tirith
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
File Explorer
Download Latest Version (.zip)- audit.toml
- tirith-check.py
- settings.json
- mcp.json
- dogfood-report.md
- fetch-threatdb-sources.sh
- test-fetch-threatdb-sources.sh
- bench.yml
- ci.yml
- fuzz.yml
- release.yml
- threatdb.yml
- dependabot.yml
- FUNDING.yml
- cover.png
- tirith-gateway.yaml
- popular_packages.csv
- copilot-cli-hook.py
- cursor-hook.sh
- kiro-hook.py
- openclaw-tirith-guard.ts
- tirith-check.py
- tirith-guard.ts
- tirith-security-guard-gemini.py
- vscode-hook.sh
- windsurf-hook.sh
- zshenv-guard.zsh
- threatdb-verify.pub
- loader_cross_dist.pth
- pth_benign_editable.pth
- pth_cross_runtime.pth
- pth_subprocess.pth
- README.md
- ai-agent-heavy.yaml
- ci-strict.yaml
- enterprise.yaml
- individual.yaml
- mcp-strict.yaml
- oss-maintainer.yaml
- startup.yaml
- bash-hook.bash
- fish-hook.fish
- nushell-hook.nu
- powershell-hook.ps1
- zsh-hook.zsh
- tirith.sh
- lab_corpus.toml
- mal-2025-6812.json
- mal-2026-2307.json
- tirith_threatdb_compile.rs
- fs_helpers.rs
- fs_helpers_windows.rs
- fs_helpers_windows_path.rs
- fs_transaction.rs
- merge.rs
- mod.rs
- shell_profile.rs
- tools.rs
- zshenv.rs
- agent.rs
- ai.rs
- aliases.rs
- audit.rs
- baseline.rs
- bash_capability.rs
- browser.rs
- browser_host.rs
- canary.rs
- capsule.rs
- capsule_child.rs
- capsule_proxy.rs
- capsule_windows.rs
- check.rs
- checkpoint.rs
- clipboard.rs
- codespaces.rs
- command_card.rs
- commands.rs
- completions.rs
- context.rs
- daemon.rs
- dashboard.rs
- devcontainer.rs
- diff.rs
- doctor.rs
- ecosystem.rs
- env_guard.rs
- exec.rs
- explain.rs
- fetch.rs
- fix.rs
- gateway.rs
- hook_event.rs
- hooks.rs
- hygiene.rs
- iac.rs
- incident.rs
- init.rs
- install.rs
- intent.rs
- lab.rs
- lab_artifacts.rs
- last_trigger.rs
- license_cmd.rs
- logs.rs
- lsp.rs
- manpage.rs
- mcp.rs
- mcp_server.rs
- mod.rs
- onboard.rs
- output_guard.rs
- package.rs
- paste.rs
- path.rs
- pending.rs
- persistence.rs
- pkg.rs
- pkg_install.rs
- policy.rs
- preview.rs
- prompt_status.rs
- provenance.rs
- pypi_integrity.rs
- receipt.rs
- rule.rs
- run.rs
- scan.rs
- score.rs
- secret.rs
- selfupdate.rs
- share.rs
- ssh.rs
- status.rs
- sudo.rs
- taint.rs
- temp_run.rs
- test_harness.rs
- threatdb_cmd.rs
- trust.rs
- view.rs
- visual_audit.rs
- warnings.rs
- why.rs
- yaml.rs
- assets.rs
- main.rs
- package.json
- package.json
- package.json
- README.md
- mod.rs
- bash_hook_exports.rs
- bash_preexec_enforce.rs
- cli_integration.rs
- help_snapshots.rs
- lab_artifact_scenarios.rs
- registry_api_integration.rs
- release_security.rs
- shell_conformance.rs
- Cargo.toml
- template.html
- confusables.txt
- credential_patterns.toml
- exfil_endpoints.txt
- known_domains.csv
- ocr_confusions.tsv
- popular_repos.csv
- prompt_injection_seeds.txt
- public_suffix_list.dat
- rule_explanations.toml
- sensitive_env.toml
- share_patterns.toml
- text_confusables.txt
- threatdb-verify.pub
- perf.rs
- archive.rs
- correlate.rs
- firewall.rs
- inspect.rs
- install.rs
- mod.rs
- native.rs
- pth.rs
- quarantine.rs
- record.rs
- release_diff.rs
- resolver.rs
- resolver_broker.rs
- wheel.rs
- linux.rs
- macos.rs
- mod.rs
- windows.rs
- shell_receipt.rs
- content.rs
- dispatcher.rs
- mod.rs
- origin.rs
- output_filter.rs
- resources.rs
- response_inspect.rs
- tools.rs
- types.rs
- dns.rs
- mod.rs
- shorturl.rs
- graph.rs
- mod.rs
- pypi_integrity.rs
- aifile.rs
- cifile.rs
- cloaking.rs
- codefile.rs
- command.rs
- configfile.rs
- container.rs
- context.rs
- credential.rs
- custom.rs
- ecosystem.rs
- environment.rs
- exfil.rs
- hostname.rs
- iac.rs
- install.rs
- mcpdrift.rs
- mod.rs
- output.rs
- paste_provenance.rs
- path.rs
- powershell.rs
- prompt_injection.rs
- rendered.rs
- shared.rs
- ssh_context.rs
- sudo.rs
- terminal.rs
- threatintel.rs
- transport.rs
- windows.rs
- contained_fs.rs
- agent_origin.rs
- aliases.rs
- approval.rs
- audit.rs
- audit_aggregator.rs
- audit_tune.rs
- audit_upload.rs
- baseline.rs
- blast_radius.rs
- canary.rs
- checkpoint.rs
- clipboard.rs
- command_card.rs
- commands_manifest.rs
- confusables.rs
- context_detect.rs
- custom_rule_dsl.rs
- dashboard.rs
- data.rs
- deobfuscate.rs
- dep_confusion.rs
- devcontainer_writer.rs
- ecosystem_scan.rs
- engine.rs
- env_guard.rs
- escalation.rs
- event_buffer.rs
- exec_provenance.rs
- execution_state.rs
- extract.rs
- homoglyph.rs
- hygiene.rs
- iac_plan.rs
- incident.rs
- install_script_analysis.rs
- install_txn.rs
- intent.rs
- lib.rs
- license.rs
- location.rs
- lsp_profiles.rs
- mcp_lock.rs
- normalize.rs
- osv_correlation.rs
- output.rs
- package_risk.rs
- parse.rs
- path_audit.rs
- pending.rs
- persistence.rs
- policy.rs
- policy_client.rs
- policy_ignored.rs
- policy_migrations.rs
- policy_validate.rs
- receipt.rs
- redact.rs
- registry_api.rs
- registry_history.rs
- repo_hooks.rs
- repo_mismatch.rs
- rule_explanations.rs
- rule_metadata.rs
- runner.rs
- safe_command.rs
- sarif.rs
- scan.rs
- scoring.rs
- script_analysis.rs
- secret_rotation.rs
- selfupdate.rs
- session.rs
- session_warnings.rs
- ssrf_guard.rs
- style.rs
- sudo_session.rs
- suppression.rs
- taint.rs
- text_confusables.rs
- threatdb.rs
- threatdb_api.rs
- threatdb_feeds.rs
- tokenize.rs
- trusted_child.rs
- url_validate.rs
- util.rs
- util_build_dirs.rs
- verdict.rs
- version_intent.rs
- webhook.rs
- bypass_regression.rs
- generate_test_fixtures.rs
- golden_fixtures.rs
- policy_integration.rs
- safe_command_integration.rs
- trusted_child.rs
- trusted_child_windows.rs
- trusted_child_windows_policy.rs
- build.rs
- Cargo.toml
- confusables.txt
- known_domains.csv
- popular_repos.csv
- public_suffix_list.dat
- agent-governance-design.md
- browser-native-messaging.md
- canary-formats.md
- capability-manifest.toml
- capability-matrix.md
- capsule.md
- commands.md
- compatibility.md
- cookbook.md
- doctor-modes.md
- dogfood-guide.md
- homebrew-core.md
- lsp-profiles.md
- mcp-output-filter.md
- paste-provenance.md
- prompt-integration.md
- prompt-status.md
- release-checklist.md
- roadmap.md
- security.md
- shell-hook-conformance.md
- threat-model.md
- threatdb-v2-rollout.md
- troubleshooting.md
- uninstall.md
- artifact_wheel.rs
- byte_scanner.rs
- extractor.rs
- normalizer.rs
- tokenizer_fish.rs
- tokenizer_posix.rs
- tokenizer_powershell.rs
- url_parser.rs
- Cargo.toml
- claude-code.md
- codex.md
- copilot-cli.md
- cursor.md
- E2E-CHECKLIST.md
- gemini-cli.md
- kiro.md
- openclaw.md
- pi-cli.md
- vscode.md
- windsurf.md
- tirith-gateway.yaml
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- package.json
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- package.json
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- package.json
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- package.json
- tirith
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- package.json
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- package.json
- PKGBUILD
- tirith.install
- chocolateyinstall.ps1
- chocolateyuninstall.ps1
- tirith.nuspec
- tirith.rb
- tirith.toml
- tirith.spec
- tirith.json
- install.ps1
- codex-upgrade-smoke.sh
- install.sh
- update-data.sh
- bash-hook.bash
- fish-hook.fish
- nushell-hook.nu
- powershell-hook.ps1
- zsh-hook.zsh
- tirith.sh
- aifile.toml
- cifile.toml
- clean.toml
- codefile.toml
- command.toml
- configfile.toml
- credential.toml
- custom_rules_dsl.yaml
- documented_commands.toml
- ecosystem.toml
- environment.toml
- hostname.toml
- injection_evasion.toml
- output.toml
- path.toml
- policy.toml
- README.md
- rendered.toml
- shell_weirdness.toml
- terminal.toml
- test-threatdb.dat
- threatintel.toml
- transport.toml
- verify_sha256.sh
- openclaw-shell-resolver.mjs
- health.rs
- mod.rs
- receipt.rs
- refresh.rs
- webhook.rs
- config.rs
- db.rs
- error.rs
- main.rs
- sign.rs
- state.rs
- webhook_verify.rs
- Cargo.toml
- main.rs
- secure_file_windows.rs
- Cargo.toml
- .dockerignore
- .gitattributes
- .gitignore
- .pre-commit-hooks.yaml
- action.yml
- Cargo.lock
- Cargo.toml
- CHANGELOG.md
- deny.toml
- Dockerfile
- flake.lock
- flake.nix
- LICENSE-AGPL
- LICENSE-COMMERCIAL
- NOTICE
- README.md
- rustfmt.toml
- SECURITY.md
- SKILL.md
- threatdb-manifest.json
- TIRITH.md
# Installation Guide
git clone https://github.com/sheeki03/tirith
Downloads the entire project code from GitHub to your computer.
cd tirith
Moves into the project folder you just downloaded.
2. Official Install Script
Easy Recommended- Homebrew A package manager for macOS/Linux.
- Scoop A package manager for Windows.
- Chocolatey A package manager for Windows.
- Node.js Node.js must be installed to use npm.
brew install tirith
Installs the pre-built package via Homebrew β no source build required.
scoop install tirith
Installs directly via Scoop (Windows).
choco install tirith
Installs directly via Chocolatey (Windows).
npm install -g tirith
Installs the package published on the npm registry globally β no need to clone the source.
Pulled directly from this repo's README.
3. Docker
Easy- Git Needed to download the project code from GitHub.
- Docker Desktop Needed to build and run containers. Install it and keep it running in the background.
$ curl -fsSL https://get.docker.com | sh
Downloads and runs the official install script in one line β this handles the full setup automatically.
$ docker compose up -d
Builds and starts all defined containers (server, database, etc.) at once, in the background.
docker run --rm ghcr.io/sheeki03/tirith check -- "curl https://example.com | bash"
Downloads and runs the official install script in one line β this handles the full setup automatically.
- "get.docker.com"
Type this command into your terminal and run it.
tirith trust add get.docker.com --broad --rule curl_pipe_shell
Type this command into your terminal and run it.
Pulled directly from this repo's README.
4. Node.js
Easytirith package risk npm react # 0/100, a known-popular package
Type this command into your terminal and run it.
tirith package risk npm reqeusts # high, one edit from a popular name
Type this command into your terminal and run it.
tirith package risk npm left-pad --path ./node_modules/left-pad
Type this command into your terminal and run it.
tirith package risk --online npm react # also consult the registry API
Type this command into your terminal and run it.
npm install -g tirith
Installs the package published on the npm registry globally β no need to clone the source.
Pulled directly from this repo's README.
5. Rust
Medium- Git Needed to download the project code from GitHub.
- Rust (rustup) Installing via rustup also installs cargo.
cargo install tirith
Builds and installs the package published on crates.io β no need to clone the repo yourself.
Pulled directly from this repo's README.
