sheeki03/tirith

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.

About the project

Tirith is a terminal security tool that intercepts commands, pasted content, and scanned files to detect deceptive URLs, hidden or obfuscated payloads, credential theft, malicious agent skills, and known-bad packages or network indicators before execution. It is for developers and AI agents that run shell commands or install software. Its catalogue entries configure or extend protection through a shell hook, skill, and setting.

This repository also configures its own agents. See what tirith tells them →

2.7kStars on the repository
4Mods indexed here, across every type
yesterdayLast push, which is what freshness is scored on
AGPL-3.0Licence, which decides whether bodies are shown

tirith-gateway

01

sheeki03/tirith

MCP server Cursor

MCP server "tirith-gateway" as configured in sheeki03/tirith. Launched with tirith gateway run --upstream-bin tirith --upstream-arg mcp-server --config ~/.c.

not rated 2.7k yesterday A tokens not measured AGPL-3.0