Know what your coding agent did. Stop it mid-run.
Brakelog records every tool call to a tamper-evident log, blocks credential reads and risky commands, and gives you a pause button that works while the agent is running. One Python file, no dependencies.
Three things, nothing else
Records
Every tool call the agent makes goes into a JSONL log. Each record carries the hash of the one before it, so an edited or deleted entry shows up in verify.
Blocks
Credential files (~/.aws, ~/.ssh, .env), curl | sh, rm -rf /, sudo, force-push, and network hosts you haven't allowed. Symlinks and case tricks are caught too.
Stops
brakelog pause blocks every tool call immediately, even mid-run. brakelog resume, from your own terminal, lets it continue.
How it works
Claude Code runs Brakelog before every tool call. It checks the call against your policy and the pause flag, writes a hash-chained record, and tells Claude Code to allow or block it. No daemon, no network, no account.
git clone https://github.com/sydanishraza/brakelog python3 brakelog/brakelog.py init # prints the hook config for .claude/settings.json
Start in "mode": "audit" to see what it would block without blocking anything. Tested on Python 3.8–3.13, macOS and Linux.
What it isn't
- Not a sandbox. Rules match the text of commands, so an obfuscated command can slip past, and a harmless command that only mentions a pattern can be blocked. Treat it as a guardrail and flight recorder.
- Deleting the newest entries isn't detectable from the log alone. Save the head hash from
verifysomewhere the agent can't write. - Logs can contain secrets that appear in commands. Brakelog keeps its folder owner-only.
- Claude Code only, for now. Other agents are on the roadmap. Tell us which one you need.
Running agents unattended?
Leave your email for updates and tell us what Brakelog should catch. Alerts, shared team policies and a hosted tamper-proof log are next if people need them.