Overview
dsh-risk-gate
README / EN
Package documentation
Registry summary
dsh.pub verifies the pinned bundle contract, runtime facts, and distribution semantics. The complete README remains in the source repository.
Read the full README on GitHubLIMITATIONS
Known limitations
- Shell inspection is regex-based (no full shell parsing): designed to be conservative (false positives over misses), but a determined prompt can still smuggle commands through obfuscation. It is a **safety gate, not a sandbox** — pair with `dsh-permission-rules` / sandbox executors for defense in depth. - Learning state is in-memory only (no persistence across restarts yet). - Approval UI is channel-provided; headless with no answerer fails closed (deny).
