DSH Market
O

Openguardrails

by openguardrails · openguardrails/openguardrails

Build failsBundlegit (build fails)fresh

The vendor-neutral protocol for AI agent safety & security — and the neutral benchmark that ranks the vendors.

Install Openguardrails

Likely fails to load: not on npm, needs a build, and ships no `prepare` script — a git install fetches sources, not built artifacts, so the entry point is never produced.

This install is expected to fail

A git install pulls source, not build output. This package needs a build step, has no prepare script to run it, and is not published to npm — so nothing produces the compiled output the loader then goes looking for.

Three things would fix it, all of them on the author's side: publish the package to npm, add a prepare script that builds on install, or commit the build output to the repository. Until one of those happens, the command below is here so you can reproduce the failure, not so you can install it.

What would be run — expected to install and then fail to load

# 1. add the bundle to a profile — --profile my-profile points at $DSH_HOME/profiles/my-profile
dsh plugin --profile my-profile add github:openguardrails/openguardrails

# 2. verify: the bundle should show up as a layer in the resolved config
dsh --profile my-profile --dump-config

# 3. boot the profile
dsh --profile my-profile

Before you run it

  • A plugin runs with your permissions once loaded: it can read your files, use your credentials and reach the network. Tool approvals do not sandbox it.
  • Installing from git resolves a moving branch. Pin a commit — github:openguardrails/openguardrails#<commit-sha> — so the code you reviewed is the code you install.

Prerequisites

API key
Not required.
Network access
Not required at runtime.
Language
Python — a git install pulls this source, not build output.

Install check

Every field the verdict was derived from, so you can re-derive it yourself

Field checkedResultWeightWhat the spec says about it
lifecycleScriptspassinfono install-time scripts
dsh.bundlepassfatalpackage.json declares a `dsh.bundle` layer
dsh.bundle.patch filepassfatalpatch file present at `integrations/agent/dsh/cordis.patch.yml`
npm registrymissingwarn`@openguardrails/dsh` is not published to npm
prepare scriptmissingfatalneeds a build but ships no `prepare` script — a git install fetches sources, not built artifacts
Verdict reason
git-only + needs build + no prepare script
package.json read
integrations/agent/dsh/package.json
Rules applied from
docs/user/develop/basic/publish.md
Checked at
2026-08-15

From the README

Excerpt as published by the author, plain text, unedited

**The vendor-neutral protocol for AI agent safety & security — and the neutral benchmark that ranks the vendors.** Integrate safety & security once, enforce it across every agent and LLM — instead of wiring every vendor to every tool by hand. Apache-2.0 · [openguardrails.com](https://openguardrails.com) This monorepo is the home of the **OpenGuardrails (OGR) specification and its reference integrations**. The specification is the normative contract every integration and detector speaks; the integrations, benchmark, examples, skill, and website live alongside it so changes can be reviewed and tested together. OGR is **not a guardrail product**: it defines the wire and referees the leaderboard. Vendors compete on detection quality behind a common plug; users get one way to configure and comp

Topics

GitHub topics on this repository

More in Protocol Shared Control

Ranked by similarity inside the cluster, not alphabetically