X402 Git

genesiscode2026/agent-workspace-guard-sdk · v1.0.0

What an agent reads when it fetches this URL: the whole manifest, in order, with the offer on the last line as a 402 it can pay. Nothing here is a button — an agent does not click, it signs. The page a person reads is here.

Pack · 4 source files · 3 test files · 1 example · 15 docs · 2 config files · 1 other file · 26 files · text 59.9 kB · no binaries · JavaScript 100% · licence undetermined

scan passed 2026-09-16 · scanner 2026.09.1 · 1 release · last release today · 0% of files seen elsewhere

computed 2026-09-16 21:07 UTC · analyzer 0.1.0

Security scan report

Scanned by X402 Git, OSV (opens in a new tab) and Socket (opens in a new tab) — passed on all three. Findings from X402 Git are listed below.

secrets
none found
X402 Git
size limits
within caps
X402 Git
known malware
no dependency manifests to check
OSV
known vulnerabilities
no dependency manifests to check
OSV
dependency behaviour
no dependency manifests to check
Socket
instruction smuggling
none found
X402 Git
what it can do
listed below
X402 Git

What this can do

Tools
none
Runs
nothing
Talks to
  • attacker.com
  • malicious.org
  • malicious.sh
Reads
no environment variables
At install
nothing runs
Links to
  • attacker.com
  • img.shields.io
  • malicious.sh
Findings (3)
  • LOWtests/adversarial-red-team.test.mjs — Talks to attacker.com
  • LOWtests/adversarial-security.test.mjs — Talks to malicious.org
  • LOWtests/adversarial-red-team.test.mjs — Talks to malicious.sh

Description self_reported

Written by the creator. Not verified by this platform — everything above and below this section is computed from the repository.

In-process filesystem confinement and command-policy guardrails for autonomous coding agents.

When to use it. When requiring verified AI Agent Security functionality in autonomous workflows

Readme

Agent Workspace Guard SDK

Filesystem confinement and command-policy guardrails for autonomous coding agents.

Tests License Zero Runtime Deps


1. WHAT IS THIS?

The Agent Workspace Guard SDK is a lightweight, zero-dependency Node.js developer security library that prevents autonomous AI coding agents (such as tool-calling LLMs, Cursor extensions, Claude Code tools, or custom agents) from escaping their designated working directory or running dangerous host commands.

2. WHO IS IT FOR?

  • Developers building autonomous coding agent workflows.
  • DevSecOps engineers integrating AI agent tools into developer machines.
  • SaaS platforms allowing AI agents to read and modify project files locally.

3. WHAT PROBLEM DOES IT SOLVE?

AI agents given shell and file-access tools can be tricked via prompt injection or unexpected planning into reading .env credentials, following symlinks outside the workspace, escaping with ../../, or executing destructive commands like rm -rf / or sudo. Heavy cloud microVMs (E2B, Modal) introduce 200ms+ network latency and $50–$200/mo cloud bills. This SDK provides in-process, sub-millisecond confinement directly in your Node.js runtime.

4. WHY PAY FOR IT INSTEAD OF BUILDING IT?

Writing ad-hoc regex or path checks fails on real-world edge cases: symlink race conditions (TOCTOU), Windows backslash traversal evasion (..\..\), multi-dot evasion (....//), shell chaining metacharacters (;, &&, |, $()), and command redirection (<, >). This SDK includes an independently verified, 110-case adversarial red-team test suite covering these exact attack vectors.

5. WHAT IS VERIFIED?

  • 110 / 110 Adversarial Attack Cases Passed: Covering path traversal, symlink escapes, secret files, command chaining, and destructive command patterns.
  • Zero External Runtime Dependencies: Built strictly on Node.js standard library (node:fs, node:path, node:crypto).
  • Cryptographic Audit Log: Every command evaluation is chained using SHA-256 digests.

6. HOW DO I RUN IT?

# 1. Run the 110-case adversarial security test suite
node --test tests/adversarial-red-team.test.mjs

# 2. Run the interactive agent runner demonstration
node examples/agent-runner-example.mjs

Contents

26 files · 59.9 kB · computed 2026-09-16
SizePath
30 B.gitignore
3.9 kBADVERSARIAL_TEST_MATRIX.md
1.4 kBAGENT_EVAL.md
3 kBARCHITECTURE.md
570 BCHANGELOG.md
506 BDEPENDENCIES.md
1.7 kBLICENSE.md
1.3 kBLIMITATIONS.md
2.5 kBPREVIEW.md
1.9 kBQUICKSTART.md
2.6 kBREADME.md
632 BSECURITY_EVIDENCE.md
775 BSUPPORT.md
1.7 kBTEST_REPORT.md
213 BTHIRD_PARTY_NOTICES.md
3.6 kBTHREAT_MODEL.md
417 BVERIFICATION.md
1.1 kBcommercial-manifest.json
2.5 kBexamples/agent-runner-example.mjs
2.5 kBrelease-manifest.json
5.1 kBsrc/command-policy.mjs
6.8 kBsrc/filesystem-shield.mjs
1.1 kBsrc/index.d.ts
2.3 kBsrc/index.mjs
7.1 kBtests/adversarial-red-team.test.mjs
4.6 kBtests/adversarial-security.test.mjs
computed 2026-09-16 21:07 UTC · analyzer 0.1.0

Dependencies

None found in the software bill of materials for this release.

computed 2026-09-16 21:07 UTC · analyzer 0.1.0

Releases

1 release · last release today
VersionDateScanChangedNotes
v1.0.02026-09-16passrelease: v1.0.0 commercial source edition

Machine-readable at https://x402git.com/api/v/genesiscode2026/agent-workspace-guard-sdk/releases. Entries cannot be deleted by the creator.

Order

GET v1.0.0 · $149 · new releases $39

The resource endpoint answers 402 with the price and the exact bytes to sign; the same request carrying PAYMENT-SIGNATURE returns a signed download URL. Access is granted only after settlement returns a transaction hash. A person can do the same thing with a browser wallet on the product page.

# the 402, with the price and the exact bytes to sign
curl -si https://x402git.com/api/r/genesiscode2026/agent-workspace-guard-sdk

# what your wallet already owns, and what the next fetch would cost it
curl -s https://x402git.com/api/v/genesiscode2026/agent-workspace-guard-sdk \
  -H "X-Wallet-Signature: 0xYOURADDRESS.<nonce>.<signature>"

The first request answers this — a real quote, made for this page load:

HTTP/1.1 402 Payment Required
Content-Type: application/json

{
  "x402Version": 2,
  "resource": {
    "url": "https://x402git.com/api/r/genesiscode2026/agent-workspace-guard-sdk",
    "description": "genesiscode2026/agent-workspace-guard-sdk v1.0.0 — release. In-process filesystem confinement and command-policy guardrails for autonomous coding agents. Security scan passed; signed download, 5-minute URL.",
    "mimeType": "application/zip",
    "serviceName": "agent-workspace-guard-sdk",
    "tags": [
      "pack",
      "source",
      "tests",
      "examples",
      "docs"
    ]
  },
  "accepts": [
    {
      "scheme": "exact",
      "network": "eip155:8453",
      "amount": "149000000",
      "asset": "0x833589fCD6eDb6E08f4c7C32D4f71b54bdA02913",
      "payTo": "0xDbd32F7565FFdb901Ea48281777aD03d35bB4b60",
      "maxTimeoutSeconds": 300,
      "extra": {
        "name": "USD Coin",
        "version": "2"
      },
      "maxAmountRequired": "149000000",
      "resource": "https://x402git.com/api/r/genesiscode2026/agent-workspace-guard-sdk",
      "description": "genesiscode2026/agent-workspace-guard-sdk v1.0.0 — release. In-process filesystem confinement and command-policy guardrails for autonomous coding agents. Security scan passed; signed download, 5-minute URL.",
      "mimeType": "application/zip"
    }
  ],
  "extensions": {
    "bazaar": {
      "info": {
        "input": {
          "type": "http",
          "queryParams": {},
          "method": "GET"
        },
        "output": {
          "type": "json",
          "example": {
            "version": "1.0.0",
            "artifact_sha256": "0123456789abcdef0123456789abcdef0123456789abcdef0123456789abcdef",
            "download_url": "https://storage.example/genesiscode2026/agent-workspace-guard-sdk/1.0.0.zip?signed=…",
            "expires_at": "2026-09-16T12:05:00.000Z",
            "version_endpoint": "https://x402git.com/api/r/genesiscode2026/agent-workspace-guard-sdk/v/1.0.0",
            "manifest_url": "https://x402git.com/api/label/genesiscode2026/agent-workspace-guard-sdk",
            "all_versions": false
          }
        }
      },
      "schema": {
        "$schema": "https://json-schema.org/draft/2020-12/schema",
        "type": "object",
        "properties": {
          "input": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string",
                "const": "http"
              },
              "method": {
                "type": "string",
                "enum": [
                  "GET"
                ]
              },
              "queryParams": {
                "type": "object",
                "properties": {}
              }
            },
            "required": [
              "type",
              "method"
            ],
            "additionalProperties": false
          },
          "output": {
            "type": "object",
            "properties": {
              "type": {
                "type": "string"
              },
              "example": {
                "type": "object",
                "properties": {
                  "version": {
                    "type": "string",
                    "description": "Semantic version of the release served."
                  },
                  "artifact_sha256": {
                    "type": "string",
                    "description": "sha256 of the zip; verify the download against it."
                  },
                  "download_url": {
                    "type": "string",
                    "description": "Signed URL over the exact bytes that were scanned. Valid five minutes."
                  },
                  "expires_at": {
                    "type": "string",
                    "format": "date-time"
                  },
                  "version_endpoint": {
                    "type": "string",
                    "description": "Re-fetch this exact version later, free, with X-Wallet-Signature."
                  },
                  "manifest_url": {
                    "type": "string",
                    "description": "The public manifest for this listing."
                  },
                  "all_versions": {
                    "type": "boolean",
                    "description": "True when the purchase covers every later release too."
                  }
                },
                "required": [
                  "version",
                  "artifact_sha256",
                  "download_url",
                  "expires_at",
                  "version_endpoint",
                  "manifest_url",
                  "all_versions"
                ],
                "additionalProperties": false
              }
            },
            "required": [
              "type"
            ]
          }
        },
        "required": [
          "input"
        ]
      }
    }
  },
  "extra": {
    "kind": "new",
    "version": "1.0.0",
    "manifest_url": "https://x402git.com/api/label/genesiscode2026/agent-workspace-guard-sdk",
    "scan_badge_url": "https://x402git.com/api/label/genesiscode2026/agent-workspace-guard-sdk#scan",
    "update_price_micro": "39000000",
    "quote_id": "q_9538a1f9a47fe531a5be9ef2c13d8b79",
    "valid_before": "2026-09-17T03:22:59.186Z",
    "instructions": "This is an x402 paywall, not an error. To buy: sign accepts[0] from the 402 as an EIP-3009 USDC authorization on Base with your own wallet, then GET https://x402git.com/api/r/genesiscode2026/agent-workspace-guard-sdk again with the payment in the PAYMENT-SIGNATURE header and extra.quote_id in X-Quote-Id — or, over MCP, call `purchase` again with the same payment as `payment_signature`. The full procedure is at https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md; the same tools are an MCP server at https://x402git.com/api/mcp. No wallet? A person can buy at https://x402git.com/genesiscode2026/agent-workspace-guard-sdk, and the free manifest at https://x402git.com/api/label/genesiscode2026/agent-workspace-guard-sdk shows what is inside before anyone pays.",
    "listing_url": "https://x402git.com/genesiscode2026/agent-workspace-guard-sdk",
    "skill_url": "https://x402git.com/.well-known/agent-skills/buy-a-repo/SKILL.md",
    "mcp_url": "https://x402git.com/api/mcp"
  }
}
Resource
https://x402git.com/api/r/genesiscode2026/agent-workspace-guard-sdk
Manifest
https://x402git.com/api/label/genesiscode2026/agent-workspace-guard-sdk
Version
https://x402git.com/api/v/genesiscode2026/agent-workspace-guard-sdk
Artifact sha256
c7053f36c99b723392e26394b3c8f0f56456490c1f20b31b8b33d3615a4b1438

Later releases cost $39, and never more than the update price in force when you bought. One charge per update, whatever the release cadence.

Sold by genesiscode2026. Read the terms and the route documentation before you script against this. Base URL https://x402git.com.