Governance-as-code for AI coding agents: author a policy once, enforce it on every agent (Claude, Copilot, Cursor, Codex) via git hooks, CI, and native controls.
https://pypi.org/project/chock/ ↗// readme
Teach your AI agent what not to do.
Open-source guardrails for AI coding agents: rules the agent reads, checks that run as it writes, and gates at commit and in CI.
chock · chock-catalog · chock.sh (launching soon)
Chock is a policy compiler. You write a policy once, and Chock compiles it into the strongest control each coding agent supports: a git hook that exits non-zero, a CI gate, or the agent’s own pre-tool hook. Every check is a deterministic script, with no model and no upload. Free and open source (Apache-2.0).
Application security for the code your agents write
Coding agents already ask before they run a shell command. What they do not check is the code they write: SQL injection in a Spring repository, an IAM grant on *, an MCP server at @latest, a bidi override hiding in a source file, a secret written into agent memory. Chock checks that code as the agent writes it, at commit and in CI.
| Area | What gets refused | Policy | Tier |
|---|---|---|---|
| Java & Kotlin | injection, XXE, SSRF, unsafe deserialization, weak crypto, dependencies below a known… |