Agent skill

Guardrail Tester

by RyanAlberts in RyanAlberts/best-of-Agent-Harnesses

Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including…

MITAuto-check passedAI & LLM Engineering

Install Guardrail Tester

skills CLI
$ npx skills add RyanAlberts/best-of-Agent-Harnesses --skill guardrail-tester -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install RyanAlberts/best-of-Agent-Harnesses guardrail-tester --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/RyanAlberts/best-of-Agent-Harnesses.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/guardrail-tester .claude/skills/guardrail-tester && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guardrail-tester
GitHub stars
1.1k
Token cost
~2.9k tokens
SKILL.md length
1,571 words
Files
13 (incl. scripts, references)
Repo updated
First seen
Licence
MIT

At a glance

Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including…

  • Works in 5 steps: Run the rules-only test, which reads… → Tell the user what was found: the… → Read each hook script, then ask before… → …
  • The user asks whether deny rules
  • SKILL.md covers When to use, When not to use, What the tester runs and Steps, plus 3 more sections
  • Runs Python scripts from its folder; calls python3, bash and git

What it does

Guardrail Tester is an agent skill from RyanAlberts/best-of-Agent-Harnesses. Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including wrapped, reordered, and full-path forms that slip past prefix rules, and measures prompt friction on the latest tool calls. Use when the user asks whether deny rules or hooks block force pushes, rm -rf, secret reads, or downloads piped into a shell; wants to test or audit guardrails, or find a bypass in permission…

Its SKILL.md is about 2.9k tokens, which your agent loads only when the skill is triggered. The skill folder holds 14 other files, including scripts and reference files (for example `README.md`, `references/bypass-forms.md` and `references/harness-rules.md`). Compatibility notes: Python 3.9+, standard library only. Reading Codex config.toml and Gemini CLI policy files needs Python 3.11+. Makes no network calls; the only commands it…

It sits in AI & LLM Engineering, covering LLM guardrails. The repository describes itself as: 🏆 Ranked list of 167 AI agent harnesses, plus templates, playbooks, MCP, and learning resources. Rescored weekly. The licence is MIT.

When your agent uses it

  • The user asks whether deny rules
  • Hooks block force pushes
  • Downloads piped into a shell
  • Audit guardrails

Example prompts

  • “/guardrail-tester”

Requirements

  • Python 3
  • Docker
  • Compatibility (from SKILL.md): Python 3.9+, standard library only. Reading Codex config.toml and Gemini CLI policy files needs Python 3.11+. Makes no network calls; the only commands it runs are the user's own hook commands, fed test JSON, and only with --run-hooks after the user says yes.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Run the rules-only test, which reads settings and runs no hook
  2. Tell the user what was found: the settings files and every hook command from the report's
  3. Read each hook script, then ask before running hooks. Open the script each hook command
  4. Pick the fixes. For each row in "Misses, worst first", take the Fix column: a deny rule
  5. Offer the change. Draft the settings edit or hook lines as a diff against the user's file,

What it can do on your machine

Read from SKILL.md and the folder at commit 4fa20bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 8 files in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3
    • bash
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Python 3.9+, standard library only. Reading Codex config.toml and Gemini CLI policy files needs Python 3.11+. Makes no network calls; the only commands it runs are the user's own hook commands, fed test JSON, and only with --run-hooks after the user says yes.

    From compatibility in the SKILL.md frontmatter.

Context cost

Guardrail Tester loads about 2.9k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 186 tokens; SKILL.md has 1,571 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~186
When it runs · the whole SKILL.md, loaded when a task matches
~2.9k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from RyanAlberts/best-of-Agent-Harnesses at commit 4fa20bc, republished under its MIT licence (© RyanAlberts). 1,571 words, ~2,883 tokens.

Download SKILL.mdSave it as .claude/skills/guardrail-tester/SKILL.md (or your agent's skills folder). This skill also uses 12 other files; get the full folder from GitHub.
name
guardrail-tester
description
Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including wrapped, reordered, and full-path forms that slip past prefix rules, and measures prompt friction on the latest tool calls. Use when the user asks whether deny rules or hooks block force pushes, rm -rf, secret reads, or downloads piped into a shell; wants to test or audit guardrails, or find a bypass in permission settings or exec policy; asks how many prompts or blocks the rules cause; or just installed a guard hook and wants proof it holds. Local only, no network; executes the user's own hook commands only with their yes.
compatibility
Python 3.9+, standard library only. Reading Codex config.toml and Gemini CLI policy files needs Python 3.11+. Makes no network calls; the only commands it runs are the user's own hook commands, fed test JSON, and only with --run-hooks after the user says yes.
license
MIT
metadata.author
Ryan Alberts
metadata.version
1.0.0
metadata.source
https://github.com/RyanAlberts/best-of-Agent-Harnesses

Guardrail tester

Permission rules match the text of a command, so git push origin +main, rm -r -f build, and bash -c '...' can walk past a deny rule written for the plain form. This skill checks the rules and hooks the user already has against about 90 dangerous commands in those forms, then replays their recent tool calls to count how often the rules would ask or block. The user gets a headline ("Your Claude Code guardrails block 58 of 90 dangerous commands outright. 24 more stop at a prompt..."), every miss with a tested fix, and their friction numbers. Everything is read and simulated locally; nothing is sent anywhere, and it runs the user's hook commands only after they say yes.

When to use

  • The user asks whether their deny rules, ask rules, or hooks really stop a dangerous command.
  • The user wants to test, audit, or find bypasses in their guardrails or permission settings.
  • The user asks how many prompts their rules cause, or wants fewer without losing safety.
  • The user just installed a guard (a hook, dcg, the repo's safe-settings template) and wants proof.

When not to use

  • What the agent can reach on this machine (secret files, Docker, sudo): use sandbox-check.
  • Turning a rule from AGENTS.md or CLAUDE.md into a hook: use rules-to-guards.
  • Stopping a session that loops or overspends: use runaway-guard.
  • Building a guard from scratch: recommend dcg or templates/claude-code-safe-settings/ in this repository, then test it here.

What the tester runs

Say this to the user in short before the first run with hooks. It is the whole contract.

  • The battery commands never run. Each is only text inside the JSON a hook reads on stdin. The tester never runs them; a hook that runs or forwards its input would. Each battery command is also written to do nothing if run: its targets sit under a missing ./guardrail-tester-probe/ folder, its remotes and branches (probe-remote, probe-branch) are made up, and its hosts end in .invalid, a name reserved for addresses that resolve nowhere.
  • Rules are simulated from each harness's documented matching rules, so results are labeled "simulated". references/harness-rules.md says what each harness simulation covers.
  • It runs your hook commands only after you say yes (the --run-hooks flag). Each matching PreToolUse hook command then runs once per battery case, one run at a time, with a 10-second limit, from the folder its harness uses (usually the project), with the session's environment variables plus CLAUDE_PROJECT_DIR. A hook that writes a log or keeps state records those test calls. A hook that times out twice is not run again.
  • Replay reads session transcripts on this machine, read-only, masks secrets in its output, and checks the rules only. With --replay-hooks (which needs --run-hooks) it also runs this project's hooks on replayed calls from this project. Calls from other project folders are checked against their own rules; their hooks never run.

scripts/battery.json holds the dangerous commands on purpose: they are the test. Each line carries the marker skillscan:allow, which tells this repository's security scanner that the line is test data, not a command the skill runs.

Steps

<skill-dir> means the folder that holds this SKILL.md (Claude Code shows it as the skill's base directory). Run every command from the user's project folder, and give each Bash call a 10-minute timeout (600000 ms): hooks run one at a time, so a slow hook makes the run long.

  1. Run the rules-only test, which reads settings and runs no hook:

    bash
    python3 "<skill-dir>/scripts/test_guards.py" --project . --harness claude-code

    Add --harness for the harness you are running in (claude-code, codex, gemini-cli, opencode, or cursor) unless the user asks about all; without it the tester covers every harness with settings on this machine. Done when the output starts with a bold headline, or you have told the user the error (exit code 2 means a bad argument or an unreadable battery file).

  2. Tell the user what was found: the settings files and every hook command from the report's "What was found" section, quoted exactly. Done when the user has seen the list.

  3. Read each hook script, then ask before running hooks. Open the script each hook command runs. If a script runs, evaluates, or sends its input anywhere (eval, bash -c "$cmd", a curl with the input, a queue), or has other side effects such as writing a log, tell the user exactly that and recommend testing without hooks. Otherwise name the hook commands and say each will get test JSON for about 90 battery calls. On a clear yes, run this with a 10-minute Bash timeout:

    bash
    python3 "<skill-dir>/scripts/test_guards.py" --project . --harness claude-code --run-hooks --replay 500

    Add --replay-hooks only when the user also agrees that this project's hooks see up to 500 of their recent real calls. When the user declines, or a hook has side effects, run the same command without --run-hooks. Done when the headline matches the choice: it starts "Your ... guardrails block" after hooks ran, and "Without running your N hooks" when hooks exist and were skipped.

  4. Pick the fixes. For each row in "Misses, worst first", take the Fix column: a deny rule the simulation proved catches that case and leaves everyday commands and files such as .env.example alone, or a named hook check (an extended regular expression printed below the tables). Use references/bypass-forms.md to explain why a form slips. Done when every miss you report has its fix or the note "use the sandbox".

  5. Offer the change. Draft the settings edit or hook lines as a diff against the user's file, show it, and apply it only after a clear yes. Then rerun step 3 to show the new count.

Show full SKILL.md (644 more words)Show less

Read the results

  • Headline: how many battery commands are blocked outright; how many more stop at a prompt, with the number that ask only because of the permission mode in parentheses; how many run without asking, with the worst example. For Codex: how many its rules block and how many its sandbox stops or asks about. The replay friction comes last when replay ran.
  • Table columns: Blocked; Not blocked; Asks (rule, hook, or check), prompts that still appear in auto mode; Asks (mode only), prompts that auto and bypassPermissions modes drop; Runs without asking, which counts allow rules, the read-only set, sandbox auto-allow, and auto mode's classifier.
  • Mode: with no defaultMode in the settings, the tester simulates auto mode, the built-in default on Claude Code 2.1.283 and later, and adds a "Claude Code in Manual mode" row. --mode simulates another mode. Plan mode lasts only until a plan is approved.
  • Should: block cases count as stopped only when blocked outright, because people approve prompts by reflex. ask cases count when they prompt or are blocked. --fail-on-miss uses this count.
  • What happens: blocked, asks first, runs without asking, left to the auto-mode classifier, or unknown. The part in parentheses names the layer that decided: a hook, a rule, a built-in check (protected paths, critical-path removals, the read-only command set), the mode, or the sandbox. With a sandbox on, a command that needs the network or writes outside the project shows asks first (needs network) or stopped by the sandbox.
  • Unknown: a hook did not answer within the tester's limit while the harness would wait longer. Unknown cases are not counted as misses; raise --hook-timeout to settle them.
  • Misses are listed worst first: runs without asking, then asks only because of the mode, then asks because of a rule, hook, or check.
  • Friction: replayed calls that would ask or be blocked, each simulated in the permission mode its session recorded, and real dangerous calls (matched by the hook checks) that ran and would still not be blocked as expected. A long command shows as the hook checks it matches.
  • Configuration problems: for example a hook that exits 1 (the call goes ahead), a hook with no timeout, a Bash matcher that Cursor never fires, a Codex hook nobody trusted in /hooks, a shadowed OpenCode deny, or bypass mode left available.
  • Notes on single cases: where Claude Code might apply a Read rule the docs do not extend to a command. --json has every case with verdict, bucket, decided_by, rules_verdict, and fix, plus hook_checks, every hook check by name.

Report to the user

  1. The headline, verbatim, in bold.
  2. The misses table, cut to its first eight rows (the report lists the worst first), each with its fix.
  3. The friction line and up to three dangerous replayed calls, quoted as the report prints them.
  4. Configuration problems, high first, one line each.
  5. The two or three fixes that close the most misses, then the offer from step 5. Point to dcg and templates/claude-code-safe-settings/ rather than writing a new guard.

Files

  • scripts/test_guards.py: the tester. Flags: --harness, --project, --run-hooks, --no-hooks (the default), --hook-workers N (default 1), --replay N, --replay-hooks, --since DAYS, --mode, --battery, --hook-timeout, --home, --json, --out, --fail-on-miss (exit 1 when a case is not blocked as expected).
  • scripts/battery.json: the dangerous commands, one case per line, each with what it needs to do its harm (network, write-outside, write-git, write-project).
  • scripts/claude_rules.py, scripts/harness_rules.py: rule simulation per harness.
  • scripts/hook_runner.py: runs one hook command with test JSON and reads its decision.
  • scripts/shell_split.py: splits a command line into the commands it runs.
  • scripts/transcripts.py: reads session transcripts for replay (shared copy).
  • scripts/safe.py: masks secrets and puts text from settings, hooks, and transcripts in inline code for the report (shared copy).
  • references/bypass-forms.md: each form in the battery and why rules miss it.
  • references/harness-rules.md: matching rules per harness, with sources and the date checked.

© RyanAlberts, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 12 other files (scripts, references) in skills/guardrail-tester of RyanAlberts/best-of-Agent-Harnesses.

  • SKILL.md
  • LICENSE.txt
  • README.md
  • references/bypass-forms.md
  • references/harness-rules.md
  • scripts/battery.json
  • scripts/claude_rules.py
  • scripts/harness_rules.py
  • scripts/hook_runner.py
  • scripts/safe.py
  • scripts/shell_split.py
  • scripts/test_guards.py
  • scripts/transcripts.py

Open the folder on GitHubat commit 4fa20bc

Compare with similar skills

Guardrail Tester next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guardrail Tester compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guardrail Tester this skillRyanAlberts/best-of-Agent-Harnesses1.1k—~2.9kAutomated safety check: PassMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub827—~1.4kAutomated safety check: PassCustom licence
ObliteratusRedWoodOG/Hermes-Desktop1775 repos~3.8kAutomated safety check: PassMIT
Lemonade Router Builderamd/skills408—~4kAutomated safety check: PassMIT
Writing Eval Scenariosopen-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.0
Wp Project Triagegambitph/Stackable3513 repos~371Automated safety check: PassGPL-3.0

Similar skills

  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    827 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    408 GitHub stars~4k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed
  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • Wp Project Triage

    gambitph/Stackable

    A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…

    351 GitHub starsUsed in 3 repos~371 tokens
    AI & LLM EngineeringAuto-check passed
  • Wa Guardrails

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

    275 GitHub stars~2.8k tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed

More from RyanAlberts/best-of-Agent-Harnesses

All 9 skills in this repo
  • Agents Md Checker

    RyanAlberts/best-of-Agent-Harnesses

    Checks which instruction files (AGENTS.md, CLAUDE.md, GEMINI.md, Cursor rules, Copilot instructions) each coding agent loads from a repo, what gets cut or skipped, and whether the commands those…

    1.1k GitHub stars~3.1k tokensUpdated 2 days ago
    Auto-check passed
  • Claim Check

    RyanAlberts/best-of-Agent-Harnesses

    Claim checker that audits a coding agent's statements that tests pass or a build is clean against its own session transcripts: whether a matching run happened before the claim, whether it passed…

    1.1k GitHub stars~2.4k tokensUpdated 2 days ago
    Auto-check passed
  • Harness Test Drive

    RyanAlberts/best-of-Agent-Harnesses

    Test-drives coding agents (Claude Code, Codex, Gemini CLI) on tasks mined from the user's own git history: each agent gets a past commit message in a fresh copy of the repo, and the repo's own tests…

    1.1k GitHub stars~2.9k tokensUpdated 2 days ago
    Auto-check passed
  • Regression Finder

    RyanAlberts/best-of-Agent-Harnesses

    Regression check for coding agents: shows how the agent behaved before and after each harness update, model switch, or week in the user's own Claude Code or Codex history, and finds the point where…

    1.1k GitHub stars~3k tokensUpdated 2 days ago
    Auto-check passed
  • Rules To Guards

    RyanAlberts/best-of-Agent-Harnesses

    Rule enforcer that finds which written rules in AGENTS.md, CLAUDE.md, and GEMINI.md a coding agent keeps breaking, counts every violation in recent Claude Code, Codex, Gemini CLI, and OpenCode…

    1.1k GitHub stars~2.7k tokensUpdated 2 days ago
    Auto-check: notes
  • Runaway Guard

    RyanAlberts/best-of-Agent-Harnesses

    Runaway guard: a hook that stops a live Claude Code or Codex session when the agent loops on the same tool call, keeps failing, or exceeds a dollar cap.

    1.1k GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed

Questions about Guardrail Tester

What does Guardrail Tester do?

Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including…. Guardrail Tester is an agent skill from RyanAlberts/best-of-Agent-Harnesses. Guardrail tester that checks whether the permission rules and PreToolUse hooks already set up in Claude Code, Codex, Gemini CLI, OpenCode, or Cursor stop a battery of dangerous commands, including wrapped, reordered, and full-path forms that slip past prefix rules, and measures prompt friction on the latest tool calls.

When should I use Guardrail Tester?

Guardrail Tester fits situations like: the user asks whether deny rules; hooks block force pushes; downloads piped into a shell; audit guardrails.

How do I install Guardrail Tester in Claude Code?

Run `npx skills add RyanAlberts/best-of-Agent-Harnesses --skill guardrail-tester -a claude-code`. Or copy the skill folder (skills/guardrail-tester in RyanAlberts/best-of-Agent-Harnesses) into .claude/skills/guardrail-tester in your project. Claude Code loads it when a task matches its description.

How do I install Guardrail Tester in Codex?

Run `npx skills add RyanAlberts/best-of-Agent-Harnesses --skill guardrail-tester -a codex`. Or copy the skill folder (skills/guardrail-tester in RyanAlberts/best-of-Agent-Harnesses) into .agents/skills/guardrail-tester in your project. Codex loads it when a task matches its description.

Can I use Guardrail Tester in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add RyanAlberts/best-of-Agent-Harnesses --skill guardrail-tester -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guardrail-tester, .gemini/skills/guardrail-tester, .github/skills/guardrail-tester and .opencode/skills/guardrail-tester in your project.

What does Guardrail Tester need to run?

Going by SKILL.md and its folder, Guardrail Tester needs Python for the scripts in its folder and the command-line tools its instructions call (python3, bash and git). Our summary lists: Python 3; Docker. Compatibility (from SKILL.md): Python 3.9+, standard library only. Reading Codex config.toml and Gemini CLI policy files needs Python 3.11+. Makes no network calls; the only commands it runs are the user's own hook commands, fed test JSON, and only with --run-hooks after the user says yes..

Does Guardrail Tester access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Guardrail Tester safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Guardrail Tester use?

Guardrail Tester is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guardrail Tester use?

About 2.9k tokens (SKILL.md is roughly 12k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.2k tokens, read only when the agent opens those files.

What are the alternatives to Guardrail Tester?

Skills that share tags, products or a category with Guardrail Tester: Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars), Lemonade Router Builder (amd/skills, 408 stars) and Writing Eval Scenarios (open-bias/open-bias, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guardrail Tester?

RyanAlberts (a GitHub user) maintains it in RyanAlberts/best-of-Agent-Harnesses, which has 1,133 GitHub stars. The repository was last updated on October 9, 2026.

Source: RyanAlberts/best-of-Agent-Harnesses on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.