# Stroq

> Updated 2026-09-10 · type: tool · category: mcp-agents · status: active · rev 1

Stroq is an open-source local firewall for AI coding agents — it tracks what an agent read and blocks dangerous follow-up actions before they run.

- Open source: yes (Apache-2.0)
- Self-hostable: yes
- Pricing model: free
- Best for: Developers running AI coding agents locally who want a runtime guardrail that blocks risky actions, not just an install-time scan.
- Last verified: 2026-09-10

- **Canonical:** https://gtmstacker.com/registry/tool/stroq/
- **Source:** [github · AGGIB/Stroq](https://github.com/AGGIB/Stroq)
- **Tags:** mcp-agents, agent-security, runtime-guardrail, firewall, governance, self-hostable
- **Repository:** https://github.com/AGGIB/Stroq

## Is Stroq open source?

Yes, Stroq is open source under the Apache-2.0 license.

## How much does Stroq cost?

Stroq is free to use.

## Can I self-host Stroq?

Yes, Stroq can be self-hosted (the source is available under the Apache-2.0 license).

## Alternatives & related

- [Tripwire](https://gtmstacker.com/registry/tool/tripwire-agent-scanner/)
- [Geiger](https://gtmstacker.com/registry/tool/geiger/)
- [MagicVault](https://gtmstacker.com/registry/tool/magicvault/)


---

Open-source local action firewall (TypeScript) for AI coding agents: it intercepts an agent's operations, tracks session state by tainting what the agent has read, and blocks dangerous follow-up actions before they run on your machine — a runtime guardrail with intent/audit that complements install-time scanners.

## Provenance

- Apache-2.0 independently WebFetch-verified 2026-09-10 (8★, 253 commits, active; TypeScript). Surfaced via the 2026-09-10 daily pull; extends the Sep-9 agent-safety cluster from install-time scanning into runtime enforcement.
- Curated from the GTM Stacker signal registry (2026-09-10 pass: daily pull + viral-posts brief); license independently WebFetch-verified 2026-09-10.
