Doberman
Sits between your AI coding agent and its tools, blocking or gating dangerous actions.
Doberman is a local MCP proxy that intercepts every tool call an AI coding agent makes and turns it into a PASS, AUTH or BLOCK verdict before it reaches the filesystem, shell or web. Any error or uncertainty fails closed, and guardrails can only tighten automatically — loosening requires explicit, 2FA-gated human approval. It ships four strength modes, from Light to Paranoid, that change bulk-delete thresholds from 100 files down to 3, and is open source under Apache-2.0 but explicitly labeled alpha.

What holds up
- +Fails closed on any error or uncertainty — nothing reaches a tool without a verdict
- +Guardrails can only auto-tighten; loosening needs explicit 2FA-gated human approval
- +Four strength modes tune the bulk-delete threshold from 100 files down to 3
- +Open source under Apache-2.0, so the safety-critical decision engine is auditable
Mind the limits
- −Labeled alpha by its own maker — not positioned as production-hardened yet
- −Installed via pip with no hosted or managed option shown on the page
Featured here? Take the badge
Put it on your site — it links back to this review. Free for every listed product, always.
<a href="https://stillworks.dev/products/p/doberman/"><img src="https://stillworks.dev/badge/doberman.svg" alt="Picked by StillWorks" width="250" height="54"></a>