Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
6 changes: 0 additions & 6 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,12 +11,6 @@ Commands are restricted to a curated set of read-only tools. Destructive operati
- `sed` -> `"Stream editing can modify files -- read-only access only. Use grep for searching."`
- `$HOME/file` -> `"Variable expansion will not expand. Use absolute paths."`

## Demo

Here's a demo of ShellGuard with [OpenCode](https://opencode.ai) against a simulated server. It works extremely well against real servers too.

<video src="https://raw.githubusercontent.com/jonchun/shellguard/refs/heads/main/docs/videos/shellguard-demo.mp4" controls width="100%"></video>

## Quick Start

### Install
Expand Down
20 changes: 20 additions & 0 deletions manifest/manifests/journalctl.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,26 @@ flags:
takes_value: true
- flag: "--until"
takes_value: true
- flag: "-p"
takes_value: true
- flag: "--priority"
takes_value: true
- flag: "--no-pager"
- flag: "-t"
takes_value: true
- flag: "--identifier"
takes_value: true
- flag: "-k"
- flag: "--dmesg"
- flag: "-b"
- flag: "-o"
takes_value: true
- flag: "--output"
takes_value: true
- flag: "-r"
- flag: "--reverse"
- flag: "-x"
- flag: "--catalog"
- flag: "-f"
deny: true
reason: "Follow mode hangs until timeout. Use --since/--until for bounded queries."
Expand Down
9 changes: 9 additions & 0 deletions manifest/manifests/ps.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -6,5 +6,14 @@ flags:
- flag: "-f"
- flag: "-o"
takes_value: true
- flag: "--sort"
takes_value: true
- flag: "-p"
takes_value: true
- flag: "-u"
takes_value: true
- flag: "-C"
takes_value: true
- flag: "--no-headers"
stdin: false
stdout: true
1 change: 1 addition & 0 deletions manifest/manifests/systemctl_list-units.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -4,5 +4,6 @@ category: services
flags:
- flag: "--type"
takes_value: true
- flag: "--failed"
stdin: false
stdout: true
8 changes: 8 additions & 0 deletions manifest/manifests/top.yaml
Original file line number Diff line number Diff line change
Expand Up @@ -5,6 +5,14 @@ flags:
- flag: "-b"
- flag: "-n"
takes_value: true
- flag: "-o"
takes_value: true
- flag: "-p"
takes_value: true
- flag: "-u"
takes_value: true
- flag: "-w"
takes_value: true
- flag: "-d"
deny: true
reason: "Only batch mode with fixed iteration count is allowed"
Expand Down