# Vaara Governance

> Runtime tool-call governance for Claude Code. Layer-1 regex deny on Bash/WebFetch/WebSearch plus file mutation (Write/Edit/NotebookEdit). Layer-2 conformal risk classifier on mcp tools. Hash-chained SQLite audit trail at ~/.vaara/claude-code/audit.db.

## Facts
- Page: https://tashan.sh/capability/plugin-vaaraio-vaara-vaara-governance
- tashan id: plugin:vaaraio/vaara/vaara-governance
- Source: https://github.com/vaaraio/vaara
- Type: plugin
- Category: security
- tashan score: 53.0 / 100
- Adoption: 20.0
- Upkeep: not measured
- Freshness: 100.0
- Evidence coverage: 59% of the inputs this score can use
- Health: active
- Instruction depth: solid
- GitHub stars: 10
- License: AGPL-3.0
- Official: no

## Install

```sh
/plugin marketplace add vaaraio/vaara
/plugin install vaara-governance@vaara
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-14 by tashan (https://tashan.sh) from public evidence. Scorer s5.
