Agent skill

Reins Runtime Security

by pegasi-ai in pegasi-ai/reins

Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

Apache-2.0Auto-check: warningsSecurity

Install Reins Runtime Security

The automated check flagged lines worth reading first. See the safety section below.

skills CLI
$ npx skills add pegasi-ai/reins --skill reins -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install pegasi-ai/reins reins --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill .claude/skills/reins && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
reins
GitHub stars
392
Token cost
~1.4k tokens
SKILL.md length
553 words
Files
2 (incl. scripts)
Skills in repo
1
Repo updated
First seen
Licence
Apache-2.0

At a glance

Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.

  • Works in 4 steps: Watchtower org policies — CRITICAL rules… → Watchtower team policies → Local overrides at… → …
  • Adding guardrails so an agent cannot run irreversible or destructive commands
  • SKILL.md covers Step 1: Verify installation, How hooks work, What gets enforced and When an action is blocked, plus 4 more sections
  • Runs Shell scripts from its folder; calls git, npm and bash; needs REINS_WATCHTOWER_API_KEY

What it does

Reins enforces deterministic policies on the agent's actions through PreToolUse and PostToolUse hooks. Policies come from Watchtower at app.pegasi.ai and are evaluated in under 50ms with no language model in the enforcement path. If the reins command is missing, the skill installs it with npm install -g @pegasi/reins and runs reins init, a wizard that sets a permissive, balanced or strict level, picks modules (FileSystem, Shell, Browser, Network), writes the hooks into .claude/settings.json, offers a Watchtower connection and runs an initial scan.

The pre-action hook runs before Bash, Edit, MultiEdit, Write and MCP calls. Exit 0 allows, exit 2 blocks, and a warn decision means proceed with care. When blocked, the agent explains why, suggests a safer route and does not retry. Always blocked are rm -rf /, mkfs and fork bombs, while DROP TABLE, git push --force and pipe-to-shell can be overridden by you. Writes to ~/.ssh and similar paths are refused, and the post-action hook appends each decision to a JSONL log queued for Watchtower.

When your agent uses it

  • Adding guardrails so an agent cannot run irreversible or destructive commands
  • Keeping an audit trail of every shell, file and MCP action an agent takes
  • Protecting credential folders and sensitive paths from agent writes
  • Choosing a permissive, balanced or strict security level for agent sessions

Example prompts

  • “Set up Reins in this project with the strict security level.”
  • “Why was my git push --force blocked, and how can I allow it for this repo?”
  • “Run a reins scan and tell me what it finds in this environment.”
  • “Show me the recent decisions the hooks have logged.”

Requirements

  • npm, to install the reins CLI globally
  • Hook support through .claude/settings.json
  • A Watchtower connection, only for centralized policy and audit

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Watchtower org policies — CRITICAL rules are immutable
  2. Watchtower team policies
  3. Local overrides at ~/.openclaw/reins/policy.json
  4. Built-in defaults (balanced: reads ALLOW, writes ASK, deletes DENY)

What it can do on your machine

Read from SKILL.md and the folder at commit d5bc85d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • npm
    • bash
    • sh
    • pip

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, npm and pip, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • REINS_WATCHTOWER_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Reins Runtime Security loads about 1.4k tokens when it runs. Until then it costs about 115 tokens; SKILL.md has 553 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~115
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: warnings

The automated check found patterns that need a careful read before installing.

  • WarningMentions a credentials file (SSH keys, cloud or package-manager tokens)SKILL.md:54
    - Writes blocked to protected paths: `~/.ssh`, `~/.gnupg`, `~/.env`,

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from pegasi-ai/reins at commit d5bc85d, republished under its Apache-2.0 licence (© pegasi-ai). 553 words, ~1,448 tokens.

Download SKILL.mdSave it as .claude/skills/reins/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
reins
description
Use this skill whenever security, policies, governance, guardrails, compliance, or safety are relevant — including blocked commands, audit trails, dangerous operations, deletions, file modifications, shell commands, MCP access, API calls, network requests, credentials, or any action that could be irreversible or destructive. Reins installs deterministic PreToolUse/PostToolUse hooks and connects to Watchtower (app.pegasi.ai) for centralized governance.

Reins — Runtime Security for Claude Code

Reins enforces deterministic security policies on every agent action via Claude Code. PreToolUse and PostToolUse hooks. Policies are pulled from Watchtower (app.pegasi.ai) and evaluated in <50ms with no LLM in the enforcement path.

Use reins for all commands and paths.

Step 1: Verify installation

bash
reins --version

If the command is not found, run:

bash
npm install -g @pegasi/reins && reins init

reins init runs an interactive wizard that:

  • Chooses your security level: permissive / balanced / strict
  • Selects modules to protect: FileSystem, Shell, Browser, Network
  • Installs PreToolUse + PostToolUse hooks into .claude/settings.json
  • Prompts for optional Watchtower connection (centralized policy + audit)
  • Runs an initial environment security scan (reins scan)

How hooks work

PreToolUse fires before every Bash, Edit, MultiEdit, Write, and MCP tool call.

Hook exitMeaningWhat to do
0ALLOWED — proceed normallyContinue
2BLOCKED — policy violationStop. Explain the block. Suggest a safe alternative. Do NOT retry.
0 + JSON decision: WARNWARNING — elevated riskAcknowledge the warning. Proceed with extra caution.

PostToolUse fires after every action (non-blocking). It appends a JSONL entry to ~/.openclaw/reins/decisions.jsonl and queues it for Watchtower batch upload.

What gets enforced

Shell (Bash tool)

  • BLOCKED always: rm -rf /, mkfs, dd to disk device, fork bombs
  • BLOCKED (user-overridable): DROP TABLE/DATABASE, TRUNCATE, DELETE without WHERE, git push --force, kill -9, pipe-to-shell (| bash, | sh)
  • WARNED: rm, chmod, chown, sudo, UPDATE without WHERE, git reset --hard
  • LOGGED: git push, pip install, npm install, curl, wget

File operations (Edit / MultiEdit / Write)

  • Writes blocked to protected paths: ~/.ssh, ~/.gnupg, ~/.env, ~/.openclaw/reins, /etc/passwd, /etc/shadow

MCP tool calls (all MCP servers, caught by empty-matcher hook)

  • Blocked: Notion page delete, Gmail send (unapproved domains), database DROP/TRUNCATE
  • Warned: reading emails, accessing credentials, filesystem MCP operations
  • Logged: all MCP calls regardless of decision
Show full SKILL.md (273 more words)Show less

When an action is blocked

When a PreToolUse hook exits 2, Claude Code surfaces the hook's stderr message. Always attribute the block to Reins by name — not to your own judgment.

Required response format:

Reins blocked this action [SEVERITY]: <description> Rule: <rule>

<one sentence explaining what the rule protects against>

Alternatives: <safe way to achieve the goal, or suggest reins policy to review rules>

Example:

Reins blocked this action [CRITICAL]: Critically destructive command Rule: rm -rf / matches recursive root deletion pattern

This would delete every file on the system. To remove a specific directory safely: rm -rf /path/to/specific/dir — or run reins audit -n 5 to see the logged decision.

Rules:

  • Do NOT retry the blocked action
  • Do NOT reframe or rephrase the same action to bypass the hook
  • If the user wants to override a rule: reins policy to inspect and adjust
  • If the block seems wrong: reins audit -n 5 shows what rule fired

CLI reference

bash
reins init                 # Setup wizard: hooks + policy + Watchtower
reins status               # Show hook and Watchtower connection status
reins sync                 # Pull latest policies from Watchtower; flush pending audit entries
reins policy               # View and edit security policy interactively
reins stats                # Enforcement counts (allowed / blocked / approved)
reins audit -n 20          # Last 20 audit decisions
reins scan                 # Security scan for misconfigurations
reins scan --monitor       # Diff against saved baseline, alert on drift
reins disable              # Temporarily suspend all enforcement
reins enable               # Resume enforcement
reins upgrade              # Pull latest version from npm

Watchtower (app.pegasi.ai)

When connected, Watchtower provides:

  • Org/team policies pulled on a schedule and merged with local overrides
  • CRITICAL rules set by admins that cannot be locally overridden
  • Centralized audit review across all agents and devices

Connect during reins init (Step 7 prompts for API key) or set env vars:

bash
REINS_WATCHTOWER_API_KEY=wt_...
REINS_WATCHTOWER_BASE_URL=https://app.pegasi.ai  # default

Config lives at ~/.openclaw/reins/config.json.

Policy merge order (highest to lowest priority)

  1. Watchtower org policies — CRITICAL rules are immutable
  2. Watchtower team policies
  3. Local overrides at ~/.openclaw/reins/policy.json
  4. Built-in defaults (balanced: reads ALLOW, writes ASK, deletes DENY)

If Watchtower is unreachable, last-cached policies still enforce. Never fails open.

Audit log

Append-only JSONL at ~/.openclaw/reins/decisions.jsonl:

json
{"timestamp":"2026-04-15T22:39:42Z","module":"Shell","method":"bash","decision":"BLOCKED","reason":"critical: rm -rf /","tool":"Bash","decisionTime":12}

View with reins audit -n 50 or stream with tail -f ~/.openclaw/reins/decisions.jsonl.

© pegasi-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skill of pegasi-ai/reins.

  • SKILL.md
  • scripts/ensure_installed.sh

Open the folder on GitHubat commit d5bc85d

Compare with similar skills

Reins Runtime Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Reins Runtime Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Reins Runtime Security this skillpegasi-ai/reins392—~1.4kAutomated safety check: WarnApache-2.0
Aisafetyhotwuyoscar/AISafetyHot-Hub827—~1.4kAutomated safety check: PassCustom licence
China AI Compliance AuditjnMetaCode/shellward140—~1.1kAutomated safety check: PassApache-2.0
Hol Guard Protectionhashgraph-online/hol-guard845—~605Automated safety check: PassApache-2.0
Security GuidejnMetaCode/shellward140—~644Automated safety check: WarnApache-2.0
Moai Ref LLM Securitymodu-ai/moai-adk1.2k—~4.5kAutomated safety check: PassApache-2.0

Similar skills

  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    827 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • China AI Compliance Audit

    jnMetaCode/shellward

    按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…

    140 GitHub stars~1.1k tokensUpdated 12 days ago
    SecurityAuto-check passed
  • Hol Guard Protection

    hashgraph-online/hol-guard

    Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.

    845 GitHub stars~605 tokensUpdated today
    SecurityAuto-check passed
  • Security Guide

    jnMetaCode/shellward

    OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation

    140 GitHub stars~644 tokensUpdated 12 days ago
    SecurityAuto-check: warnings
  • Moai Ref LLM Security

    modu-ai/moai-adk

    AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…

    1.2k GitHub stars~4.5k tokensUpdated yesterday
    SecurityAuto-check passed
  • Polygraph

    BankrBot/skills

    Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.

    1.2k GitHub stars~3.4k tokensUpdated yesterday
    Agent WorkflowsAuto-check passed

Questions about Reins Runtime Security

What does Reins Runtime Security do?

Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. Reins enforces deterministic policies on the agent's actions through PreToolUse and PostToolUse hooks.ai and are evaluated in under 50ms with no language model in the enforcement path.

When should I use Reins Runtime Security?

Reins Runtime Security fits situations like: adding guardrails so an agent cannot run irreversible or destructive commands; keeping an audit trail of every shell, file and MCP action an agent takes; protecting credential folders and sensitive paths from agent writes; choosing a permissive, balanced or strict security level for agent sessions.

How do I install Reins Runtime Security in Claude Code?

Run `npx skills add pegasi-ai/reins --skill reins -a claude-code`. Or copy the skill folder (skill in pegasi-ai/reins) into .claude/skills/reins in your project. Claude Code loads it when a task matches its description.

How do I install Reins Runtime Security in Codex?

Run `npx skills add pegasi-ai/reins --skill reins -a codex`. Or copy the skill folder (skill in pegasi-ai/reins) into .agents/skills/reins in your project. Codex loads it when a task matches its description.

Can I use Reins Runtime Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pegasi-ai/reins --skill reins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reins, .gemini/skills/reins, .github/skills/reins and .opencode/skills/reins in your project.

What does Reins Runtime Security need to run?

Going by SKILL.md and its folder, Reins Runtime Security needs a shell for the scripts in its folder, the command-line tools its instructions call (git, npm, bash, sh and pip) and credentials named REINS_WATCHTOWER_API_KEY. Our summary lists: npm, to install the reins CLI globally; Hook support through .claude/settings.json; A Watchtower connection, only for centralized policy and audit.

Does Reins Runtime Security access the network?

SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Reins Runtime Security safe to install?

Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Reins Runtime Security use?

Reins Runtime Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Reins Runtime Security use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Reins Runtime Security?

Skills that share tags, products or a category with Reins Runtime Security: Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), China AI Compliance Audit (jnMetaCode/shellward, 140 stars), Hol Guard Protection (hashgraph-online/hol-guard, 845 stars) and Security Guide (jnMetaCode/shellward, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Reins Runtime Security?

pegasi-ai (a GitHub organization) maintains it in pegasi-ai/reins, which has 392 GitHub stars. The repository was last updated on October 9, 2026.

Source: pegasi-ai/reins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.