Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.
-
Updated
Aug 10, 2026 - TypeScript
Pi guardrails that keep LLM shell and file access safe, transparent, and user-approved.
Bounded shell and CLI execution for AI agents: structured contracts, policy-gated execution, hardened Linux runtime enforcement, and signed receipts.
Semantic paste firewall for Linux terminals that warns before risky copied shell commands run.
Windows safety layer for AI coding agents, protecting Git worktrees and important folders from destructive shell commands.
Shellsafe - Trust Layer for AI Agent Skills
Security skills for Minis on iOS: agent operational safety and prompt-injection defense.
AI-powered shell command interceptor built with Rust. Analyzes command intent via Gemini API and provides risk-based control (Pass/Warning/Block) in real-time.
Defense-in-depth against curl|bash attacks. Four-layer shell interception (accept-line, ZLE paste, hardened wrappers, preexec audit) with YARA-based detection. Catches malicious piped installs before execution — where macOS Gatekeeper can't.
Compiler-style pre-execution safety analysis for AI agent shell actions.
Add a description, image, and links to the shell-security topic page so that developers can more easily learn about it.
To associate your repository with the shell-security topic, visit your repo's landing page and select "manage topics."