agy can read repositories, edit files, run shell commands, and call
tools on a developer’s machine.
TrustGuard lifecycle hooks evaluate those local actions. The hooks ship in the
trustguard-gemini-cli-plugin
repository, the same package Gemini CLI uses.
NeuralTrust controls
PreToolUse is the only event that can stop a tool. PostToolUse,
PreInvocation, PostInvocation, and Stop are sent to TrustGuard and the
hook answers {}, so the agent keeps running. An allow on PreToolUse does
not suppress Antigravity’s own review prompt.
Before you start
Create the policy in Observe mode. Observe records decisions in Activity
without enforcing them. Review the results, then switch the policy to
Enforce. See Policies.
Install the hooks
trustguard entry into ~/.gemini/config/hooks.json and leaves
every other hook in place. Antigravity reads that file at startup. Restart the
IDE or CLI, then run /hooks in the CLI to confirm the commands.
The user file is the default because some CLI versions ignore the workspace
file .agents/hooks.json. To install it anyway:
trustguard/hooks/trustguard-hook.sh. Windows calls
trustguard-hook.ps1. Both forward the event name to trustguard-gemini-cli.
Deploy the managed config
Antigravity and Gemini CLI share one config file. Deploy it with MDM:
For a pilot without MDM, write the same JSON to
~/.trustguard/gemini-cli.json
and chmod 600 it.
fail_mode: "open" allows the tool when TrustGuard cannot be reached.
fail_mode: "closed" denies PreToolUse in that case and still lets the
telemetry events through, so a network blip does not freeze the agent.
What is evaluated
Activity shows these calls with
source.application = antigravity-plugin.
Verify
- Run a shell command Antigravity would execute, such as listing a directory.
- In Activity, confirm an event with
source.application=antigravity-plugin. - Put the policy in Enforce and add a rule that blocks that command. The next
PreToolUseshould returndenyand Antigravity should not run it.