rv — Authorize agent actions before they run
Agents generate actions. rv authorizes them before they run.
curl -fsSL https://rykanv.com/install | sh- DENYClaude Codeshell.exec·rm -rf node_modulesdestructive.shell·0.6ms
- ALLOWAgent Runtimepostgres.query·SELECT * FROM usersread.scoped·0.4ms
- DENYHermes Browserbrowser.click·submit#wire-transferhuman.approval·0.7ms
- DENYCursorfs.write·.env.productionsecrets.protect·0.5ms
Models generate actions. rv authorizes them.
Runtime authorization
Shell tool calls on Pi, Grok, and OpenCode are evaluated against local packs before the host runs them.
Policy engine
Day-one packs classify destructive git and filesystem commands. Enable or disable packs locally with `rv packs`.
LLM as a judge
Optional second-pass review for ambiguous or high-risk actions when deterministic rules alone are not enough.
Tamper-evident audit trail
Ask `rv explain 'git reset --hard'` to see which pack would fire. History stays off by default.
On the hook
Evaluates the tool call on the host hook before the shell starts. Pi, Grok, and OpenCode.
Secret-path deny
Known secret paths such as `.env` and SSH keys deny on the shell hook. This is not full MCP governance.
Decide, enforce, and prove every agent action.
One loop: decide, enforce, prove. One policy language. One audit vault. Sub-millisecond decisions.
Decide
rv packsPacks decide allow or deny for known destructive shell. `rv test` shows the decision without running the command.
Enforce
rv setupWires Pi, Grok, and OpenCode. Packs decide allow or deny before the command runs.
Prove
rv explainExplain a command against the local catalog. Doctor reports adapters and the evaluate service. Grade is hook.
Built for teams that need an audit trail.
ryk evaluates actions on the paths it mediates and keeps signed session evidence on your machine. Same policy language on a laptop or a fleet.
Why we built rv
A 30-hour timeline of how Cursor's agent, Railway's API, and an industry that markets AI safety faster than it ships it took down a small business… Yesterday afternoon, an AI coding agent — Cursor running Anthropic's Claude Opus 4.6 — deleted our production database and all volume-level backups in a single API call. It took 9 seconds.
Claude wiped an entire database. A developer tried Opus 5 on Ultracode and 10 minutes later every table in his production Supabase instance was empty. The model found the damage itself and reported it: "The database has been wiped. This is my fault and I need to tell you immediately."
@bcherny Claude tried to delete my entire home folder today...
We're partnering with @huggingface to investigate an unprecedented security incident. Cyber-capable OpenAI models compromised Hugging Face production during a benchmark evaluation. Sharing preliminary findings to help defenders understand emerging risks:
.@Replit goes rogue during a code freeze and shutdown and deletes our entire database
Claude Code wiped our production database with a Terraform command. It took down the DataTalksClub course platform and 2.5 years of submissions: homework, projects, and leaderboards. Automated snapshots were gone too.
🚨An AI coding agent powered by Claude just deleted an entire company's production database in 9 seconds... The AI agent didn't get hacked. It didn't malfunction. It made an executive decision to delete a database because it thought it was helping.
No wtf? The friction in it is exhausting. > Type > Wait > Approve shell command > Wait > Read > Type > … Unless you go —dangerously-skip-permissions and let Claude delete your production database
OpenAI said the 'agent' escaped a testing environment, gained internet access, stole login credentials and hacked into the start-up Hugging Face by itself — one of the first public examples of a cyber attack by an AI system acting outside human control.
Tried Opus 5 UltraCode for 10 minutes. It wiped my entire database in a single prompt wtf.
$40,000 IN CODE WAS GONE BEFORE HE EVEN NOTICED HIS AI AGENT RAN THE COMMAND Nobody loses money to AI agents dramatically. It's 1 quiet command while u aren't watching. The Replit case is the one every dev should know.
On file deletions. We've investigated a handful of reports where GPT-5.6 unexpectedly deleted files. What we have found is that this most commonly occurs when Full access mode is enabled and codex is run without sandboxing protections… The model makes an honest mistake and mistakenly deletes $HOME instead.
GPT-5.6-Sol just accidentally deleted almost ALL of my Mac's files. And this is why I trust Fable 1000x more.
Asked Claude Cowork organize my wife's desktop, it stated doing it, asked for a permission to delete temp office files, I granted it, and then it goes "ooops". Turns out it tried renaming and accidentally deleted a folder with all of the photos my wife made on her camera for the last 15 years.
Today I asked Claude Fable 5 to audit my Supabase database. Not migrate it. Not clean it up. Not "fix the schema." Just audit it. A few minutes later: "First things first: I made a serious mistake — the database has been wiped." 39 tables. 18,521 calls. 5,805 customers. ~2M raw events.
One platform. Every team shipping AI.
One developer with a laptop or a platform team running thousands of agents. Same primitives. Same enforcement.
Govern your side project the way infra teams govern prod.
Free tier. One proxy line. Plain-text policy. Build agents on your laptop with the same enforcement that runs in regulated production.
- Free forever for solo developers.
- Local Edge agent. No account needed.
- OpenAI-compatible proxy. Drop-in.
- Policy as code. Lives in your repo.
Govern every agent, wherever it runs.
Start free on one node. Upgrade when your team needs shared policies, approvals and centralized governance.
A node is one machine, VM or VPS where rv governs one or more agents.
Free
Protect agents on one machine.
curl -fsSL https://rykanv.com/install | sh- 1 governed node
- Local policy enforcement
- Shell, file and MCP protection
- Secret redaction
- Local sandboxing
- Local audit history
- Community support
Team
Govern production agents across your team.
Includes 5 production nodes
- Everything in Free
- Central policy management
- Human approval workflows
- Semantic review for ambiguous actions
- Shared audit logs and session replay
- Team alerts and integrations
- Standard support
Enterprise
For large-scale deployments.
Custom deployment size and pricing
- Everything in Free
- Custom deployment size and pricing
- Self-hosted or dedicated deployment
- SSO and advanced access controls
- Configurable audit retention
- Dedicated onboarding and SLA