#  I built a Safety Kernel for Crews - blocks dangerous file ops automatically

**URL:** <https://community.crewai.com/t/i-built-a-safety-kernel-for-crews-blocks-dangerous-file-ops-automatically/7321>\
**Category:** Showcase\
**Created:** [February 2, 2026, 10:46am UTC](https://community.crewai.com/t/i-built-a-safety-kernel-for-crews-blocks-dangerous-file-ops-automatically/7321 "2026-02-02T10:46:33Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![imran-siddique](https://sea1.discourse-cdn.com/flex025/user_avatar/community.crewai.com/imran-siddique/32/4833_2.png) [@imran-siddique](https://community.crewai.com/u/imran-siddique)\
**Post date:** [February 2, 2026, 10:46am UTC](https://community.crewai.com/t/i-built-a-safety-kernel-for-crews-blocks-dangerous-file-ops-automatically/7321/1 "2026-02-02T10:46:33Z")

</div>

Hey CrewAI community! 👋

I’ve been working on kernel-level safety for AI agents and wanted to share a demo specifically for CrewAI.

**The Problem:** Agents can hallucinate dangerous operations like `rm -rf` or `DROP TABLE`. Prompt engineering alone can’t reliably prevent this.

**The Solution:** [Agent OS](https://github.com/imran-siddique/agent-os) intercepts these at the kernel level - before they execute.

## Demo

I just submitted a PR to crewAI-examples: [feat: Add Agent OS safety governance example by imran-siddique · Pull Request #300 · crewAIInc/crewAI-examples · GitHub](https://github.com/crewAIInc/crewAI-examples/pull/300)

**Run it yourself:**

```bash
git clone https://github.com/imran-siddique/agent-os
cd agent-os/examples/crewai-safe-mode
python crewai_safe_mode.py

```

**What it does:**

- ✅ Wraps your CrewAI agents in a safety kernel
- ✅ Blocks operations like rm -rf, sudo, chmod 777
- ✅ Maintains full audit log of all agent actions
- ✅ Zero code changes to your existing crews

**Screenshot**

Image: Agent OS Demo →  
[agent-os/examples/crewai-safe-mode/demo.svg at master · imran-siddique/agent-os](https://github.com/imran-siddique/agent-os/blob/master/examples/crewai-safe-mode/demo.svg)

Would love feedback on:

1. What other operations should we block by default?
2. Would this be useful as a native CrewAI integration?

Happy to contribute upstream if there’s interest! 🛡

---

<div class="post-metadata">

**Author:** ![Bin\_Zhang](https://sea1.discourse-cdn.com/flex025/user_avatar/community.crewai.com/bin_zhang/32/5029_2.png) [@Bin\_Zhang](https://community.crewai.com/u/Bin_Zhang)\
**Post date:** [March 9, 2026, 1:10pm UTC](https://community.crewai.com/t/i-built-a-safety-kernel-for-crews-blocks-dangerous-file-ops-automatically/7321/2 "2026-03-09T13:10:07Z")

</div>

Really interesting approach. Intercepting dangerous operations at the kernel level makes a lot of sense, especially as agents start executing real system commands.

One thing I’ve been thinking about in a similar space is what happens _after_ the execution layer — how we verify what the agent actually did.

Blocking rm -rf or DROP TABLE is important, but in more complex multi-agent systems we also start needing something like verifiable execution logs: a structured record of the agent’s decisions and actions that can be audited later.

We’ve been experimenting with this idea as part of an execution-integrity layer for agents, where actions are recorded and verifiable rather than just logged.

Curious if you’ve thought about that side of the problem — not just preventing dangerous actions, but also making agent behavior provable afterwards.I’ve been exploring something related here:

> **[GitHub - joy7758/fdo-kernel-mvk: Minimum Verifiable Kernel for Executable Digital...](https://github.com/joy7758/fdo-kernel-mvk)**
>
> Minimum Verifiable Kernel for Executable Digital Objects (causally closed, deterministic, replay-verifiable).

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex025/uploads/crewai/original/1X/ecda97e72f77c7100e0a761444b1c991925cc789.png) [@system](https://community.crewai.com/u/system)\
**Post date:** [May 3, 2026, 10:46am UTC](https://community.crewai.com/t/i-built-a-safety-kernel-for-crews-blocks-dangerous-file-ops-automatically/7321/3 "2026-05-03T10:46:53Z")

</div>

This topic was automatically closed after 90 days. New replies are no longer allowed.
