Put policy between your agent and its tools.

Warden evaluates routed tool calls against deterministic rules before they execute. No model in the decision path. No cloud service to deploy.

npm install -g @stlw/warden-cli

Node.js 22+MIT licensedView on npm ↗

A routed call, under policy Illustrative trace
REQUESTwrite_filetrust: EXTERNAL
MATCHED RULEquarantine-externalexternal → write
DECISION QUARANTINEoutput quarantined · ledgered
Policy evaluation is deterministicSHA-256 ledger entry

DeterministicRules, not a second model call

Local-firstRun beside your agent

InspectableDecisions recorded in a hash-chained ledger

Explicit boundaryOnly calls routed through Warden are governed

A clear rule. A recorded decision.

Warden sits on the path between an agent and the tool call you choose to route through it. Policy decides what happens; the ledger keeps the evidence.

  1. Receive the call

    A supported hook, MCP proxy, or embedded gateway passes Warden a tool call with its relevant context.

    tool + trust + environment
  2. Evaluate policy

    Warden matches the call to your local rules. Unmatched calls and evaluation failures deny by default.

    warden.config.yml
  3. Apply the outcome

    Allow, deny, request human confirmation, or quarantine content according to the matching rule.

    ALLOW · DENY · CONFIRM · QUARANTINE
  4. Keep an audit trail

    Decisions are recorded in a local, hash-chained ledger you can inspect with the CLI.

    warden audit

Choose where Warden sits.

Different agents expose different enforcement points. Start with a path that routes the calls you need governed, and verify its current status before relying on it.

Read the agent capability matrix
01 / Native plugin

OpenCode

Project plugin for native tool hooks. Headless tool enforcement is verified; see the setup guide for the tested scope.

Verified
02 / MCP proxy

Claude Code, Codex CLI, Cursor, Windsurf

Route selected MCP tools through Warden. Native agent tools remain outside the proxy boundary.

MCP tools only
03 / TypeScript

Embed the authorization runtime

Evaluate a policy directly in your application with @stlw/warden, without starting the MCP proxy.

↗
Know the boundary.Warden cannot intercept native agent actions that do not pass through a supported Warden integration. Check the current capability matrix before relying on an integration for enforcement.

Start with the path that fits.

Install the CLI to initialize policy and inspect decisions. For agent-specific routing, use the tested setup instructions in the repository.

Install the CLI

Initialize a project policy, then inspect a decision before connecting an agent.

Read the full installation guide
Terminal
$ npm install -g @stlw/warden-cli
$ warden init
$ warden policy --tool write_file --trust EXTERNAL --environment production

A small command surface. A clear record.

Use the CLI to initialize policy, run a dry evaluation, inspect decisions, and check the local setup.

Browse CLI documentation
warden init
Create a project policy and runtime state.
warden proxy
Start the local stdio MCP policy proxy.
warden audit
Inspect ledger entries and chain integrity.
warden policy
Dry-run a policy decision for a tool call.
warden scan
Scan text for prompt-injection patterns.
warden supply-chain
Check package integrity against pinned hashes.

Know what Warden does—and where it stops.

Security tools should be precise about their guarantees. Here are the boundaries that matter most.

Does Warden control every action my agent can take?

No. Warden governs calls routed through a supported Warden integration. Native agent actions outside that path remain outside its control. Review the capability matrix for tested scope.

Does a language model make the policy decision?

No. The policy evaluation path is deterministic. It matches tool-call context against configured rules; it does not ask a second model whether an action is safe.

What happens if the MCP proxy is unavailable?

MCP calls routed through Warden's proxy cannot reach their upstream when the proxy is unavailable. This does not extend to native agent tools that bypass Warden.

Does Warden require a hosted service?

No hosted Warden service is required for the local CLI, plugin, or MCP proxy workflows described here. MCP upstreams configured by you may of course be remote services.

Where can I inspect decisions?

Use warden audit to inspect the local hash-chained ledger. See the manual for configuration and usage.

Make the policy path visible.

Install the CLI, initialize your project, and route only the calls you intend Warden to govern.