Skip to content

feat(v2): Massive ShieldedShell v2 Upgrade (ACOB 4-Tier Hardening & Dual-Agent Engine) - #22

Merged
connerkup merged 1 commit into
mainfrom
feat/v2-acob-upgrade
Oct 2, 2026
Merged

connerkup merged 1 commit into
mainfrom
feat/v2-acob-upgrade

Conversation

@connerkup

Copy link
Copy Markdown
Owner

Summary of ShieldedShell v2.0 Upgrade

Implements the Unified Agentic Containment & OpSec Benchmark (ACOB v2.0) hardening and dual-agent runtime across core and CLI packages, as specified in docs/VULNERABILITY_WHITE_PAPER_V2.md.

🛡️ Key Implementations

  1. Tier 2 System OpSec & Persistence Lockdown:

    • Mandated default write-deny policy for .git/hooks/**, preventing silent git hook backdoor persistence.
    • Enforced default write-deny for shell rc / profile persistence targets (.bashrc, .zshrc, .profile, .bash_profile, .config/fish/**).
    • Added execution timeouts (cpuTimeoutMs, default 30s) with active SIGTERM -> SIGKILL escalation to block CPU spinning and infinite loops.
  2. Tier 3 Runtime & Execution Integrity:

    • Anti-Spoof Assertion Token Handshake: Rejects rogue process.exit(0) assertion overrides by validating a cryptographically generated 256-bit nonce in test stdout before accepting a pass verdict.
    • Ephemeral Copy-on-Write Overlay (--ephemeral): Runs untrusted commands inside an isolated scratchpad overlay, calculates diffs, and rolls back cleanly with zero host disk mutation.
  3. Tier 4 Multi-Agent Consensus & Verifiable Receipts:

    • Verification Receipt: Produces a cryptographic receipt with Merkle tree calculation over workspace diffs, ACOB status verification, and formatted terminal output.
    • Dual-Engine CLI Loop: Orchestrates developer and auditor agent roles with policy-isolated execution.
  4. CLI & Zero-Friction Distribution:

    • Added CLI commands and flags: shieldedshell run --ephemeral, --timeout <ms>, --anti-spoof, shieldedshell loop, and shieldedshell acob.
    • Added 1-line installation scripts: curl -fsSL https://shieldedshell.com/install.sh | sh.
    • Updated documentation website landing page.

🧪 Verification

  • Unit & Integration Tests: 46/46 passing across 5 suites (npm test exits 0).
  • Live ACOB Benchmark Scorecard: 12/12 checks passing (100% compliant).
  • Website Build: Astro docs site compiles cleanly without errors.

… hardening)

- Tier 2 OpSec: Mandate default write-deny for .git/hooks/**, .bashrc, .zshrc, .profile, .bash_profile, and .config/fish/** in PolicyEngine; add configurable execution timeout cpuTimeoutMs (default 30,000ms) with SIGTERM/SIGKILL escalation in runner and sandbox.
- Tier 3 Runtime Integrity: Implement anti-spoof assertion handshake (rejecting rogue process.exit(0) without verified cryptographic token); implement ephemeral Copy-on-Write overlay scratchpad (--ephemeral) capturing diffs and rolling back cleanly with zero host disk mutation.
- Tier 4 Multi-Agent Consensus: Add cryptographic VerificationReceipt generation (Merkle root of workspace diffs, 4-tier ACOB status, verifiable signature, clean terminal card) and dual-engine loop orchestration support.
- CLI Integration: Support shieldedshell run --ephemeral, --timeout <ms>, --anti-spoof; shieldedshell loop --dev <engine> --audit <engine> --goal <prompt>; shieldedshell acob benchmark scorecard command.
- Verification: Add comprehensive v2 test suite in packages/core/src/v2-acob.test.ts (all 46 tests passing across 5 test suites, 12/12 ACOB checks passing).
@vercel

vercel Bot commented Oct 2, 2026

Copy link
Copy Markdown

The latest updates on your projects. Learn more about Vercel for GitHub.

Project Deployment Actions Updated
shielded-shell-website Error Error Oct 2, 2026 8:30pm UTC

@cloudflare-workers-and-pages

Copy link
Copy Markdown

Deploying shielded-shell with  Cloudflare Pages  Cloudflare Pages

Latest commit: fbd0fe6
Status: ✅  Deploy successful!
Preview URL: https://833a4e72.shielded-shell.pages.dev
Branch Preview URL: https://feat-v2-acob-upgrade.shielded-shell.pages.dev

View logs

@connerkup
connerkup merged commit 4a4a73e into main Oct 2, 2026
9 of 10 checks passed
@connerkup
connerkup deleted the feat/v2-acob-upgrade branch October 2, 2026 20:32

This branch had an error being deployed

1 failed deployment
Preview — fbd0fe65 Deployed Oct 2, 2026 by vercel[bot]
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant