CAIN-42 CAIN Studio

Recipes

Guard files

For an agent that writes files, in 17 frameworks.

Last reviewed 2026-10-02

Writing SSH keys is refused; writing to the agent's own output folder runs.

The rule

{
  "name": "files-guard",
  "effect": "deny",
  "priority": 10,
  "match_path": "/tools/write_file",
  "conditions": [
    {
      "field": "path",
      "op": "matches",
      "value": "*/.ssh/*"
    }
  ]
}

Measured on production (2026-10-02, rule tester): the risky call below matches this rule and the safe one does not.

Risky{"path": "/home/app/.ssh/authorized_keys", "content": "ssh-ed25519 AAAA..."}
Safe{"path": "/srv/app/out/report.csv", "content": "a,b"}

Pick your framework

FrameworkTool name CAIN seesPlugs into
Python (any function)write_filethe function that acts
LangChainwrite_fileyour agent's tool list
LangGraphwrite_filethe tools your graph's nodes call
OpenAI Agents SDKwrite_filefunction tools
CrewAIwrite_fileCrewAI's before-tool-call hooks
LlamaIndexwrite_fileFunctionTool
Pydantic AIwrite_filean agent capability
AutoGen (agentchat)write_filethe callables you give AssistantAgent
Google ADKwrite_filethe functions in an agent's tools
Claude Agent SDKmcp__ops__write_filePreToolUse hooks
MCP client (Python)write_fileany MCP client session
OpenTelemetrywrite_fileyour existing tracing
Any other frameworkwrite_fileany Python callable
Claude Code hooksWriteClaude Code's PreToolUse hook
Cursor hooksread_fileCursor's permission hooks
TypeScript / JavaScriptwrite_fileany async function
HTTP (any language)write_fileyour own call site

Try CAIN-42 on your own agents

Create a free account and every new account starts with a 7-day trial of the full platform. Or try the sandbox first, with no account at all.

Create a free account →  ·  Try the sandbox  ·  See the whole ecosystem