Security
Policy summary. The full statement lives on the
Security & trust page and in the
repository's SECURITY.md.
Scope
AIGuard is an Execution-Layer Security tool — a guardrail, not a sandbox. Its threat model is the honest-but-fallible assistant: friction, authentication, and an audit trail around dangerous shell commands. It does not defend against a deliberately adversarial agent, and it does not gate file writes or network access performed without spawning a command.
Guarantees, briefly
- AIGuard fails closed; the host platforms fail open on hook timeout or crash.
- Approvals are single-use, bound to the exact command string (SHA-256, truncated to 12 hex chars), and expire after 5 minutes.
- Absolute Blocks cannot be overridden by approval or user policy.
~/.aiguard/is 0700; state files are 0600; the audit log records every command verbatim.
Reporting a vulnerability
Private reports only
Report security issues via a GitHub Security Advisory, not a public issue. While the repository is private, contact the maintainer directly. Include the affected version, platform, assistant and its version, reproduction steps, and whether the issue bypasses policy evaluation or approval.
Supported versions
| Version | Supported |
|---|---|
| 6.1.0bx (Beta) | Latest pre-release only |
| < 6.1 | No |