1. Wire + report
Inits .kya/, writes MCP configs, opens the activity feed in your browser.
One command inits the project, wires local MCP, and opens a live activity report. Restart your host once. Unwrapped tools stay invisible on purpose.
npm i -g @shield-agent/kya@latest && kya start
Windows / any shell: same command. Details on /install.
KYA sees tools that go through wrap or MCP. It does not replace Claude Code, Cursor, Codex, Gemini, or Grok.
Not an island — add another host.
kya startInits .kya/, writes MCP configs, opens the activity feed in your browser.
Silent deny for never-events. No second approve prompt on the free path.
High-stakes writes land on the trail. Org Hold when you set KYA_HOLD=1.
Receipt rows show path / shell bin, not just a tool id.
Each coding host is a tentacle: Claude Code, Cursor, Codex, Gemini, Grok, and whatever you PR next. Merged recipes show up here and on /integrations.
Same inventory on this site, in the console, and in the public tree. Source is The-Pixel-Boys/shield-kya (mark in the header).
Named agents in a registry. Kill or revoke stops them. Parent and orphan are visible.
Tag work host=ide while authoring or host=runtime in production. Same policy both ways.
Every tool call is ALLOW, DENY, or REQUIRE_APPROVE. One enforcement point.
A person registering an agent follows the workspace mint mode. An agent creating another agent is itself a tool.
Read, Build, or Deploy. A live session can lose powers without killing the agent.
Agent passports and session claims are RS256 documents you can verify.
Hash-chained events: who ran, who approved, what was redacted.
Session risk can only make a verdict stricter. It cannot approve a submit.
npx @shield-agent/kya and
the public GitHub tree.
Offline demo first. Same PEP once a plane is wired.
Marketplace button, or start from npx and the public GitHub tree. Connect with OAuth/OIDC or MCP. No private Shield protocol.
Claude, ChatGPT, Grok, Gemini via MCP tools or OpenAPI Actions.
AWS, Azure, GCP. Subscribe with the cloud account you already bill through.
MCP, OAuth 2.1 / OIDC, OpenAPI, and marketplace entitlements.
Approvals, agent identity, sessions, and policy live in one tenant view. You manage that here, not inside a chat window.
Hold, Clear, Watch. Same lanes as the signed-in dashboard.
export.case · Approve · Rejecttool.invoke · Approve · RejectBlocked until APPROVED
High-stakes actions wait here. Risk can only make a decision stricter.
ops-workera1b2c3d4…Kill / revoke · JSON export
Who may act, which version is live, and a kill switch when you need it.
Complements can raise risk. Shield still decides what may run.
If policy needs approval, the action waits. The model can draft. You decide what actually runs.
Which agent, which version, which policy, what was redacted, who approved. You can inspect it later.
Sensitive fields are tokenized before prompts. Raw personal data should not sit in model traces by default.
Identity, authority, policy, monitoring, and evidence sit in the product core. Workflows use that path. They do not invent a second one.
Agent principals, versions, registry, kill and revoke.
Sign-in, authorization, delegation scopes, time bounds.
ALLOW, DENY, or REQUIRE_APPROVE when a tool is called.
Behavior signals and kill switch. Observe can only raise risk.
Graph, hash-chained event log, passports, export.
Irreversible actions only after policy and, when required, a person approves.
Shield decides allow, deny, or wait for a person. Other pieces add risk signals or trail data. They do not approve work on their own.
Registry, policy, human approval, redaction, event log.
Session ingest, tool timelines, risk that can only get stricter.
Optional graph dual-write and decision chain when you need an exportable account.
Shield Agent Gatekeeper only after Shield has approved. It does not replace that decision.
Hold restarts, deploys, and external side effects until someone approves. Kill switch included.
Post-transaction work uses the same approval and trail rules. Pair with AccessioAI if you also need storefront labeling.
Watch IDE or CLI sessions, raise risk on unknown tools, and block irreversible actions from running alone.
Register agent principals. Connect the systems they may read.
Agents gather context with redaction and checks at each tool call.
When policy says REQUIRE_APPROVE, the action waits until someone decides.
Only after APPROVED does the side effect run. The event log keeps the trail.
If approval is missing or policy says DENY, the side effect does not run.
Observe and guardrails can raise severity. They cannot approve a submit on their own.
Optional edge steps run only after Shield has approved. An edge click does not replace that.
Know Your Agent: which agent ran, under whose authority, on what evidence, how personal data was handled, and who approved the action.
Shield works for agents in many domains. See use cases and how KYA works.
No. Shield runs on its own. AccessioAI is optional if you also want storefront accessibility and EU AI Act labeling.
Two systems that both claim allow or deny can disagree. Shield keeps one decision path for actions that can change production systems.
Yes. Cancel when you want and export your trail data.