ShieldedShell
Run coding agents in a bounded workspace. Orchestrate developer and auditor loops with reconciler gates.
Public Beta (v2.0). The Unified Agentic Containment & OpSec Engine. Feedback welcome on GitHub Issues.
1-Line Quick Install
Section titled “1-Line Quick Install”curl -fsSL https://shieldedshell.com/install.sh | shOr install via npm:
npm install -g @shieldedshell/cli@betashieldedshell initshieldedshell doctorThe 4-Tier Containment Architecture (ACOB v2.0)
Section titled “The 4-Tier Containment Architecture (ACOB v2.0)”ShieldedShell bridges OS-level containment with autonomous multi-agent execution integrity:
- Tier 1: OS Boundary & Perimeter — Credential masking (AWS SIGv4, JWT), symlink traversal traps, PID namespace isolation, and egress loopback proxy.
- Tier 2: System OpSec & Persistence Defense — Mandatory default-deny on
.git/hooks/**(blocking backdoor injection), shell rc write locks, and CPU timeout escalation. - Tier 3: Execution & Runtime Integrity — Ephemeral Copy-on-Write (
--ephemeral) overlay scratchpads with zero host disk mutation, and cryptographic anti-spoof assertion verification. - Tier 4: Multi-Agent Game Theory — Asymmetric spatial partitioning for developer and auditor agents, verifiable consensus receipts, and non-LLM interval/Datalog invariant solvers.
Packages: @shieldedshell/cli · @shieldedshell/core