概览
@mokuyoaxis/agent-guard
README / ZH
插件文档
目录摘要
dsh.pub 核对固定版本的组合包契约、运行时事实与分发语义;完整 README 请查看源仓库。
在 GitHub 阅读完整 READMELIMITATIONS
已知限制
This is stated plainly, because a reliability tool that overstates its reach is a false security claim: - **Not a sandbox.** It does not prevent adversarial exfiltration. An agent that obfuscates a secret to evade the scanner is out of scope; this catches *accidents*. - **Channels with no hook are unreachable by construction.** A hosted model call with no proxy, the model's own tool calls, content produced *inside* a program, and the human clipboard get **no verdict at all** — no coverage is claimed there. See `references/channels.md` and [docs/secret-guard-analysis.md](docs/secret-guard-analysis.md) §2.4 for the reachability table this claim is traceable to. - **Not a file scanner.** It is not a gitleaks replacement; it scans what the guard can see *on the way out*. - **No history rewriting.** Detecting a secret already in Git history is a report at most. Rewriting history is a human action with its own risks. - **No T3 entropy detector in this release.** It is the single largest false-positive source, and the named scenarios do not require it.
