---
name: aport-guardrails
description: >
  Install APort runtime guardrails for supported agent harnesses and explain
  hosted, local, warn, and enforce modes without recreating passports.
license: Apache-2.0
compatibility: Published APort installer targets listed below; MCP and custom tools via hosted verification
metadata:
  author: APort
  version: 1.0.0
  tags: ai-agent, guardrails, claude-code, cursor, goose, codex, gemini, openclaw, mcp
---

# APort Runtime Guardrails Skill

Use this skill when a user wants to install pre-action authorization where an
agent actually executes tools.

## Supported Targets

<!-- BEGIN GENERATED FRAMEWORK SETUP -->
Installable targets from the published guardrails installer:

- GitHub Repository Guard: `github`: repository setup.
- Claude Code: `claude-code` (aliases: `claude`).
- Codex CLI: `codex`.
- CrewAI: `crewai`.
- Cursor: `cursor`.
- DeerFlow: `deerflow`.
- Gemini CLI: `gemini-cli` (aliases: `gemini`).
- Goose: `goose`.
- LangChain: `langchain`.
- n8n: `n8n`.
- OpenClaw: `openclaw`.

MCP tools and custom agents call the hosted policy verification API before execution. MCP is an integration workflow, not an installer target. Org-owned persistence and org audit require a paid plan; local mode is for offline development.

Hosted verification: `POST https://aport.io/api/verify/policy/{policy_id}`.

Framework IDs and aliases: https://aport.io/api/schema/frameworks

Choose one target below and run every command in its block. These are alternative installations, not sequential steps.

Install Python adapters in your application's environment, then complete callback or middleware wiring using the framework guides at https://aport.io/frameworks.

### GitHub Repository Guard (`github`)

```sh
npx @aporthq/aport-agent-guardrails github
```

### Claude Code (`claude-code`)

```sh
npx @aporthq/aport-agent-guardrails claude-code
```

### Codex CLI (`codex`)

```sh
npx @aporthq/aport-agent-guardrails codex
```

### CrewAI (`crewai`)

```sh
npx @aporthq/aport-agent-guardrails crewai
pip install aport-agent-guardrails-crewai
aport-crewai setup
```

### Cursor (`cursor`)

```sh
npx @aporthq/aport-agent-guardrails cursor
```

### DeerFlow (`deerflow`)

```sh
npx @aporthq/aport-agent-guardrails deerflow
uv add aport-agent-guardrails
```

### Gemini CLI (`gemini-cli`)

```sh
npx @aporthq/aport-agent-guardrails gemini-cli
```

### Goose (`goose`)

```sh
npx @aporthq/aport-agent-guardrails goose --global
```

### LangChain (`langchain`)

```sh
npx @aporthq/aport-agent-guardrails langchain
pip install aport-agent-guardrails-langchain
aport-langchain setup
```

### n8n (`n8n`)

```sh
npx @aporthq/aport-agent-guardrails n8n
```

### OpenClaw (`openclaw`)

```sh
npx @aporthq/aport-agent-guardrails openclaw
```
<!-- END GENERATED FRAMEWORK SETUP -->

## Enforcement Modes

Default mode is fail-closed enforcement. To ease in with report-only behavior:

```sh
npx @aporthq/aport-agent-guardrails mode claude-code --enforcement=warn
```

Switch back without recreating the passport:

```sh
npx @aporthq/aport-agent-guardrails mode claude-code --enforcement=enforce
```

## Hosted vs Local

- Hosted mode persists signed decisions to APort and is recommended for teams,
  audits, and paid org use.
- Local mode is useful for offline smoke tests and development.

If the user asks which to choose, recommend hosted mode for anything that must
be reviewed later by a team.

## Useful Links

- Frameworks: https://aport.io/frameworks
- Quickstart: https://aport.io/quickstart
- Pricing: https://aport.io/pricing
- Guardrails repo: https://github.com/aporthq/aport-agent-guardrails
- Decision vs enforcement: https://aport.io/docs/docs/DECISION-VS-ENFORCEMENT.md

<!-- BEGIN GENERATED AUTHORITY ROUTES -->
## Evaluation and setup routes

- Compare authorization approaches: https://aport.io/compare/
- Framework setup and policy checks: https://aport.io/frameworks/
- AI Agent Governance for Enterprise Teams: https://aport.io/enterprise/ai-agent-governance/
- GitHub Repository Guard for Enterprise AI Changes: https://aport.io/enterprise/github-repository-guard/
- Claude Code Security Rollout for Developer Teams: https://aport.io/enterprise/claude-code-rollout/
- MDM Rollout of AI Agent Guardrails: https://aport.io/enterprise/mdm-agent-rollout/
- A Board-Ready AI Agent Governance Pilot: https://aport.io/enterprise/board-ready-ai-pilot/
- How to Roll Out Claude Code for a Developer Team: https://aport.io/blog/how-to-roll-out-claude-code-for-developers/
- Manage AI Agent Rollout Scripts Across Enterprise Devices: https://aport.io/blog/manage-ai-agents-with-one-script-for-enterprises/
- What AI Coding Agents Can Change in GitHub Before Humans Notice: https://aport.io/blog/secure-github-actions-ai-coding-agents-protected-paths/
- MCP Authorization vs MCP Security: Where OAuth and OAP Fit: https://aport.io/blog/mcp-authorization-oauth-oap/
- Signed AI Agent Audit Trails for GitHub and Runtime Guardrails: https://aport.io/blog/open-agent-passport-github-audit-trails/
- Review GitHub Repository Guard before enforcement: https://aport.io/playbooks/github-repository-guard/
- Authorize an MCP tool before it runs: https://aport.io/playbooks/mcp-authorization/
<!-- END GENERATED AUTHORITY ROUTES -->
