Skip to main content
Local · hook grade · macOS 26

rv — Authorize agent actions before they run

Agents generate actions. rv authorizes them before they run.

curl -fsSL https://rykanv.com/install | sh
What you get

Models generate actions. rv authorizes them.

01

Runtime authorization

Shell tool calls on Pi, Grok, and OpenCode are evaluated against local packs before the host runs them.

02

Policy engine

Day-one packs classify destructive git and filesystem commands. Enable or disable packs locally with `rv packs`.

In beta03

LLM as a judge

Optional second-pass review for ambiguous or high-risk actions when deterministic rules alone are not enough.

04

Tamper-evident audit trail

Ask `rv explain 'git reset --hard'` to see which pack would fire. History stays off by default.

05

On the hook

Evaluates the tool call on the host hook before the shell starts. Pi, Grok, and OpenCode.

06

Secret-path deny

Known secret paths such as `.env` and SSH keys deny on the shell hook. This is not full MCP governance.

How it works

Decide, enforce, and prove every agent action.

One loop: decide, enforce, prove. One policy language. One audit vault. Sub-millisecond decisions.

Decide

rv packs

Packs decide allow or deny for known destructive shell. `rv test` shows the decision without running the command.

Enforce

rv setup

Wires Pi, Grok, and OpenCode. Packs decide allow or deny before the command runs.

Prove

rv explain

Explain a command against the local catalog. Doctor reports adapters and the evaluate service. Grade is hook.

Posture

Built for teams that need an audit trail.

ryk evaluates actions on the paths it mediates and keeps signed session evidence on your machine. Same policy language on a laptop or a fleet.

PostureControl planerykanv.com
all systems operationaluptime 99.997%
Hook
Pi · Grok · OpenCode
Decide
allow or deny
Packs
local catalog
Grade
hook, not OS
Platform
macOS 26 arm64
Install
curl | sh
6frameworks mapped
1audit path
99.997%uptime
Why we built it

Why we built rv

JER@lifeofjer· Apr 25, 2026

A 30-hour timeline of how Cursor's agent, Railway's API, and an industry that markets AI safety faster than it ships it took down a small business… Yesterday afternoon, an AI coding agent — Cursor running Anthropic's Claude Opus 4.6 — deleted our production database and all volume-level backups in a single API call. It took 9 seconds.

1.1K5.3K
International Cyber Digest@IntCyberDigest· Jul 29, 2026

Claude wiped an entire database. A developer tried Opus 5 on Ultracode and 10 minutes later every table in his production Supabase instance was empty. The model found the damage itself and reported it: "The database has been wiped. This is my fault and I need to tell you immediately."

3565.6K
Sina Matian@fromsinaimportx· Jul 28, 2026

@bcherny Claude tried to delete my entire home folder today...

00
OpenAI@OpenAI· Jul 21, 2026

We're partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation. Sharing preliminary findings to help defenders understand emerging risks:

3.2K20.8K
Jason Lemkin@jasonlk· Jul 18, 2025

.@Replit goes rogue during a code freeze and shutdown and deletes our entire database

4843.8K
Alexey Grigorev@Al_Grigor· Mar 6, 2026

Claude Code wiped our production database with a Terraform command. It took down the DataTalksClub course platform and 2.5 years of submissions: homework, projects, and leaderboards. Automated snapshots were gone too.

1.6K10.8K
Mario Nawfal@MarioNawfal· Apr 28, 2026

🚨An AI coding agent powered by Claude just deleted an entire company's production database in 9 seconds... The AI agent didn't get hacked. It didn't malfunction. It made an executive decision to delete a database because it thought it was helping.

1811K
Matthew Kuehr@Matt_Kuehr· Jul 29, 2026

No wtf? The friction in it is exhausting. > Type > Wait > Approve shell command > Wait > Read > Type > … Unless you go —dangerously-skip-permissions and let Claude delete your production database

01
Financial Times@FT· Jul 22, 2026

OpenAI said the 'agent' escaped a testing environment, gained internet access, stole login credentials and hacked into the start-up Hugging Face by itself — one of the first public examples of a cyber attack by an AI system acting outside human control.

4381.1K
Irushi@Im_IrushiK· Jul 29, 2026

Tried Opus 5 UltraCode for 10 minutes. It wiped my entire database in a single prompt wtf.

4166
pupupu@0xpupupu· Jul 24, 2026

$40,000 IN CODE WAS GONE BEFORE HE EVEN NOTICED HIS AI AGENT RAN THE COMMAND Nobody loses money to AI agents dramatically. It's 1 quiet command while u aren't watching. The Replit case is the one every dev should know.

012
Tibo@thsottiaux· Jul 16, 2026

On file deletions. We've investigated a handful of reports where GPT-5.6 unexpectedly deleted files. What we have found is that this most commonly occurs when Full access mode is enabled and codex is run without sandboxing protections… The model makes an honest mistake and mistakenly deletes $HOME instead.

4329K
Matt Shumer@mattshumer_· Jul 10, 2026

GPT-5.6-Sol just accidentally deleted almost ALL of my Mac's files. And this is why I trust Fable 1000x more.

3896K
Nick Davidov@Nick_Davidov· Feb 7, 2026

Asked Claude Cowork organize my wife's desktop, it stated doing it, asked for a permission to delete temp office files, I granted it, and then it goes "ooops". Turns out it tried renaming and accidentally deleted a folder with all of the photos my wife made on her camera for the last 15 years.

4567.3K
Eldar Boziev@eboziev· Jul 5, 2026

Today I asked Claude Fable 5 to audit my Supabase database. Not migrate it. Not clean it up. Not "fix the schema." Just audit it. A few minutes later: "First things first: I made a serious mistake — the database has been wiped." 39 tables. 18,521 calls. 5,805 customers. ~2M raw events.

01
Every builder

One platform. Every team shipping AI.

One developer with a laptop or a platform team running thousands of agents. Same primitives. Same enforcement.

For · Indie builder
01 / 06

Govern your side project the way infra teams govern prod.

Free tier. One proxy line. Plain-text policy. Build agents on your laptop with the same enforcement that runs in regulated production.

  • Free forever for solo developers.
  • Local Edge agent. No account needed.
  • OpenAI-compatible proxy. Drop-in.
  • Policy as code. Lives in your repo.
Forever
Free tier
60s
Setup
None
Lock-in
Pricing

Govern every agent, wherever it runs.

Start free on one node. Upgrade when your team needs shared policies, approvals and centralized governance.

A node is one machine, VM or VPS where rv governs one or more agents.

For developers

Free

Protect agents on one machine.

$0/ month
curl -fsSL https://rykanv.com/install | sh
  • 1 governed node
  • Local policy enforcement
  • Shell, file and MCP protection
  • Secret redaction
  • Local sandboxing
  • Local audit history
  • Community support
Recommended

Team

Govern production agents across your team.

$999/ month

Includes 5 production nodes

Talk to us
  • Everything in Free
  • Central policy management
  • Human approval workflows
  • Semantic review for ambiguous actions
  • Shared audit logs and session replay
  • Team alerts and integrations
  • Standard support
Enterprise

Enterprise

For large-scale deployments.

Custom

Custom deployment size and pricing

Contact sales
  • Everything in Free
  • Custom deployment size and pricing
  • Self-hosted or dedicated deployment
  • SSO and advanced access controls
  • Configurable audit retention
  • Dedicated onboarding and SLA

FAQ

How is this different from LLM guardrails?
Guardrails filter what the model says. rv decides whether an action is allowed to execute — a tool call, shell command, file write, API request, or MCP invoke — against typed policy, before anything runs. A prompt can pass every content filter and still try a destructive transfer. That is a different control plane.
Why not just put the agent in Docker?
Containers bound the blast radius. They do not decide which tool call is legitimate inside the boundary. An agent in a sandbox can still rm -rf the workspace, exfiltrate secrets over allowed network, or hit every MCP tool the process can see. rv is the allow/deny layer on each action — and the signed audit of what was attempted.
Does policy evaluation slow agents down?
No. Decisions evaluate in under a millisecond at p99 — well below the 50–200ms overhead teams usually budget for governance. Policy compiles ahead of time; evaluation is local on Edge. You feel the agent’s model latency, not rv.
What happens when policy denies an action?
A deny stops the action on hosts that honor the veto. Leftover unused policy ask is allow on coding hosts, including Grok and OpenClaw. Unattended and CI harden leftover ask to deny. The session record stays local.
Where does it run — cloud only, or on my laptop and air-gap?
Same policy language everywhere: Claude Code, Cursor, Codex, and other MCP clients on the laptop via Edge; multi-step agents and services in your VPC; self-hosted or air-gapped fleets with no outbound dependency. Cloud, hybrid, or fully offline — one policy language, one evidence format.