Protect
Let agents work. Keep production, secrets and main safe.
Protect checks every tool call before your terminal runs it. A blocked call never runs, and the model is told why.
.env and .env.*. Examples and templates are allowed.
⛔ context-mode Cage blocked this command, so it was NOT executed:
Blocked by your team’s policy: Read environment files. .env files hold secrets.main, master, production and release/*.
⛔ context-mode Cage blocked this command, so it was NOT executed:
Blocked by your team’s policy: Push to protected branches. Protected branches change through reviewed pull requests.Read through sudo, sh -c and about 130 other wrappers.
The inner host is checked too.
A project folder is fine. Only losses you can't undo are blocked.
Nothing is blocked until you choose rules.
Checked before it runs.
- 01The agent asks for a call
Shell, file, fetch or tool server.
- 02Protect reads what it does
Through sudo, sh -c, xargs and 130 other wrappers.
- 03Allowed or blocked
A blocked call never reaches the shell.
How tool-call rules compare.
| Context Mode | Built-in permissions | General LLM gateways | |
|---|---|---|---|
| Decides by | What a call does, through sudo, sh -c and 130 wrappers | Rules per client | Tool name and arguments |
| Covers | Every agent and machine on the account | One client, one machine | Apps you route through it |
| Org policy members cannot loosen | Yes, on Team | No | Varies |
| Set up | One command | Per client | Your own infrastructure |
Read 2026-09-29 and 2026-09-30. Method and sources →
Start in a minute.
Stop losses you can't undo, like wiping your home folder.
Keep .env files away from the model.
Allow or block hosts, nested URLs included.
Record matches before you block them.
Three presets and four extra packs.
Protect reads the call, not the program. Use both.
One policy for the whole org.
On Team, the org sets the rules once. Every member's agents follow them, on every machine.
What agents tried and which rule answered. Export as CSV or JSON Lines.
Our cloud, a dedicated instance, or your own Cloudflare account.
Write the rules once.
npx @context-mode/cli connects your agents. 1,000 requests free, no card.