mayrun

Docs

Quickstart

From zero to a fail-closed shell gate — init, hook, deny, approve, and read a receipt.

1. Install and init

cargo install --git https://github.com/kiket-dev/mayrun --locked
cd your-repo
mayrun init --detect

init --detect writes mayrun.policy.yaml with packs chosen from project signals (Rust, Node, git, …).

2. Turn on the shell-hook

eval "$(mayrun shell-hook)"

Every interactive shell command now goes through mayrun before it runs.

3. Prove deny

rm -rf /
# Deny · dangerous-defaults · prints rule_id

4. Prove allow + receipt

mayrun run 'git status'
mayrun status

Receipts land in .mayrun/receipts.jsonl — hash-chained, secrets redacted.

5. Human approval when needed

mayrun run 'git push'
# Require approval →
mayrun run 'git push' --approve

6. Optional: MCP for Cursor / Claude

mayrun setup cursor
# or: mayrun setup claude --write

Same packs. Same receipts. Agent-agnostic.

What you just got

StageResult
DecideYAML packs + rules, fail closed
ProveLocal receipts with rule_id / reason
ConfineOptional --sandbox under Allow

Deep dive: Architecture · Compose packs: Policy