Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
Tirith is a terminal security tool that intercepts commands, pasted content, and scanned files to detect deceptive URLs, hidden or obfuscated payloads, credential theft, malicious agent skills, and known-bad packages or network indicators before execution. It is for developers and AI agents that run shell commands or install software. Its catalogue entries configure or extend protection through a shell hook, skill, and setting.
Latest release v0.4.1 · 2 Sept 2026
These files are sheeki03/tirith's own configuration. They tell Claude Code how to work on this repository, so they are not mods to install elsewhere. Copy one as a starting point and replace the parts that are about this project.
.claude/settings.json A — .claude/settings.json A —