snapif 0.1.2

Snapif scores one tool call and returns Auto, Review, or Escalate.
Documentation

Snapif

Snapif scores one tool call. The score is Auto, Review, or Escalate.

Getting started

Build the snapif binary. The cli feature includes http.

cargo install snapif --features cli

From this repo, cargo run --features cli -- --help prints the same commands.

Gate

Write one tool call to call.json:

{"action_id":"tag","name":"list_files","args":{},"trusted":{"user_request":"list the workspace"},"untrusted":null,"script":{"harm":"read","confidence":0.91}}
SNAPIF_BACKEND=fake snapif gate --call call.json

The process prints one word and exits:

Exit Word Meaning
0 auto The call may proceed.
10 review A person should look first.
11 escalate Do not run the call.

script is only for SNAPIF_BACKEND=fake. A live score uses typesafe or compatible.

Hook

snapif hook is a Claude Code PreToolUse hook. It reads one JSON object on stdin and prints a permission decision on stdout. A bad body still exits 0 and denies the call, because a hook error would otherwise let the call proceed.

printf '%s\n' '{"tool_name":"bash","tool_input":{"command":"ls"}}' | SNAPIF_BACKEND=fake snapif hook

Example

This run uses a scripted fake scorer and prints auto:

cargo run --example pre_tool_use

Live score

  • SNAPIF_BACKEND is typesafe or compatible.
  • SNAPIF_BASE_URL is required for compatible and must be a URL.
  • SNAPIF_API_KEY is required when the base URL is not a loopback address.