Your agents should never (try to) read your secrets.
Website โข Quick Start โข How It Works โข Issues โข Discussions
Crust is a transparent, local gateway between your AI agents and LLM providers. It intercepts every tool call โ file reads, shell commands, network requests โ and blocks dangerous actions before they execute. No code changes required.
100% local. Your data never leaves your machine.
macOS / Linux:
/bin/bash -c "$(curl -fsSL https://raw.githubusercontent.com/BakeLens/crust/main/install.sh)"Windows (PowerShell):
irm https://raw.githubusercontent.com/BakeLens/crust/main/install.ps1 | iexThen start the gateway:
crust start --autoPoint your agent to Crust:
| Agent | Configuration |
|---|---|
| Claude Code | ANTHROPIC_BASE_URL=http://localhost:9090 |
| Codex CLI | OPENAI_BASE_URL=http://localhost:9090/v1 |
| Cursor | Settings โ Models โ Override OpenAI Base URL โ http://localhost:9090/v1 |
| Cline | Settings โ API Configuration โ Base URL โ http://localhost:9090/v1 |
| Windsurf | Settings โ AI โ Provider Base URL โ http://localhost:9090/v1 |
| Open Claw | Set baseUrl to http://localhost:9090 in ~/.openclaw/openclaw.json |
| OpenCode | OPENAI_BASE_URL=http://localhost:9090/v1 |
| Any OpenAI-compatible agent | Set your LLM base URL to http://localhost:9090/v1 |
That's it. Crust auto-detects the provider from the model name and passes through your auth. Works with all 7 major coding agents out of the box โ each agent's tool names are recognized automatically.
Crust inspects tool calls at three layers:
- Layer 0 (Request Scan): Scans tool calls in conversation history before they reach the LLM โ catches agents replaying dangerous actions.
- Layer 1 (Response Scan): Scans tool calls in the LLM's response before they execute โ blocks new dangerous actions in real-time.
- Layer 2 (OS Sandbox): Kernel-level enforcement via Landlock (Linux) and Seatbelt (macOS) โ last line of defense even if rules are bypassed.
All activity is logged locally to encrypted storage.
Crust ships with 14 security rules out of the box:
| Category | What's Protected |
|---|---|
| Credentials | .env, SSH keys, cloud creds (AWS, GCP, Azure), GPG keys |
| System Auth | /etc/passwd, /etc/shadow, sudoers |
| Shell History | .bash_history, .zsh_history, .python_history, and more |
| Browser Data | Chrome, Firefox, Safari passwords, cookies, local storage |
| Package Tokens | npm, pip, Cargo, Composer, NuGet, Gem, Hex auth tokens |
| Git Credentials | .git-credentials, .gitconfig with credentials |
| Persistence | Shell RC files, authorized_keys, crontabs |
| Key Exfiltration | Content-based PEM private key detection |
| Self-Protection | Agents cannot read, modify, or disable Crust itself |
| Dangerous Commands | eval/exec with dynamic code execution |
All rules are open source: internal/rules/builtin/security.yaml
Rules use a progressive disclosure schema โ start simple, add complexity only when needed:
rules:
# One-liner: block all .env files
- block: "**/.env"
# With exceptions and specific actions
- block: "**/.ssh/id_*"
except: "**/*.pub"
actions: [read, copy]
message: "Cannot access SSH private keys"
# Advanced: regex matching on commands
- name: block-rm-rf
match:
command: "re:rm\\s+-rf\\s+/"
message: "Blocked: recursive delete from root"crust add-rule my-rules.yaml # Rules active immediately (hot reload)CLI Reference
# Gateway
crust start --auto # Auto mode (recommended)
crust start --endpoint URL --api-key KEY # Manual mode
crust start --auto --block-mode replace # Show block messages to agent
crust start --foreground --auto # Foreground mode (for Docker)
crust stop # Stop the gateway
crust status # Check if running
crust logs [-f] # View logs
# Rules
crust list-rules # List active rules
crust add-rule FILE # Add custom rules (hot reload)
crust remove-rule FILE # Remove user rules
crust reload-rules # Force reload all rules
crust lint-rules [FILE] # Validate rule syntax
# Other
crust version # Show version
crust uninstall # Complete removalConfiguration
Crust stores configuration in ~/.crust/config.yaml:
server:
port: 9090
log_level: info
upstream:
url: "https://openrouter.ai/api" # fallback upstream
timeout: 300
providers: # custom model routing
my-llama: "http://localhost:11434/v1"
my-vllm: "http://gpu-server:8000/v1"
security:
enabled: true
block_mode: remove # "remove" or "replace"
rules:
enabled: true
watch: true # hot reload on file change
sandbox:
enabled: false # OS-level sandbox (Landlock/Seatbelt)In auto mode (--auto), the gateway resolves providers from the model name using a built-in registry (Anthropic, OpenAI, DeepSeek, Gemini, Mistral, Groq, and more). Clients bring their own API keys. User-defined providers take priority.
Docker
A Dockerfile is included in the repo. Build and run:
docker build -t crust .
docker run -p 9090:9090 crustOr with docker-compose:
# docker-compose.yml
services:
crust:
build: .
ports:
- "9090:9090"
restart: alwaysPoint your agents to http://<docker-host>:9090 instead of localhost.
The --foreground flag keeps the process in the foreground so the container stays alive. --listen-address 0.0.0.0 binds to all interfaces so the host can reach the container.
What works in Docker: All rule-based blocking, tool call inspection (Layers 0 & 1), content scanning, telemetry, and auto-mode provider resolution. These operate on API traffic passing through the proxy and work regardless of where Crust runs.
Build from Source
Requires Go 1.24+ and Task.
git clone https://github.com/BakeLens/crust.git
cd crust
task build
./crust versionCrust is open-source and in active development. We welcome contributions โ PRs for new security rules are especially appreciated.
- Report a bug
- Security vulnerabilities โ please report privately
- Discussions
Add this badge to your project's README:
[](https://github.com/BakeLens/crust)Citation
If you use Crust in your research, please cite:
@software{crust2026,
title = {Crust: A Transparent Gateway for AI Agent Security},
author = {Chen, Zichen and Chen, Yuanyuan and Jiang, Bowen and Xu, Zhangchen},
year = {2026},
url = {https://github.com/BakeLens/crust}
}

