AI Developer Tools

Termaxa

A cooperative gate for shell commands that AI agents run, providing previews, backups, policy enforcement, and audit for tools like Claude Code and Cursor.

What is Termaxa?

Termaxa is an open-source CLI tool and agent hook that gates shell commands executed by AI coding agents. It evaluates commands against a policy, shows blast radius previews, creates automatic backups before destructive operations, and maintains a full audit log. It works cooperatively with Claude Code and Cursor, acting as a windshield rather than a sandbox.

Termaxa vs Similar AI Tools

Pricing ModelFreeFreeFreeFree
Free Credits
Key Features
  • Policy-based command gating (allow/ask/deny) with first-match-wins rules
  • Blast radius preview for git, PostgreSQL, Terraform, and file operations
  • Automatic backups before destructive operations (git ref pinning, pg_dump, rm insurance)
  • Seven breakable boxes covering OWASP Agentic Top-10 vulnerabilities
  • Three guided simulations for cascading failures, human-agent trust, and rogue agents
  • Network-isolated Docker containers for safe execution
  • Code-to-runtime reasoning across cloud, Git, and Kubernetes
  • Action-gate enforces read-only policy on every API call
  • Sandboxed JavaScript execution for concurrent research
  • Append-only, SHA-256-addressed event history through Jaybase
  • AES-256-GCM encryption for stored node payloads
  • Unified RBAC for ledger, notes, snapshots, and audit reads
Pros
  • Provides command previews before execution
  • Automatic backups for destructive operations
  • Covers full OWASP Agentic Top-10 in a realistic manner
  • Docker isolation prevents accidental damage
  • Read-only by construction prevents accidental writes
  • Evidence-backed verification cross-checks every finding
  • Opinionated and secure accounting CLI with immutable audit trail
  • Designed for AI agent integration with JSON output
Cons
  • Hooks are cooperative, not enforced (agent can bypass)
  • Native agent tools (e.g., file editing) are not gated
  • Requires Docker and technical setup
  • Not for production use; only for lab environments
  • Requires an LLM API key, incurring token costs
  • Limited to read-only operations, cannot remediate
  • Pre-1.0, limited feature set
  • No native QuickBooks import (agents must normalize data)
Best For
  • Developers using AI coding agents like Claude Code or Cursor
  • Teams needing visibility and control over agent-issued shell commands
  • Security researchers focusing on AI agent vulnerabilities
  • Developers building MCP-based applications
  • Security engineers
  • DevOps teams
  • Small teams needing secure, auditable accounting with AI agent support
  • Developers integrating automated bookkeeping workflows

How to use Termaxa?

  1. 1Install the binary (prebuilt release or cargo install termaxa).
  2. 2Run 'termaxa init --claude-code' in your project to scaffold policy and install the hook.
  3. 3Define rules in .termaxa/policy.yaml.
  4. 4Use 'termaxa check "command"' to dry-run and see verdict.
  5. 5Run 'termaxa run -- command' for gated execution with preview and backup.
  6. 6Review session audit with 'termaxa report'.

Termaxa Key Features

  • Policy-based command gating (allow/ask/deny) with first-match-wins rules
  • Blast radius preview for git, PostgreSQL, Terraform, and file operations
  • Automatic backups before destructive operations (git ref pinning, pg_dump, rm insurance)
  • Circuit breaker that auto-denies repeated destructive intent across different commands
  • Full audit log stored in JSONL format outside the repo
  • Session execution reports with command summary and risk score
  • Webhook notification on deny or ask events
  • Works as a standalone CLI or integrated hook for Claude Code and Cursor

Termaxa Use Cases

  • Safely run AI coding agents on production repositories with automatic rollback
  • Prevent accidental destructive database operations like DROP TABLE
  • Review and approve force pushes with commit loss preview
  • Block malicious or unintended rm -rf commands with circuit breaker
  • Audit all shell commands executed by AI agents for compliance

Termaxa Pricing & Free Credits

Termaxa currently operates on a Free model.

This tool is completely free to use

Open Source

Free

MIT or Apache 2.0 licensed, prebuilt binaries available for free.

Termaxa Pros & Cons

Pros

  • Provides command previews before execution
  • Automatic backups for destructive operations
  • Circuit breaker prevents repeated dangerous commands
  • Customizable policy via YAML
  • Works with Claude Code and Cursor out of the box
  • Audit logs are stored safely outside the repository

Cons

  • Hooks are cooperative, not enforced (agent can bypass)
  • Native agent tools (e.g., file editing) are not gated
  • Shell parsing is not perfect for complex commands
  • Backups have no retention or pruning yet
  • Pre-1.0, schema and CLI may change between minor versions

What is Termaxa best for?

  • Developers using AI coding agents like Claude Code or Cursor
  • Teams needing visibility and control over agent-issued shell commands
  • Users managing critical git repositories, databases, or infrastructure via AI agents

Termaxa FAQ

Top free alternatives to Termaxa

Openbase logo

A voice-controlled IDE that enables developers to initiate AI coding sessions with Codex or Claude Code, approve commands, and review diffs from their phone.

Free
SureWire logo

SureWire is a specialized QA platform that stress-tests AI agents for safety, reliability, and compliance using purpose-built testing agents.

Free
Notte logo

Browser infrastructure platform for AI agents to run on the internet at speed with cloud browser sessions, agents, and serverless functions.

Free
YAFL logo

An agent-first file transfer tool that enables secure, encrypted file sharing between AI agents via MCP calls without human involvement.

Free
Manifest logo

Manifest converts any URL into a structured JSON map of what AI agents can interact with on a page—buttons, forms, inputs, and required fields.

Free
B

Personal GitHub Pages site by Basert, currently displaying default welcome content and instructions for using GitHub Pages with Jekyll.

Free
Agentcard logo

Agentcard provides agent-friendly card issuing and payment infrastructure for AI agents, enabling 5-minute setup and autonomous purchases.

Free

Best alternatives AI Tools to Termaxa

mcploitable logo

A collection of deliberately vulnerable MCP servers for training in agentic security, mapped to the OWASP Top 10 for Agentic Applications.

Cynative logo

Open-source AI tool for deep infrastructure research, running frontier models across code, cloud, and runtime to deliver verified answers.

Magpie logo

Magpie is an opinionated accounting CLI for humans and AI agents, providing double-entry bookkeeping with RBAC and immutable event storage on Jaybase.

agent-manager logo

Terminal UI to manage AI coding-agent sessions (Claude Code, OpenCode, Codex, Grok Build) in tmux with live status, group tree, and diff review.

Openbase logo

A voice-controlled IDE that enables developers to initiate AI coding sessions with Codex or Claude Code, approve commands, and review diffs from their phone.

Free
OpsCat logo

Zero-config, single-binary software catalog with auto-discovery, dependency visualization, compliance scorecards, and native MCP integration for AI agents.

BrowserAct Skills logo

Browser automation CLI for AI agents to bypass anti-bot walls, hand off to humans, and run parallel tasks.

lee-ai logo

An AI-powered shopper assistant that provides a live cursor to guide website visitors, point out products, and display price calculations.