Protect

Let agents work. Keep production, secrets and main safe.

Protect checks every tool call before your terminal runs it. A blocked call never runs, and the model is told why.

Pick a command
Blocked · never reaches your shellRead environment files

.env and .env.*. Examples and templates are allowed.

⛔ context-mode Cage blocked this command, so it was NOT executed:
Blocked by your team’s policy: Read environment files. .env files hold secrets.
Blocked · never reaches your shellPush to protected branches

main, master, production and release/*.

⛔ context-mode Cage blocked this command, so it was NOT executed:
Blocked by your team’s policy: Push to protected branches. Protected branches change through reviewed pull requests.
Blocked · never reaches your shellCore protection: delete the root or home folder

Read through sudo, sh -c and about 130 other wrappers.

Blocked · never reaches your shellSites: pastebin.com

The inner host is checked too.

RunsNo rule matches

A project folder is fine. Only losses you can't undo are blocked.

RunsNo rule matches

Nothing is blocked until you choose rules.

How it works

Checked before it runs.

  1. 01The agent asks for a call

    Shell, file, fetch or tool server.

  2. 02Protect reads what it does

    Through sudo, sh -c, xargs and 130 other wrappers.

  3. 03Allowed or blocked

    A blocked call never reaches the shell.

Proof

How tool-call rules compare.

Context ModeBuilt-in permissionsGeneral LLM gateways
Decides byWhat a call does, through sudo, sh -c and 130 wrappersRules per clientTool name and arguments
CoversEvery agent and machine on the accountOne client, one machineApps you route through it
Org policy members cannot loosenYes, on TeamNoVaries
Set upOne commandPer clientYour own infrastructure

Read 2026-09-29 and 2026-09-30. Method and sources →

Features

Start in a minute.

Core protections

Stop losses you can't undo, like wiping your home folder.

Secrets

Keep .env files away from the model.

Sites

Allow or block hosts, nested URLs included.

Monitor first

Record matches before you block them.

Presets

Three presets and four extra packs.

Keep your sandbox

Protect reads the call, not the program. Use both.

Team and Enterprise

One policy for the whole org.

Members cannot loosen it

On Team, the org sets the rules once. Every member's agents follow them, on every machine.

Read environment filesBlock · lockedPush to protected branchesBlock · lockedChange cloud resourcesMonitor
One log

What agents tried and which rule answered. Export as CSV or JSON Lines.

Your deployment

Our cloud, a dedicated instance, or your own Cloudflare account.

Write the rules once.

npx @context-mode/cli connects your agents. 1,000 requests free, no card.