Gemini CLI
A Gemini CLI BeforeTool hook sends each shell command to dagsec before it runs. Install commands are checked; everything else is allowed and nothing is stored.
Setup
- Create an API key.
- Add this to
~/.gemini/settings.json(merge it into existing settings), replacingYOUR_DAGSEC_API_KEY:
json
{
"hooks": {
"BeforeTool": [
{
"matcher": "run_shell_command",
"hooks": [
{
"name": "dagsec",
"type": "command",
"command": "curl -s -m 15 -H \"Authorization: Bearer YOUR_DAGSEC_API_KEY\" -H \"Content-Type: application/json\" --data-binary @- https://app.dagsec.net/api/hooks/gemini",
"timeout": 20000
}
]
}
]
}
}On Windows, write curl.exe instead of curl. The Integrations page in the dashboard shows this ready to copy.
What it does
| Result | Gemini CLI |
|---|---|
| Not an install, or nothing risky | The command runs |
| Risky, block mode | The command is denied and the reason is shown to you and the agent |
| Risky, warn mode | The finding is shown and the command runs, because Gemini CLI can't ask |
Warn mode: add ?mode=warn to the URL or send X-Dagsec-Mode: warn. The recognized commands and rules are the same as for Cursor.
Failure behaviour
If dagsec can't be reached or the key is wrong, the command runs.