Launched September 8, 2026
Doberman

Doberman

The guard dog to stop your AI when it goes rogue.

FreeAI AgentsMCP1,864 impressions#11 of its week

Doberman is an open-source, runtime security layer for AI coding agents. It sits between the agent and its tools and gives every action a PASS, AUTH or BLOCK verdict before it runs. A deterministic core catches known dangerous behavior, while an adaptive layer learns what’s normal for you and raises risk when something looks off. It fails closed and learning is raise-only. Works with Claude Code, Codex, OpenClaw and MCP clients like Cursor.

Doberman is an open-source runtime security layer that proxies AI coding agents and decides PASS, AUTH or BLOCK for each tool call.

for
Developers using AI coding agents who need runtime protection against rogue actions.
pricing
open source
license
Apache-2.0
DobermanCore/Doberman-Core 277 42Pythonupdated 7 days ago
  • v0.18.7v0.18.7 — phone approvals and closed bypassesa month ago
  • v0.18.6v0.18.6 — security hardening and UX overhaula month ago
  • v0.18.5v0.18.5 — decision-log retention, update nudges, dashboard polisha month ago
works withClaude CodeCursorOpenClaw

Key features

8 features of Doberman
  • MCP proxy — Intercepts every tool call from an agent and normalizes it into a SecurityObject.
  • Three-verdict engine — Deterministic core returns PASS, AUTH (human approval) or BLOCK before execution.
  • Raise-only learning — Behavioral baselines can only tighten; weakening requires 2FA-gated approval.
  • Mode dial — Four security postures (Light, Balanced, Strict, Paranoid) adjust thresholds and default verdicts.
  • Tiered authentication — Local confirmation, TOTP 2FA, and time-limited role elevation for AUTH actions.
  • Local audit log — Append-only, redacted log of decisions with reason codes and HMAC fingerprints.
  • Extensible plugins — Custom detectors, auth providers, or audit sinks can be added via Python entry points.
  • Fail-closed default — Any error, uncertainty or unknown case results in a BLOCK verdict.

Use cases

  • Prevent an AI agent from executing destructive commands like `rm -rf ~`.
  • Require human approval before an agent writes to sensitive paths such as authentication files.
  • Block secret exfiltration by scanning tool arguments and outputs for leaked credentials.

Doberman vs alternatives

DobermanClaude CodeOpenAI CodexLangChainCrewAI
Best forAdaptive authorization for AI coding agentsAgentic coding in the terminalCode generation with OpenAI modelsLLM app developmentMulti-agent orchestration
PricingOpen sourceSubscriptionSubscriptionFreeSubscription
DevHunt upvotes30000
LaunchedSep 2026————
  • Doberman vs Claude Code: Claude Code provides an agentic coding environment but lacks a runtime security proxy that enforces PASS/AUTH/BLOCK on tool calls.
  • Doberman vs OpenAI Codex: OpenAI Codex offers code generation and execution but does not include a deterministic guardrail layer like Doberman.
  • Doberman vs LangChain: LangChain is a framework for building LLM apps; it does not provide a built-in, fail-closed security gate for agents.
  • Doberman vs CrewAI: CrewAI orchestrates multiple agents but does not focus on runtime tool-call authorization and local audit logging.

Doberman FAQ

How does Doberman stop an AI coding agent from running dangerous commands?+

It sits between the agent and its tools, reads each call, and the policy engine returns PASS, AUTH or BLOCK; BLOCKed actions never reach the tool.

Which AI agents does it work with?+

Native hooks for Claude Code and Codex; any MCP-speaking client such as Cursor, OpenClaw, or custom agents can point to Doberman as a transparent proxy.

How is this different from built-in permission prompts?+

Built-in prompts only ask the agent; Doberman inspects the actual call (paths, secrets, destinations) and blocks or requires approval only when needed, passing routine work silently.

Is any code or data sent to the cloud?+

No. All policy evaluation, decision making and audit logging run locally on the developer’s machine.

What happens on errors or unknown situations?+

Doberman fails closed – unknown cases or internal errors default to a BLOCK verdict, with a reason code and explanation logged.

Summarized by DevHunt from trydoberman.dev · Oct 4, 2026. Details may change; check the official site.