Brakelog
Open source · Claude Code hook

Know what your coding agent did. Stop it mid-run.

Brakelog records every tool call to a tamper-evident log, blocks credential reads and risky commands, and gives you a pause button that works while the agent is running. One Python file, no dependencies.

Three things, nothing else

Records

Every tool call the agent makes goes into a JSONL log. Each record carries the hash of the one before it, so an edited or deleted entry shows up in verify.

Blocks

Credential files (~/.aws, ~/.ssh, .env), curl | sh, rm -rf /, sudo, force-push, and network hosts you haven't allowed. Symlinks and case tricks are caught too.

Stops

brakelog pause blocks every tool call immediately, even mid-run. brakelog resume, from your own terminal, lets it continue.

How it works

Claude Code runs Brakelog before every tool call. It checks the call against your policy and the pause flag, writes a hash-chained record, and tells Claude Code to allow or block it. No daemon, no network, no account.

#41prev 000…
→
#42prev a3f…
→
#43prev 9c1…
→
#44prev 7e0…
git clone https://github.com/sydanishraza/brakelog
python3 brakelog/brakelog.py init   # prints the hook config for .claude/settings.json

Start in "mode": "audit" to see what it would block without blocking anything. Tested on Python 3.8–3.13, macOS and Linux.

What it isn't

  • Not a sandbox. Rules match the text of commands, so an obfuscated command can slip past, and a harmless command that only mentions a pattern can be blocked. Treat it as a guardrail and flight recorder.
  • Deleting the newest entries isn't detectable from the log alone. Save the head hash from verify somewhere the agent can't write.
  • Logs can contain secrets that appear in commands. Brakelog keeps its folder owner-only.
  • Claude Code only, for now. Other agents are on the roadmap. Tell us which one you need.