feat(v2): Massive ShieldedShell v2 Upgrade (ACOB 4-Tier Hardening & Dual-Agent Engine) - #22
Merged
Merged
Conversation
… hardening) - Tier 2 OpSec: Mandate default write-deny for .git/hooks/**, .bashrc, .zshrc, .profile, .bash_profile, and .config/fish/** in PolicyEngine; add configurable execution timeout cpuTimeoutMs (default 30,000ms) with SIGTERM/SIGKILL escalation in runner and sandbox. - Tier 3 Runtime Integrity: Implement anti-spoof assertion handshake (rejecting rogue process.exit(0) without verified cryptographic token); implement ephemeral Copy-on-Write overlay scratchpad (--ephemeral) capturing diffs and rolling back cleanly with zero host disk mutation. - Tier 4 Multi-Agent Consensus: Add cryptographic VerificationReceipt generation (Merkle root of workspace diffs, 4-tier ACOB status, verifiable signature, clean terminal card) and dual-engine loop orchestration support. - CLI Integration: Support shieldedshell run --ephemeral, --timeout <ms>, --anti-spoof; shieldedshell loop --dev <engine> --audit <engine> --goal <prompt>; shieldedshell acob benchmark scorecard command. - Verification: Add comprehensive v2 test suite in packages/core/src/v2-acob.test.ts (all 46 tests passing across 5 test suites, 12/12 ACOB checks passing).
|
The latest updates on your projects. Learn more about Vercel for GitHub.
|
Deploying shielded-shell with
|
| Latest commit: |
fbd0fe6
|
| Status: | ✅ Deploy successful! |
| Preview URL: | https://833a4e72.shielded-shell.pages.dev |
| Branch Preview URL: | https://feat-v2-acob-upgrade.shielded-shell.pages.dev |
This branch had an error being deployed
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Summary of ShieldedShell v2.0 Upgrade
Implements the Unified Agentic Containment & OpSec Benchmark (ACOB v2.0) hardening and dual-agent runtime across core and CLI packages, as specified in
docs/VULNERABILITY_WHITE_PAPER_V2.md.🛡️ Key Implementations
Tier 2 System OpSec & Persistence Lockdown:
.git/hooks/**, preventing silent git hook backdoor persistence..bashrc,.zshrc,.profile,.bash_profile,.config/fish/**).cpuTimeoutMs, default 30s) with activeSIGTERM->SIGKILLescalation to block CPU spinning and infinite loops.Tier 3 Runtime & Execution Integrity:
process.exit(0)assertion overrides by validating a cryptographically generated 256-bit nonce in test stdout before accepting a pass verdict.--ephemeral): Runs untrusted commands inside an isolated scratchpad overlay, calculates diffs, and rolls back cleanly with zero host disk mutation.Tier 4 Multi-Agent Consensus & Verifiable Receipts:
CLI & Zero-Friction Distribution:
shieldedshell run --ephemeral,--timeout <ms>,--anti-spoof,shieldedshell loop, andshieldedshell acob.curl -fsSL https://shieldedshell.com/install.sh | sh.🧪 Verification
npm testexits 0).