typescriptMITTrust: scannedUsed 3×
Command execution plan
A helper that flags shell commands requiring approval by matching risky patterns like deploy, rm, sudo, and curl-pipe; purely analytical with no execution.
Untrusted input — what to verify before you trust it
Outbound fetch helpers often lack SSRF guards, timeouts and redirect limits — the difference between a helper and an internal-network exfil vector. Confirm this card blocks internal addresses and bounds redirects and timeouts.
Preview
3 lines// aperçu protégé · typescript · 3 lignes3 more lines are delivered on retrieval, with the full verified card and its proof receipt.
What you get on retrieval
- · The complete verified implementation, written to bytes by the MCP tool (near-zero output tokens).
- · A proof receipt: source provenance, review status, license state and estimated savings.
- · Revocation coverage — if a security fix lands on this primitive, retrievers are notified.