Install MoorAI and guard Claude Code
To install MoorAI, run one command: it registers MoorAI’s on-device hooks in Claude Code, and a second command adds Codex, Copilot CLI, Gemini CLI or Cursor. From then on the agent’s file reads, shell commands, writes, web fetches and MCP tool calls are checked on the machine before they run. The agent is open source (MIT) and needs no account; without one it coaches, and a device enrolled in the free console enforces.
-
Install MoorAI and its Claude Code hooks
curl -fsSL https://raw.githubusercontent.com/gitayg/moorai/main/scripts/install.sh | sh
The script clones MoorAI to
~/.moorai, installs its dependencies and registers MoorAI’sPreToolUse,PostToolUseandUserPromptSubmithooks in~/.claude/settings.json. It needsgitand Node 18 or later, and no account. SetMOORAI_NOHOOK=1to skip hook registration, orMOORAI_HOMEto install somewhere else. To remove the hooks later:node ~/.moorai/cli/moorai-hook.mjs uninstall, which removes only MoorAI’s entries.Prefer a desktop app? Download MoorAI for macOS (Apple silicon, signed and notarized, or
brew install --cask gitayg/tap/moorai) or Windows (x64 installer). -
Add Codex, Copilot CLI, Gemini CLI or Cursor
node ~/.moorai/cli/moorai-agent-hook.mjs codex install # or: copilot | gemini | cursor
Each command registers a pre-tool hook in that agent’s own config (
~/.codex/hooks.json,~/.copilot/hooks/moorai.json,~/.gemini/settings.json,~/.cursor/hooks.json) that runs the same engine and policy as the Claude Code hook. In Codex, trust the hook once with/hooks. These four adapters are built from each vendor’s documentation and tested against its documented hook payloads; they have not yet been run end to end against the live agents. Enforcement is validated on Claude Code. -
Check that it is working
node ~/.moorai/cli/moorai-doctor.mjs node ~/.moorai/cli/moorai-explain.mjs "cat .env"
moorai-doctoris read-only: it reports MoorAI’s hook registration in each agent, Claude Code’s managed settings that can switch hooks off, enrollment (coach or enforce), which policy is enforced and whether its signature verifies, and runs a live self-test of the real hook on a benign and a known-bad command. It exits 1 if any check fails.moorai-explainruns a string through the same engine and policy the hook uses and shows each finding, the final decision and the safer alternative, locally. -
Enroll the device to enforce
Until a device is enrolled, MoorAI coaches: in Claude Code a flagged call goes on to its normal permission prompt with a note, shown to you and handed to the agent, that names what was caught and the safer way. Nothing is blocked and nothing is posted anywhere. Enrolled in a MoorAI console (hosted, free for up to 200 users), the same findings are blocked, held for sign-off or end the session, per policy; with no policy set, built-in defaults block a reverse shell and a local secret leaving the machine. Enroll from the desktop app’s settings panel, or with an installation token from the console.
What the console receives from an enrolled device: a category, a risk level and a keyed one-way hash, never the prompt, the file or the matched text. MoorAI is governance, not a sandbox: it fails open if the hook crashes or times out. Full install notes, every command and their limits are in the README. Next: Claude Code security · MCP security · capabilities · pricing.
One command,
on the device.
Open source (MIT). Coaches with no account; enforces once enrolled.