Protocol for bounded shell and CLI execution with explicit scope, policy, and provenance for AI agents.
-
Updated
Mar 20, 2026 - Python
Protocol for bounded shell and CLI execution with explicit scope, policy, and provenance for AI agents.
Defense-in-depth against curl|bash attacks. Four-layer shell interception (accept-line, ZLE paste, hardened wrappers, preexec audit) with YARA-based detection. Catches malicious piped installs before execution — where macOS Gatekeeper can't.
Claude Code safety guard plugin. AST-based bash command classification
Add a description, image, and links to the shell-security topic page so that developers can more easily learn about it.
To associate your repository with the shell-security topic, visit your repo's landing page and select "manage topics."