Aisafetyhot
wuyoscar/AISafetyHot-Hub
Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.
Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.
The automated check flagged lines worth reading first. See the safety section below.
$ npx skills add pegasi-ai/reins --skill reins -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install pegasi-ai/reins reins --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skill .claude/skills/reins && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "reins" agent skill from https://github.com/pegasi-ai/reins/tree/main/skill into .claude/skills/reins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reins", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/pegasi-ai/reins/tree/main/skillType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add pegasi-ai/reins --skill reins -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install pegasi-ai/reins reins --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skill .agents/skills/reins && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "reins" agent skill from https://github.com/pegasi-ai/reins/tree/main/skill into .agents/skills/reins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reins", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pegasi-ai/reins --skill reins -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install pegasi-ai/reins reins --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skill .cursor/skills/reins && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "reins" agent skill from https://github.com/pegasi-ai/reins/tree/main/skill into .cursor/skills/reins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reins", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/pegasi-ai/reins.git --path skill--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add pegasi-ai/reins --skill reins -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install pegasi-ai/reins reins --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skill .gemini/skills/reins && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "reins" agent skill from https://github.com/pegasi-ai/reins/tree/main/skill into .gemini/skills/reins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reins", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install pegasi-ai/reins reinsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add pegasi-ai/reins --skill reins -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .github/skills && cp -r skills-src/skill .github/skills/reins && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "reins" agent skill from https://github.com/pegasi-ai/reins/tree/main/skill into .github/skills/reins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reins", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add pegasi-ai/reins --skill reins -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install pegasi-ai/reins reins --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/pegasi-ai/reins.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skill .opencode/skills/reins && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "reins" agent skill from https://github.com/pegasi-ai/reins/tree/main/skill into .opencode/skills/reins/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "reins", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
reinsInstalls hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision.
Reins enforces deterministic policies on the agent's actions through PreToolUse and PostToolUse hooks. Policies come from Watchtower at app.pegasi.ai and are evaluated in under 50ms with no language model in the enforcement path. If the reins command is missing, the skill installs it with npm install -g @pegasi/reins and runs reins init, a wizard that sets a permissive, balanced or strict level, picks modules (FileSystem, Shell, Browser, Network), writes the hooks into .claude/settings.json, offers a Watchtower connection and runs an initial scan.
The pre-action hook runs before Bash, Edit, MultiEdit, Write and MCP calls. Exit 0 allows, exit 2 blocks, and a warn decision means proceed with care. When blocked, the agent explains why, suggests a safer route and does not retry. Always blocked are rm -rf /, mkfs and fork bombs, while DROP TABLE, git push --force and pipe-to-shell can be overridden by you. Writes to ~/.ssh and similar paths are refused, and the post-action hook appends each decision to a JSONL log queued for Watchtower.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit d5bc85d. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
Shell commands in SKILL.md call:
gitnpmbashshpipFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, npm and pip, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
REINS_WATCHTOWER_API_KEYFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Reins Runtime Security loads about 1.4k tokens when it runs. Until then it costs about 115 tokens; SKILL.md has 553 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found patterns that need a careful read before installing.
- Writes blocked to protected paths: `~/.ssh`, `~/.gnupg`, `~/.env`,Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from pegasi-ai/reins at commit d5bc85d, republished under its Apache-2.0 licence (© pegasi-ai). 553 words, ~1,448 tokens.
.claude/skills/reins/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Reins enforces deterministic security policies on every agent action via Claude Code. PreToolUse and PostToolUse hooks. Policies are pulled from Watchtower (app.pegasi.ai) and evaluated in <50ms with no LLM in the enforcement path.
Use reins for all commands and paths.
reins --versionIf the command is not found, run:
npm install -g @pegasi/reins && reins initreins init runs an interactive wizard that:
.claude/settings.jsonreins scan)PreToolUse fires before every Bash, Edit, MultiEdit, Write, and MCP tool call.
| Hook exit | Meaning | What to do |
|---|---|---|
0 | ALLOWED — proceed normally | Continue |
2 | BLOCKED — policy violation | Stop. Explain the block. Suggest a safe alternative. Do NOT retry. |
0 + JSON decision: WARN | WARNING — elevated risk | Acknowledge the warning. Proceed with extra caution. |
PostToolUse fires after every action (non-blocking). It appends a JSONL entry to
~/.openclaw/reins/decisions.jsonl and queues it for Watchtower batch upload.
Shell (Bash tool)
rm -rf /, mkfs, dd to disk device, fork bombsDROP TABLE/DATABASE, TRUNCATE, DELETE without WHERE,
git push --force, kill -9, pipe-to-shell (| bash, | sh)rm, chmod, chown, sudo, UPDATE without WHERE, git reset --hardgit push, pip install, npm install, curl, wgetFile operations (Edit / MultiEdit / Write)
~/.ssh, ~/.gnupg, ~/.env,
~/.openclaw/reins, /etc/passwd, /etc/shadowMCP tool calls (all MCP servers, caught by empty-matcher hook)
When a PreToolUse hook exits 2, Claude Code surfaces the hook's stderr message. Always attribute the block to Reins by name — not to your own judgment.
Required response format:
Reins blocked this action [
SEVERITY]:<description>Rule:<rule>
<one sentence explaining what the rule protects against>Alternatives:
<safe way to achieve the goal, or suggest reins policy to review rules>
Example:
Reins blocked this action [CRITICAL]: Critically destructive command Rule:
rm -rf /matches recursive root deletion patternThis would delete every file on the system. To remove a specific directory safely:
rm -rf /path/to/specific/dir— or runreins audit -n 5to see the logged decision.
Rules:
reins policy to inspect and adjustreins audit -n 5 shows what rule firedreins init # Setup wizard: hooks + policy + Watchtower
reins status # Show hook and Watchtower connection status
reins sync # Pull latest policies from Watchtower; flush pending audit entries
reins policy # View and edit security policy interactively
reins stats # Enforcement counts (allowed / blocked / approved)
reins audit -n 20 # Last 20 audit decisions
reins scan # Security scan for misconfigurations
reins scan --monitor # Diff against saved baseline, alert on drift
reins disable # Temporarily suspend all enforcement
reins enable # Resume enforcement
reins upgrade # Pull latest version from npmWhen connected, Watchtower provides:
Connect during reins init (Step 7 prompts for API key) or set env vars:
REINS_WATCHTOWER_API_KEY=wt_...
REINS_WATCHTOWER_BASE_URL=https://app.pegasi.ai # defaultConfig lives at ~/.openclaw/reins/config.json.
~/.openclaw/reins/policy.jsonIf Watchtower is unreachable, last-cached policies still enforce. Never fails open.
Append-only JSONL at ~/.openclaw/reins/decisions.jsonl:
{"timestamp":"2026-04-15T22:39:42Z","module":"Shell","method":"bash","decision":"BLOCKED","reason":"critical: rm -rf /","tool":"Bash","decisionTime":12}View with reins audit -n 50 or stream with tail -f ~/.openclaw/reins/decisions.jsonl.
© pegasi-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (scripts) in skill of pegasi-ai/reins.
Open the folder on GitHubat commit d5bc85d
Reins Runtime Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Reins Runtime Security this skillpegasi-ai/reins | 392 | — | ~1.4k | Automated safety check: Warn | Apache-2.0 | |
| Aisafetyhotwuyoscar/AISafetyHot-Hub | 827 | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| China AI Compliance AuditjnMetaCode/shellward | 140 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 | |
| Hol Guard Protectionhashgraph-online/hol-guard | 845 | — | ~605 | Automated safety check: Pass | Apache-2.0 | |
| Security GuidejnMetaCode/shellward | 140 | — | ~644 | Automated safety check: Warn | Apache-2.0 | |
| Moai Ref LLM Securitymodu-ai/moai-adk | 1.2k | — | ~4.5k | Automated safety check: Pass | Apache-2.0 |
wuyoscar/AISafetyHot-Hub
Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.
jnMetaCode/shellward
按中国法规(网安法 / PIPL / 等保2.0 / 数据出境 / AI生成内容标识)审计一个 AI 项目的代码仓库,产出每条都带 文件:行 取证、经独立复核、经脚本校验的合规报告。当用户问「这个项目上线合不合规」「调用了 OpenAI/Claude 算不算数据出境」「要不要做 AI 标识」「帮我做合规自查/等保/PIPL 检查」时使用。Audit an AI project's…
hashgraph-online/hol-guard
Use HOL Guard to preview and protect AI-agent package installs, Cursor surfaces, CI, and automation workflows.
jnMetaCode/shellward
OpenClaw 安全部署指南 / Security deployment guide — help users secure their OpenClaw installation
modu-ai/moai-adk
AI/LLM defensive security reference: prompt-injection defense, OWASP LLM Top 10 defensive mapping, MCP and agentic tool-call hardening, training-data poisoning detection, model-output validation and…
BankrBot/skills
Behavioral trust grades (A–F) for MCP servers. An agent skill from BankrBot/skills.
Works with
Categories
Installs hooks that check each agent action against security policies before it runs, blocking destructive commands and logging every decision. Reins enforces deterministic policies on the agent's actions through PreToolUse and PostToolUse hooks.ai and are evaluated in under 50ms with no language model in the enforcement path.
Reins Runtime Security fits situations like: adding guardrails so an agent cannot run irreversible or destructive commands; keeping an audit trail of every shell, file and MCP action an agent takes; protecting credential folders and sensitive paths from agent writes; choosing a permissive, balanced or strict security level for agent sessions.
Run `npx skills add pegasi-ai/reins --skill reins -a claude-code`. Or copy the skill folder (skill in pegasi-ai/reins) into .claude/skills/reins in your project. Claude Code loads it when a task matches its description.
Run `npx skills add pegasi-ai/reins --skill reins -a codex`. Or copy the skill folder (skill in pegasi-ai/reins) into .agents/skills/reins in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add pegasi-ai/reins --skill reins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/reins, .gemini/skills/reins, .github/skills/reins and .opencode/skills/reins in your project.
Going by SKILL.md and its folder, Reins Runtime Security needs a shell for the scripts in its folder, the command-line tools its instructions call (git, npm, bash, sh and pip) and credentials named REINS_WATCHTOWER_API_KEY. Our summary lists: npm, to install the reins CLI globally; Hook support through .claude/settings.json; A Watchtower connection, only for centralized policy and audit.
SKILL.md contains no URLs. Its commands use git, npm and pip, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md flagged 1 warning(s): mentions a credentials file (ssh keys, cloud or package-manager tokens). Read the flagged lines before installing; the check is not a guarantee either way. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Reins Runtime Security is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Reins Runtime Security: Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), China AI Compliance Audit (jnMetaCode/shellward, 140 stars), Hol Guard Protection (hashgraph-online/hol-guard, 845 stars) and Security Guide (jnMetaCode/shellward, 140 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
pegasi-ai (a GitHub organization) maintains it in pegasi-ai/reins, which has 392 GitHub stars. The repository was last updated on October 9, 2026.
Source: pegasi-ai/reins on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.