Docs
Security guardrails
The teammate who says "don't commit that key" before you do. Plain-language checks for the classic footguns in a tracked repo's working tree, each paired with the exact fix. The checks: a .env-family file tracked by git, a key or token committed in a tracked file, the same in an untracked-not-ignored file, a server bound to 0.0.0.0, wildcard CORS, and a .env present but not in .gitignore.
Where to find it
- Localhost:
/security-guardrails.html - API:
GET /api/security-guardrails(add?fresh=1to re-scan) - Navigation: AI Security in the sidebar, then Guardrails under All tools, in the Vulnerabilities group
What it does for you
Built vs. planned
All six checks, the plain-language fixes, and the on-demand re-scan (?fresh=1) ship today, backed by lib/security-guardrails.mjs (pure detection over already-read content) and its git plus filesystem wrapper. A non-git path degrades to an honest error rather than throwing. Results are cached per repo, the same pattern as the file-integrity scan.
Last updated