Inspiration

Al coding agents running real commands on real systems often guess when instructions are vague, leading to boundary violations, such as Replit's agent deleting a production database during a code freeze. During our internships and work, we saw people just blindly using these AI agents without checking the output, and it led to some genuinely chaotic moments.

What it does

Nocap is a VS Code extension that acts as a control layer for any CLI coding agent or chat, forcing every risky action to undergo a three-way check of Task, Intent, and Effect measured via a dry run before it executes. It provides specific protections against data destruction, runaway LLM API spend, and test-cheating such as agents altering test assertions instead of code.

How we built it

Built using a TypeScript VS Code extension, a Node 20 / Fastify / WebSocket daemon, POSIX shell shims, and native Claude Code hooks. Utilizes the Gemini API for judging intent and task alignment.

Challenges we ran into

Intercepting agent commands universally while keeping safe commands fast. Handling edge cases like foreign-key cascades during SQL dry runs and ensuring LLM API spend is accurately estimated before script execution.

Accomplishments that we're proud of

Achieving a complete three-way verification loop where dangerous actions like broad database deletions or runaway embedding backfills are automatically caught, measured, and blocked. Implementing a human-intent pop-up guard that rejects reflex approvals and forces developers to justify actions matching the measured effects.

What we learned

Relying solely on pattern matching is insufficient for real-world agent safety. Measuring actual impacts through dry-run transactions and code diffs is crucial. Strict separation of concerns such as Shims/hooks, daemon pipeline, and UI extension enables rapid parallel development during tight hackathon constraints

What's next for Nocap

Adding deep production system checks for infrastructure tools like Terraform plans, along with implementing a Model Context Protocol server version.

Expanding support for a shared team feed where blocked actions are posted to a common channel so the whole team can view them.

Share this project:

Updates

Submission history