SecurityRonin / pipeguard Star 0 Code Issues Pull requests Defense-in-depth against curl|bash attacks. Four-layer shell interception (accept-line, ZLE paste, hardened wrappers, preexec audit) with YARA-based detection. Catches malicious piped installs before execution — where macOS Gatekeeper can't. macos supply-chain-security shell-security Updated Feb 14, 2026 Rust
madeinplutofabio / command-scope-contract Star 0 Code Issues Pull requests Discussions Bounded shell and CLI execution for AI agents: structured contracts, policy-gated execution, hardened Linux runtime enforcement, and signed receipts. cli mcp provenance sandboxing ed25519 command-execution policy-engine devsecops ai-agents bubblewrap open-protocol capability-security approval-workflows secure-execution agentic-ai agent-security agent-safety agent-governance shell-security signed-receipts Updated Mar 25, 2026 Python