OpenCode
Project plugin for native tool hooks. Headless tool enforcement is verified; see the setup guide for the tested scope.
Warden evaluates routed tool calls against deterministic rules before they execute. No model in the decision path. No cloud service to deploy.
npm install -g @stlw/warden-cliNode.js 22+MIT licensedView on npm ↗
trust: EXTERNALexternal → writeoutput quarantined · ledgeredDeterministicRules, not a second model call
Local-firstRun beside your agent
InspectableDecisions recorded in a hash-chained ledger
Explicit boundaryOnly calls routed through Warden are governed
Warden sits on the path between an agent and the tool call you choose to route through it. Policy decides what happens; the ledger keeps the evidence.
A supported hook, MCP proxy, or embedded gateway passes Warden a tool call with its relevant context.
tool + trust + environmentWarden matches the call to your local rules. Unmatched calls and evaluation failures deny by default.
warden.config.ymlAllow, deny, request human confirmation, or quarantine content according to the matching rule.
ALLOW · DENY · CONFIRM · QUARANTINEDecisions are recorded in a local, hash-chained ledger you can inspect with the CLI.
warden auditDifferent agents expose different enforcement points. Start with a path that routes the calls you need governed, and verify its current status before relying on it.
Read the agent capability matrixProject plugin for native tool hooks. Headless tool enforcement is verified; see the setup guide for the tested scope.
Route selected MCP tools through Warden. Native agent tools remain outside the proxy boundary.
Evaluate a policy directly in your application with @stlw/warden, without starting the MCP proxy.
Install the CLI to initialize policy and inspect decisions. For agent-specific routing, use the tested setup instructions in the repository.
Initialize a project policy, then inspect a decision before connecting an agent.
Read the full installation guide$ npm install -g @stlw/warden-cli
$ warden init
$ warden policy --tool write_file --trust EXTERNAL --environment productionWarden's project plugin integrates with OpenCode's native tool hooks. Follow the repository guide to add the plugin and run its verification steps.
Open the OpenCode setup guide# See the setup guide for the supported plugin layout
mkdir -p .opencode/plugins/lib
cp packages/opencode-plugin/warden-plugin.ts .opencode/plugins/
cp packages/opencode-plugin/lib/ledger.ts .opencode/plugins/lib/Start Warden as a local stdio proxy and configure an MCP client to use it. Only the tools routed through the proxy are in scope.
See client-specific configuration$ warden init
$ warden proxyUse the CLI to initialize policy, run a dry evaluation, inspect decisions, and check the local setup.
Browse CLI documentationwarden initwarden proxywarden auditwarden policywarden scanwarden supply-chainSetup and reference material live with the source, where integration limits and implementation details can stay current.
@stlw/warden on npmEmbed the TypeScript authorization runtime.↗
Security tools should be precise about their guarantees. Here are the boundaries that matter most.
No. Warden governs calls routed through a supported Warden integration. Native agent actions outside that path remain outside its control. Review the capability matrix for tested scope.
No. The policy evaluation path is deterministic. It matches tool-call context against configured rules; it does not ask a second model whether an action is safe.
MCP calls routed through Warden's proxy cannot reach their upstream when the proxy is unavailable. This does not extend to native agent tools that bypass Warden.
No hosted Warden service is required for the local CLI, plugin, or MCP proxy workflows described here. MCP upstreams configured by you may of course be remote services.
Use warden audit to inspect the local hash-chained ledger. See the manual for configuration and usage.
Install the CLI, initialize your project, and route only the calls you intend Warden to govern.