Skip to content
Termaxa Coding AI tool logo

Termaxa Review: The Command Gate Your Coding Agent Needs

CodingFree
Best for: Developers who hand real command-line work to AI coding agents and want previews, backups, and an audit trail before anything destructive runs

Termaxa is a free, open-source command gate that previews what a shell command will actually do, backs up what it could destroy, and blocks the dangerous few before Claude Code or Codex runs them.

Founded 2026

What Is Termaxa?

It is a local command gate built for the era of agents that type in your terminal. The agent's own prompt shows the command it wants to run; the gate shows the consequence. Before anything executes it can preview affected files, back up data a command would destroy, block the commands your policy marks as too dangerous, and record every decision in an audit log the agent has no permission to touch. It is a guardrail that cooperates with the agent instead of fighting it, and the README is blunt about the trade-off: this is a windshield, not a sandbox.

How the Command Gate Works

The gate inspects each covered command before execution and answers with an explicit disposition. Safe operations pass through, suspicious ones pause for your approval, and the clearly dangerous handful are denied outright. Backups are created automatically for state that a command would replace, such as files, database rows, or the branch tip a force push wants to move. The record includes the command, the disposition, and the reasoning, giving you a reproducible trail long after the session closes.

  • Pre-execution inspection with explicit dispositions
  • Automatic backups of state a command would replace
  • Force push and destructive delete protection
  • Compound commands are split and judged command by command

Which Coding Agents Does Termaxa Protect?

Coverage maps to the hooks the project ships. Claude Code gets a hook on Bash and the write tools, with the wrapped path covered too. Codex uses a deny-only hook where an ask becomes a refusal. Cursor hooks shell events plus the Write and Delete tools, and Copilot CLI surfaces the request as a real prompt you can answer. The practical lesson is the same across every integration: the guarantee is bounded by what the hook can observe, so set-up time is a few minutes but verification is on you.

  • Claude Code: Bash and write-tool hooks, plus wrap coverage
  • Codex: deny-only hook where an ask is a refusal
  • Cursor: shell events with Write and Delete hooks
  • Copilot CLI: the request arrives as a real prompt

What Termaxa Adds That Other Guardrails Miss

Most safety layers for coding agents either classify intent at a policy level or rely on the agent's own permission prompts. This gate works the other way: it reasons about the concrete blast radius of the exact command, creates rollback state before anything runs, and keeps an append-only record of every disposition. That combination — consequence previews plus backup plus an audit an agent cannot rewrite — is rarer than it should be, and it is offered with no paid tiers and no license gates, which matters for individuals who want real protection without a subscription.

  • Classifies the concrete command, not just the intent
  • Rollback state is created before execution, not after damage
  • Audit trail is written outside the agent's control
  • No paid tiers, no license keys, free forever

Rollback and the Audit Record

The rollback story is what separates a gate from a yes-or-no prompt. Because state is backed up first, a mistaken approve can be undone rather than mourned. That includes the commit a force push would have erased and the rows a deleting query would have emptied. Alongside the backups, the audit holds the command, the disposition, and the hook that produced it, structured so you can review what happened on any machine at any time.

  • Backups cover files, git refs, and database state
  • Rollback restores what a mistaken approve destroyed
  • Audit entries are append-only and agent-proof
  • Disposition and reasoning are stored with each command

Platforms and Requirements

It ships as a compiled binary with sha256-pinned releases for macOS, Linux, and Windows, and Homebrew, cargo, winget, and scoop are all supported install paths. It works in plain terminals and inside the coding agents listed above, and the browser-based playground lets you watch the gate make decisions before you install anything. Being a local tool, it has no cloud dependency and no account to create.

  • macOS, Linux, and Windows binaries with pinned hashes
  • Homebrew, cargo, winget, or scoop installation
  • Browser playground for trying the gate before installing
  • Local-only operation with no account required

Alternatives to Termaxa

The closest existing directory entry is [Harden](/tools/harden), a local-first AI firewall that also guards coding-agent tool calls but leans on an on-device decision model, while this gate reasons about concrete command consequences and adds rollback backups. Beyond that, [Claude Code](/tools/claude-code) and [Cursor](/tools/cursor) are the agents you would protect rather than peers. Every coding agent ships its own permission prompts, so the baseline alternative is prompt-based approval; the gate formalizes that surface with previews and an audit trail.

  • Harden — an AI firewall comparing favorably on model-based evaluation
  • Claude Code and Cursor — the agents the gate protects
  • Agent-native permission prompts remain the baseline alternative

Pricing & Plans

Free and open source (MIT/Apache-2.0) with no feature gates or license keys. Install via Homebrew, cargo, winget, or scoop with sha256-pinned binaries for macOS, Linux, and Windows.

Most Popular

Free and open source

$0

The entire command gate is free forever under MIT and Apache-2.0 licenses, with no feature gates and no license keys.

  • Command consequence previews and backups
  • Policy rules with allow, ask, and deny decisions
  • Audit recording the agent cannot rewrite
  • Hooks for Claude Code, Codex, Cursor, and Copilot
  • Install via Homebrew, cargo, winget, or scoop
Install free

Best For

Recommended use cases and scenarios where Termaxa shines.

Pros and Cons

The strongest argument for the gate is architectural: protection that runs exactly where the agent runs, understands the specific command, and leaves you a rollback path and an audit record at zero cost. The honest limits are coverage — the gate can only see what its hooks observe — and the explicit refusal to be a sandbox, which means a capable agent can still do damage you approved. For developers who have started trusting Claude Code or Codex with real machines, that is a worthwhile trade to understand before you install.

Pros

  • Shows concrete consequences (files, rows, commits) before a command runs
  • Creates automatic backups so a wrong move can be rolled back
  • Maintains an audit record the agent cannot rewrite
  • Free and open source with no feature gates or license keys
  • Hooks into Claude Code, Codex, Cursor, and Copilot

Cons

  • Protects covered surfaces; some agent actions need explicit hook setup
  • Not a full sandbox by design — you still approve what runs
  • Young project with a fast-moving feature set
  • Windows support is newer than macOS and Linux support

Frequently Asked Questions

Common questions about Termaxa, answered.

What is Termaxa?

Termaxa is a free, open-source command gate for AI coding agents. It previews the consequences of a shell command, backs up state it could destroy, blocks dangerous commands, and records every decision in an audit log the agent cannot rewrite.

Which coding agents does Termaxa work with?

Claude Code (Bash and write-tool hooks), Codex (deny-only hook), Cursor (shell, Write, and Delete hooks), and Copilot CLI. Coverage depends on what each agent's hook can observe.

Is Termaxa really free?

Yes. It is open source under MIT and Apache-2.0 with no paid tiers, no feature gates, and no license keys. Hosted cloud features are on the roadmap but not yet shipping.

Is Termaxa a sandbox?

No. The project explicitly describes itself as a windshield, not a sandbox. It previews, backs up, blocks the dangerous few, and records everything, but a command you approve will run.

Which platforms are supported?

macOS, Linux, and Windows with sha256-pinned binaries, installable via Homebrew, cargo, winget, or scoop. No cloud dependency and no account is needed.

How does the rollback work?

State that a command would replace — files, database rows, or the branch tip a force push would move — is backed up before execution, so a mistaken approval can be undone.

Reviews & Ratings

Share your experience

Your rating

Loading reviews...

Similar Tools

More Coding tools you might like

Claude Code AI tool logo

Claude Code

CodingFreemium
Best for: Agentic coding in the terminal

Anthropic's agentic coding tool that lives in your terminal — plan, build, test, and ship software by describing tasks in plain English.

GitHub Copilot AI tool logo

GitHub Copilot

CodingPaid
Best for: In-IDE code completion

AI coding assistant that suggests code completions and entire functions in VS Code, JetBrains, and Neovim.

Amazon Q Developer AI tool logo

Amazon Q Developer

CodingFreemium
Best for: AI coding assistant on AWS

Amazon Q Developer is AWS's AI coding assistant for code completion, agents, and security scans across your IDE.