SecurityRonin / pipeguard Star 0 Code Issues Pull requests Defense-in-depth against curl|bash attacks. Four-layer shell interception (accept-line, ZLE paste, hardened wrappers, preexec audit) with YARA-based detection. Catches malicious piped installs before execution — where macOS Gatekeeper can't. macos supply-chain-security shell-security Updated Feb 14, 2026 Rust
madeinplutofabio / command-scope-contract Star 0 Code Issues Pull requests Protocol for bounded shell and CLI execution with explicit scope, policy, and provenance for AI agents. mcp provenance command-execution policy-engine ai-agents open-protocol capability-security agentic-ai agent-safety shell-security Updated Mar 20, 2026 Python