Skip to content

Install

sloprail runs inside your agent as a plugin, and its hooks call a separate set of binaries (sr, sr-session, sr-file, sr-mark, sr-agent, sr-eval). The plugin installs those itself, so installing the plugin is the whole install.

Terminal window
/plugin marketplace add sloprail/sloprail
/plugin install sloprail@sloprail-marketplace

Pick the project scope. The hooks are registered; a project with a .sloprail/ directory is now guarded, and a project with none is an ordinary project until its first rule.

More harnesses will get their own tab as they go live. The engine’s contract — hook points in, events out — isn’t specific to one, so the rules a project writes don’t change between them.

The first session after the install fetches them, once: the GitHub release matching the plugin’s version (never “latest”), verified against the release’s checksums, into ~/.local/bin (set SLOPRAIL_INSTALL_DIR to choose another directory). The session says it is doing this, and says so loudly if it fails.

To install them yourself instead, set SLOPRAIL_NO_AUTO_INSTALL=1 and run

Terminal window
curl -fsSL https://raw.githubusercontent.com/sloprail/sloprail/main/install.sh | sh

or, with Go, go install ./services/... from a checkout of sloprail/sloprail. Either way, if the binaries are missing the next file write is refused with the install command, never silently let through.

A missing binary does not, however, block a plain shell command — a git commit guarded only by a gate on Bash goes through silently if sr-session can’t be found, since there is no file write for that check to attach to. Confirm the install actually worked (see below) before you rely on a guardrail whose action runs through Bash rather than a file write.

Terminal window
sr-session --version

should print a version, not a “command not found” error. If you skipped step 1 or ~/.local/bin isn’t on $PATH, this is how you find out — check it before trying a guardrail, especially one that guards a Bash command rather than a file write. Once it prints a version, a file-write guardrail’s own missing-binary refusal (the install command, repeated until it can find sr-session) is the fallback safety net, not the first check.

Write your first guardrail and watch it refuse — the Quickstart.