guard

package
v0.3.15 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 7, 2026 License: AGPL-3.0 Imports: 7 Imported by: 0

Documentation

Overview

Package guard implements the safety boundary layer (docs §11): an audit log, user-configured intercept-rule evaluation, and Observer/G5 failure attribution. Every tool call passes through the PreToolUse hook before executing. (The RoE authorization-scope mechanism was removed; a replacement may be added later.) Destructive/exfil gating is no longer hard-coded here — it lives in the DB intercept rules (seeded as ordinary [内置] rules, so users can disable or delete them), evaluated via applyIntercept.

Index

Constants

This section is empty.

Variables

This section is empty.

Functions

This section is empty.

Types

type AuditEntry

type AuditEntry struct {
	TS      int64  `json:"ts"`
	Tool    string `json:"tool"`
	Action  string `json:"action"` // allow|block
	Reason  string `json:"reason,omitempty"`
	Command string `json:"command,omitempty"`
}

AuditEntry records one gated tool call.

type Guard

type Guard struct {
	// contains filtered or unexported fields
}

Guard enforces the side-effect policy via agent-core hooks.

func New

func New() *Guard

New creates a Guard without user-configured intercept rules (used for pentest tasks where the Interceptor is not yet available).

func NewWithInterceptor

func NewWithInterceptor(ic *intercept.Interceptor) *Guard

NewWithInterceptor creates a Guard with user-configured intercept rules.

func (*Guard) Attributions

func (g *Guard) Attributions() map[string]int

Attributions returns failure-attribution counts (Observer / G5).

func (*Guard) Audit

func (g *Guard) Audit() []AuditEntry

Audit returns a snapshot of recent gated calls (most recent last).

func (*Guard) Hooks

func (g *Guard) Hooks() *hook.Registry

Hooks returns the hook registry to attach to an agent session.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL