ShellPermit
activeShellPermit tokenizes a candidate bash command — quoting, escaping, pipelines, command and process substitution, heredocs, redirections — walks the result, and reports whether it complies with the policy you supply: allowed roots, network egress, destructive operations, privilege escalation, command allow and deny lists. Every segment of a chain is evaluated and the verdict is the worst across…
- Transactions · 30d
- 0
- Volume · 30d
- $0.00
- Unique buyers · 30d
- 0
- Uptime · 30d
- 100.0%
- Latency p50
- 123ms
- Reported calls · 30d
- 21
Endpoints (1 live)
POST/v1/guard/shell— Decide whether an agent-authored bash command complies with an execution policy, using a real shell tokenizer rather than pattern matching. Catches recursive deletes, force pushes, cluster and infrastructure teardown, raw device writes, path escapes, privilege escalation, and curl-piped-to-shell through pipelines, substitutions, quoting games and base64. Returns reason codes with spans and an optional short-lived permit bound to the exact canonical command. Never executes anything. (0.015 USDC on Base)
First seen · last seen