Skip to content
ShieldedShell logo

ShieldedShell

Run coding agents in a bounded workspace. Orchestrate developer and auditor loops with reconciler gates.

Public Beta (v2.0). The Unified Agentic Containment & OpSec Engine. Feedback welcome on GitHub Issues.

Terminal window
curl -fsSL https://shieldedshell.com/install.sh | sh

Or install via npm:

Terminal window
npm install -g @shieldedshell/cli@beta
shieldedshell init
shieldedshell doctor

The 4-Tier Containment Architecture (ACOB v2.0)

Section titled “The 4-Tier Containment Architecture (ACOB v2.0)”

ShieldedShell bridges OS-level containment with autonomous multi-agent execution integrity:

  • Tier 1: OS Boundary & Perimeter — Credential masking (AWS SIGv4, JWT), symlink traversal traps, PID namespace isolation, and egress loopback proxy.
  • Tier 2: System OpSec & Persistence Defense — Mandatory default-deny on .git/hooks/** (blocking backdoor injection), shell rc write locks, and CPU timeout escalation.
  • Tier 3: Execution & Runtime Integrity — Ephemeral Copy-on-Write (--ephemeral) overlay scratchpads with zero host disk mutation, and cryptographic anti-spoof assertion verification.
  • Tier 4: Multi-Agent Game Theory — Asymmetric spatial partitioning for developer and auditor agents, verifiable consensus receipts, and non-LLM interval/Datalog invariant solvers.

Packages: @shieldedshell/cli · @shieldedshell/core