercontent.com/BakeLens/crust/main/install.ps1 | iex

Then start the gateway:

crust start --auto

Point your agent to Crust:

Agent Configuration
Claude Code ANTHROPIC_BASE_URL=http://localhost:9090
Codex CLI OPENAI_BASE_URL=http://localhost:9090/v1
Cursor Settings โ†’ Models โ†’ Override OpenAI Base URL โ†’ http://localhost:9090/v1
Cline Settings โ†’ API Configuration โ†’ Base URL โ†’ http://localhost:9090/v1
Windsurf Settings โ†’ AI โ†’ Provider Base URL โ†’ http://localhost:9090/v1
Open Claw Set baseUrl to http://localhost:9090 in ~/.openclaw/openclaw.json
OpenCode OPENAI_BASE_URL=http://localhost:9090/v1
Any OpenAI-compatible agent Set your LLM base URL to http://localhost:9090/v1

That's it. Crust auto-detects the provider from the model name and passes through your auth. Works with all 7 major coding agents out of the box โ€” each agent's tool names are recognized automatically.

How It Works

Crust architecture

Crust inspects tool calls at three layers:

  1. Layer 0 (Request Scan): Scans tool calls in conversation history before they reach the LLM โ€” catches agents replaying dangerous actions.
  2. Layer 1 (Response Scan): Scans tool calls in the LLM's response before they execute โ€” blocks new dangerous actions in real-time.
  3. Layer 2 (OS Sandbox): Kernel-level enforcement via Landlock (Linux) and Seatbelt (macOS) โ€” last line of defense even if rules are bypassed.

All activity is logged locally to encrypted storage.

Built-in Protection

Crust ships with 14 security rules out of the box:

Category What's Protected
Credentials .env, SSH keys, cloud creds (AWS, GCP, Azure), GPG keys
System Auth /etc/passwd, /etc/shadow, sudoers
Shell History .bash_history, .zsh_history, .python_history, and more
Browser Data Chrome, Firefox, Safari passwords, cookies, local storage
Package Tokens npm, pip, Cargo, Composer, NuGet, Gem, Hex auth tokens
Git Credentials .git-credentials, .gitconfig with credentials
Persistence Shell RC files, authorized_keys, crontabs
Key Exfiltration Content-based PEM private key detection
Self-Protection Agents cannot read, modify, or disable Crust itself
Dangerous Commands eval/exec with dynamic code execution

All rules are open source: internal/rules/builtin/security.yaml

Custom Rules

Rules use a progressive disclosure schema โ€” start simple, add complexity only when needed:

rules:
  # One-liner: block all .env files
  - block: "**/.env"

  # With exceptions and specific actions
  - block: "**/.ssh/id_*"
    except: "**/*.pub"
    actions: [read, copy]
    message: "Cannot access SSH private keys"

  # Advanced: regex matching on commands
  - name: block-rm-rf
    match:
      command: "re:rm\\s+-rf\\s+/"
    message: "Blocked: recursive delete from root"
crust add-rule my-rules.yaml    # Rules active immediately (hot reload)
CLI Reference
# Gateway
crust start --auto                          # Auto mode (recommended)
crust start --endpoint URL --api-key KEY    # Manual mode
crust start --auto --block-mode replace     # Show block messages to agent
crust start --foreground --auto             # Foreground mode (for Docker)
crust stop                                  # Stop the gateway
crust status                                # Check if running
crust logs [-f]                             # View logs

# Rules
crust list-rules                            # List active rules
crust add-rule FILE                         # Add custom rules (hot reload)
crust remove-rule FILE                      # Remove user rules
crust reload-rules                          # Force reload all rules
crust lint-rules [FILE]                     # Validate rule syntax

# Other
crust version                               # Show version
crust uninstall                             # Complete removal
Configuration

Crust stores configuration in ~/.crust/config.yaml:

server:
  port: 9090
  log_level: info

upstream:
  url: "https://openrouter.ai/api"       # fallback upstream
  timeout: 300
  providers:                               # custom model routing
    my-llama: "http://localhost:11434/v1"
    my-vllm:  "http://gpu-server:8000/v1"

security:
  enabled: true
  block_mode: remove    # "remove" or "replace"

rules:
  enabled: true
  watch: true           # hot reload on file change

sandbox:
  enabled: false        # OS-level sandbox (Landlock/Seatbelt)

In auto mode (--auto), the gateway resolves providers from the model name using a built-in registry (Anthropic, OpenAI, DeepSeek, Gemini, Mistral, Groq, and more). Clients bring their own API keys. User-defined providers take priority.

Docker

A Dockerfile is included in the repo. Build and run:

docker build -t crust .
docker run -p 9090:9090 crust

Or with docker-compose:

# docker-compose.yml
services:
  crust:
    build: .
    ports:
      - "9090:9090"
    restart: always

Point your agents to http://<docker-host>:9090 instead of localhost.

The --foreground flag keeps the process in the foreground so the container stays alive. --listen-address 0.0.0.0 binds to all interfaces so the host can reach the container.

What works in Docker: All rule-based blocking, tool call inspection (Layers 0 & 1), content scanning, telemetry, and auto-mode provider resolution. These operate on API traffic passing through the proxy and work regardless of where Crust runs.

Build from Source

Requires Go 1.24+ and Task.

git clone https://github.com/BakeLens/crust.git
cd crust
task build
./crust version

Contributing

Crust is open-source and in active development. We welcome contributions โ€” PRs for new security rules are especially appreciated.

Add this badge to your project's README:

[![Protected by Crust](https://img.shields.io/badge/Protected%20by-Crust-blue)](https://github.com/BakeLens/crust)
Citation

If you use Crust in your research, please cite:

@software{crust2026,
  title = {Crust: A Transparent Gateway for AI Agent Security},
  author = {Chen, Zichen and Chen, Yuanyuan and Jiang, Bowen and Xu, Zhangchen},
  year = {2026},
  url = {https://github.com/BakeLens/crust}
}

License

Elastic License 2.0

Contributors

cyyeverchen-zichen

Issues