← All tools

shleder/vetto

AI Agent
Popularity 65 Updated AI & Agents

Daemon-less OS security boundary & sandbox for AI coding agents (Codex, Claude Code, Cursor, Aider)

githubauto-collected

Installation

A directly usable install command is not verified yet. Check the project documentation or releases.

<p align="center" <a href="https://github.com/shleder/vetto/actions"<img src="https://img.shields.io/github/actions/workflow/status/shleder/vetto/ci.yml?branch=main&label=CI&style=flat-square" alt="CI"</a <a href="https://github.com/shleder/vetto/releases/tag/v0.5.3"<img src="https://img.shields.io/badge/version-0.5.3-blue?style=flat-square" alt="Version"</a <a href="https://www.npmjs.com/package/@shledery/vetto"<img src="https://img.shields.io/badge/npm-v0.5.3-CB3837?logo=npm&logoColor=white&style=flat-square" alt="npm"</a <a href="https://crates.io/crates/vetto"<img src="https://img.shields.io/badge/crates.io-v0.5.3-orange?logo=rust&logoColor=white&style=flat-square" alt="crates.io"</a <a href="LICENSE"<img src="https://img.shields.io/badge/license-Apache--2.0-green?style=flat-square" alt="License"</a </p

<p align="center" <a href="README.md"<bEnglish</b</a | <a href="docs/README.ru.md"Русский</a | <a href="docs/README.zh.md"简体中文</a | <a href="docs/README.ja.md"日本語</a | <a href="docs/README.es.md"Español</a | <a href="docs/README.de.md"Deutsch</a </p

Rootless, daemon-less kernel-level sandbox and policy enforcement runtime for AI coding CLI agents (Claude Code, OpenAI Codex, Cursor, OpenCode, Aider, Antigravity, OMP, ZCode, Kimi, Grok). Vetto injects immutable security boundaries directly between fork() and execve() with sub-4ms startup latency and zero Docker overhead.

---

Interactive TUI Mission Control

Launch the interactive Mission Control dashboard by simply running vetto in any interactive terminal:

vetto

Features live AI agent fleet detection, one-touch PATH-shim toggling, real-time VFS secret matrix auditing, kernel preflight diagnostics, zero-loss snapshot rollbacks, real-time policy interception streaming ([5: SECURITY STREAM]), and multi-agent swarm orchestration ([6: FLEET SWARM]).

For keybindings, detailed views, and theme configuration, see the Mission Control TUI Guide.

---

Proof Before Promises

Autonomous agents execute non-deterministic code. Untrusted dependency hooks, prompt injections, or hallucinated bash commands can compromise host credentials (~/.ssh, ~/.aws, .env) or leak runaway background servers. Under Vetto, unauthorized system calls are blocked deterministically:

> Reading ~/.ssh/id_rsa...         BLOCKED (secret mask, EACCES)
> Opening raw socket...             BLOCKED (net namespace, EAFNOSUPPORT)
> Spawning detached daemon...       TERMINATED (process tree extinction, exit 125)

Fail-Closed Contract (Exit 125)

If an isolation boundary is violated or if required kernel primitives cannot be enforced, execution is terminated immediately with exit code 125. Descendant process trees and orphaned subprocesses are reaped synchronously via cgroups v2 cgroup.kill. Guarantees that the underlying OS cannot enforce are reported as unsupported—security is never silently downgraded.

---

Quick Start

1. Installation