Skip to content

feat: add HOL Guard before_tool adapter - #68

Open
kantorcodes wants to merge 7 commits into
KlaatAI:mainfrom
kantorcodes:distribution/hol-guard-before-tool
Open

kantorcodes wants to merge 7 commits into
KlaatAI:mainfrom
kantorcodes:distribution/hol-guard-before-tool

Conversation

@kantorcodes

Copy link
Copy Markdown

Summary

Adds an optional before_tool adapter for run_command that asks the installed HOL Guard runtime for a native pre-tool decision before Klaat Code executes the command.

The adapter keeps Klaat's existing hook semantics intact. It allows only an authoritative Guard allow result and fails closed when Guard is unavailable, not ready, malformed, asks for review, or blocks the command.

Safety

The full command is sent to Guard over stdin, not a process argument. The adapter also rejects allow-shaped responses when Guard reports unavailable or non-authoritative native review.

An isolated HOL Guard 3.4.2 runtime was used to verify both sides of the boundary: pwd and git status --short received authoritative allow decisions, while a destructive command received native_destructive_command and was blocked before a sentinel target could execute. Guard-unavailable behavior also blocks.

Validation

  • bun run typecheck
  • bun test
  • bun run bench:selfcheck
  • bun run build
  • focused adapter tests: 7/7 passing
  • isolated HOL Guard 3.4.2 authoritative allow/deny and unavailable-runtime proof

This does not change Klaat's default policy or require a Klaatu API change.

Affiliation: I maintain HOL Guard / Hashgraph Online.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant