---
name: sigmashake
license: LicenseRef-SigmaShake-Proprietary
description: >
  Adopt and use SigmaShake so AI agent tool calls are governed before they
  run. ssg evaluates each tool call against declarative rules and returns a
  decision the agent must follow. Use when installing ssg, onboarding a
  repository, wiring an agent host, writing or tuning rules, or deciding
  whether a behavior belongs in a rule or in ordinary code. Also use when
  a task needs a safer substitute for a blocked command, or when an install
  or rule change must be verified. Read the live docs before inventing
  install flags, rule syntax, prices, or API fields.
---

# Use SigmaShake

SigmaShake governs AI agent tool calls. **ssg** checks each call against the rules in `.sigmashake/rules/` before the tool runs, and returns a decision. The rules own policy. The agent carries the decision out. A DENY stops the call. A FORCE names the safer command to run instead.

SigmaShake is free to download and install. A **$5/month** subscription unlocks the governed value surfaces: evaluation, the dashboard, hub rule bodies, metering, and fleet. There is no free tier and no trial of that value. Those gates fail closed without a verified subscription. SigmaShake is a sole-operator individual entity (USA).

The `ssg` binary is proprietary software. The [license](https://docs.sigmashake.com/policies/license) is the rights statement. This skill tells an agent how to read the docs and onboard a project. It is not a grant to redistribute the binary.

## Read the live docs

**The live docs are the source of truth. Read them as part of the task.** This skill gives direction. The docs carry the current install flags, rule language, host integrations, and limits.

- Start with the [documentation index](https://docs.sigmashake.com/llms.txt). Pick the pages for this task. Do not load the whole site.
- Doc pages are HTML. Fetch the URL from the index. Do not invent a `.md` suffix. If a fetch fails, open the normal page.
- Before installing, wiring a host, or writing a rule, read the page for that task. If the index is unavailable, use the direct links below. If live access is unavailable, say so, and do not invent flags, ports, prices, or operators.

| Task | Start here |
| --- | --- |
| Install and reach a first governed session | [Getting Started](https://docs.sigmashake.com/getting-started), [Agent Install Guide](https://docs.sigmashake.com/agent-install-guide) |
| Install this skill | [Agent skill](https://docs.sigmashake.com/agent-skill) |
| Understand the product | [Introduction](https://docs.sigmashake.com/), [why SigmaShake](https://docs.sigmashake.com/why-sigmashake) |
| Write a rule | [Rule syntax](https://docs.sigmashake.com/rule-syntax), [operators](https://docs.sigmashake.com/operators), [fields](https://docs.sigmashake.com/fields), [writing rules](https://docs.sigmashake.com/writing-rules) |
| Wire an agent host | [Adapters](https://docs.sigmashake.com/adapters), [MCP](https://docs.sigmashake.com/mcp), [Grok Bot](https://docs.sigmashake.com/grok-bot) |
| See what a subscription unlocks | [Plans and limits](https://docs.sigmashake.com/plans-and-limits), [pricing](https://sigmashake.com/pricing) |
| See what install writes to disk | [What SSG changes](https://docs.sigmashake.com/what-ssg-changes) |

When two docs disagree, follow [Getting Started](https://docs.sigmashake.com/getting-started) and the [Agent Install Guide](https://docs.sigmashake.com/agent-install-guide) for install and for what is free versus paid, and say which pages you read.

## Onboard in one command

Follow the [Agent Install Guide](https://docs.sigmashake.com/agent-install-guide). Do not add steps, flags, or config-file edits it does not list.

Non-interactive install (no TTY). The consent flag is required. Without it the installer fails closed:

```bash
curl -fsSL https://install.sigmashake.com | sh -s -- -y
```

Windows (PowerShell pipe form):

```powershell
iwr -useb https://install.sigmashake.com/install.ps1 | iex
```

Pass `-Yes` when you need non-interactive consent on Windows.

Then onboard this project. Prefer the MCP tool `ssg_onboard` when it is available. Otherwise:

```bash
ssg init --smart --client=<host>
```

Host names are on the Agent Install Guide. Run `ssg init --list` if you are unsure. Use `--dry-run` when you should show writes before applying them.

Grok Bot does not use local `ssg init --client`. Follow the [Grok Bot](https://docs.sigmashake.com/grok-bot) page and the hosted MCP server.

SigmaShake Desktop is optional. If you install it, leave the first-run license and terms gate fail-closed. Do not tell the user to skip that gate.

Activating a subscription is the human's step (`ssg auth login`, or a license key they already hold). Point them at https://sigmashake.com/pricing. Do not invent a license key, and do not repeat a key in chat, rules, or commits.

On any failure, run `ssg probe onboard`, parse the single JSON object, and execute `nextStep` verbatim until `ok` is true. Do not pattern-match `findings` text.

Cargo is not an install channel for ssg.

## Find the useful shape

Start from what the user wants the agent to be allowed to do. Keep builds, tests, formatting, and exact lookups in ordinary code. Add a rule where a tool call needs a policy decision.

- **Block a dangerous action.** A destructive command, a secret read, or an unreviewed publish is a DENY or an ASK. The condition lives in a rule file, not only in a prompt.
- **Hand back the safe command.** When the repo already has a gated path for build, test, or push, use FORCE so the agent runs that path. A block with no substitute stalls the work.
- **Onboard the repo you are in.** `ssg init --smart` or `ssg_onboard` detects the stack and installs starter rules. Do not hand-author a second policy beside that.
- **One rules source, many agents.** Wire each host with `ssg init --client=<host>`. Do not invent another config format. See [one source, many agents](https://docs.sigmashake.com/one-source-many-agents).
- **Watch before you tighten.** LOG or SHADOW when you need to see the action without blocking it. Promote to DENY or ASK after you have seen real calls.
- **Prove the session is governed.** `ssg probe onboard` is the check. A rule that did not load is not governing anything.

For "set up SigmaShake", use the one-command path above. For a concrete policy ("block npm publish unless I approve"), write that rule and run `ssg lint`.

## Design the rule

Read the syntax, operators, and fields pages before writing a rule. Pick the decision by what should happen to the tool call:

| Need | Decision |
| --- | --- |
| Stop the tool call | DENY |
| Let a person decide | ASK |
| Run a known safer command instead | FORCE |
| Keep an audit row only | LOG |
| Observe without enforcing | SHADOW |
| Permit a case a broader rule would catch | ALLOW |

One rule, one condition. Name a field the fields page documents (`command`, `path`, `content`, `tool`, `input.<key>`). Use an operator the operators page documents. Keep regular expressions flat: do not put a quantifier around a group of alternatives.

Prefer `ssg new` when the writing-rules guide shows it, then `ssg lint` and `ssg rule sync`. Install a shared ruleset with the hub command the docs show. Do not paste private hub rule bodies into a public file.

A rule file that parses is not proof the policy is right. After it loads, read a sample of real decisions in the audit log the docs describe before calling a new DENY finished.

## Compose and verify

- Read the index, then the one page that matches the task.
- Do not bypass governance to finish a task: no hook disable, no `--no-verify`, no rule edit whose only purpose is to let the current command through. If a rule blocks you, follow its FORCE text or ask the user.
- Do not raise CPU or GPU power caps, and do not stop power-limit services.
- Keep license keys and tokens out of chat, rule files, and commits.
- After install or a rule change, run `ssg probe onboard` or `ssg lint` as the guide specifies. Report the command and the result.
- Treat example rules in the docs as examples. Check fields against the field reference before committing a rule into a repo.
