The Rule Pack Catalog
35 signed packs, 15 of them free, mapped to the five things you want guarded. This list renders straight from the same public catalog the CLI installs from.
START FREE15 of the 35 packs cost nothing, forever. One signed install line turns them on.
Install NebGuardProtect the infrastructure agents touch
11 PACKS · ALL FREEClusters, pipelines, charts, cloud accounts, and the bills they generate: the surfaces an agent can actually break stand guarded before your subscription starts.
Core
The always-on safety baseline. Guards git workflows, destructive shell operations, and infrastructure changes for every install.
core · v0.1.0
AWS Cloud
AWS cloud guardrails: IAM, encryption, storage, secrets, and cost.
aws-cloud · v0.2.0
Kubernetes Platform
Kubernetes platform guardrails: RBAC, pod-security, resource, namespace, and admission safety.
kubernetes-platform · v0.2.0
Cluster Networking
Cluster networking guardrails: TLS, policies, and mesh/DNS.
cluster-networking · v0.2.0
Containers
Container guardrails: image provenance, base-image, and runtime.
containers · v0.2.0
Helm Charts
Helm chart guardrails: dependency, values type-safety, versioning, and template safety.
helm-charts · v0.2.0
Crossplane
Crossplane composition, provider-config, and lifecycle guardrails.
crossplane · v0.2.0
Gitops Argocd
GitOps and ArgoCD delivery safety: declarative enforcement and sync-lifecycle guards.
gitops-argocd · v0.2.0
CI CD Delivery
CI/CD delivery guardrails: build, release, deployment, and pipeline safety.
ci-cd-delivery · v0.2.0
Observability
Observability guardrails: logging, metrics, alerting, and debugging discipline.
observability · v0.2.0
Cost Management
Cost-management guardrails: sizing, licensing, attribution, and cleanup.
cost-management · v0.2.0
Keep secrets and data inside
6 PACKS · 0 FREECredentials, customer data, and supply-chain trust stay where they belong, even when an AI is the one typing.
No free tier in this group: every pack here comes with the platform subscription, because half-guarded secrets are not a starter feature.
Secrets Management
Secrets management: detection, container, architecture, and runtime handling.
secrets-management · v0.2.0
Data Protection
Data protection: PII handling, encryption at rest, and retention.
data-protection · v0.2.0
Runtime Protection
Runtime protection: agent-context guards against local configuration and credential introspection, environment and process disclosure, credential exfiltration, and high-risk fetched commands.
runtime-protection · v0.2.0
Security Appsec
Application security: injection, authentication, authorization, network-security, and cryptography.
security-appsec · v0.2.0
Supply Chain
Supply-chain security: dependency, audit, and package safety.
supply-chain · v0.2.0
CI CD Security
CI/CD security: pipeline, artifact, and logging safety.
ci-cd-security · v0.2.0
Govern the agents themselves
3 PACKS · 1 FREEAutonomy with a leash: session lifecycle, scope, methodology, and transparency rules for the AI doing the work.
Agent Session Core
Agent-session governance: the autonomy, stop, compaction, evidence, and lifecycle safety-nets for autonomous AI agents.
agent-session-core · v0.2.0
AI Governance
AI governance policy: mode enforcement, scope, methodology, session, and transparency for licensed tenants.
ai-governance · v0.2.0
Pro
The paid guardrail set. AI governance, business policy, and security enforcement for licensed NebCore tenants.
pro · v0.1.0
Prove it when the auditor asks
4 PACKS · 2 FREEIncidents get runbooks, docs stay honest, business copy follows policy, and framework evidence files itself along the way.
Docs Hygiene
Documentation hygiene: ADR, changelog, API-doc, and general doc guards.
docs-hygiene · v0.2.0
Incident Management
Incident-management discipline: runbooks and postmortems.
incident-management · v0.2.0
Compliance Frameworks
Compliance frameworks: SOC2, NIST, and logging/audit mappings.
compliance-frameworks · v0.2.0
Business Content
Business content and multi-country policy: tone, accuracy, formatting, legal, and privacy.
business-content · v0.2.0
Hold AI-written code to your bar
11 PACKS · 1 FREEThe bar for merged code does not drop because an AI wrote it: git workflow for free, then review discipline, testing, and per-language guards as add-ons.
Git Workflow
Git workflow safety: commit, branch, monorepo, and destructive-operation guards.
git-workflow · v0.3.0
Development
The development add-on. Code review discipline, test hygiene, and engineering workflow guards.
development · v0.1.0
Engineering Practices
Engineering practices: twelve-factor, code-quality, API design, and code documentation discipline.
engineering-practices · v0.2.0
Testing Discipline
Testing discipline: test design, mocking, and reliability.
testing-discipline · v0.2.0
Lang Go
Go language guardrails: error handling, concurrency, style, build, and testing.
lang-go · v0.2.0
Lang Typescript
TypeScript language guardrails: type-safety, security, dependencies, and React.
lang-typescript · v0.2.0
Lang Python
Python language guardrails: type-safety, security, dependencies, and testing.
lang-python · v0.2.0
Lang Java
Java language safety guardrails.
lang-java · v0.2.0
Lang Rust
Rust language safety guardrails.
lang-rust · v0.2.0
Lang Shell
Shell scripting safety guardrails.
lang-shell · v0.2.0
Lang SQL
SQL safety guardrails.
lang-sql · v0.2.0
Every install starts a 7-day trial of the full library, and the free packs keep working forever. Subscription and add-on packs come with your NebCore AI Platform plan, activated the moment you sign in with NebCLI.
Install NebGuardCoverage that grows with your stack
Packs ship as signed data, so protection updates without waiting for a binary release.