{"_id":"@agnt-gg/nope","_rev":"5-d0f58fc3a4d2e9a693afac5b9c178ee8","name":"@agnt-gg/nope","dist-tags":{"latest":"0.1.4"},"versions":{"0.1.0":{"name":"@agnt-gg/nope","version":"0.1.0","keywords":["ai-agents","security","guardrails","llm","prompt-injection","ssrf","sandbox","secret-redaction","agent-security","agnt"],"author":{"url":"https://agnt.gg","name":"AGNT"},"license":"MIT","_id":"@agnt-gg/nope@0.1.0","maintainers":[{"name":"agnt_gg","email":"nathan@bizop.io"}],"homepage":"https://agnt.gg","dist":{"shasum":"90fc3d30d7eda7590fb85375846c7feb3fc9d46b","tarball":"https://registry.npmjs.org/@agnt-gg/nope/-/nope-0.1.0.tgz","fileCount":11,"integrity":"sha512-uHXhUnWV/N/rnHgpZKbihff4YQUdco98DH8bC3t1b6f7SxWe9l4X9zGgEDj/kAjsoWaYJy4eyfLgtD/BDBiE5A==","signatures":[{"sig":"MEUCIQCHbROWoY25PLyILNrLkolgDtz9/tIhbVi2t6s6eev6jgIgPMfKGVaAHnslB66Z0VPrWVIp9axcFdSYyH2X4s5eP94=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":142362},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"node test/run-tests.mjs","build":"tsc -p tsconfig.json","prepublishOnly":"npm run build && npm test"},"_npmUser":{"name":"agnt_gg","email":"nathan@bizop.io"},"_npmVersion":"10.9.2","description":"NOPE — Neutralize Operations Prior to Execution. Security guardrails for AI agents: 63 dangerous-operation rules, secret redaction with binary-safe sanitization, prompt-injection scanning, DNS-aware SSRF protection, plugin/MCP scanning, sandboxing, identi","directories":{},"_nodeVersion":"22.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/nope_0.1.0_1783986974879_0.043377005686974224","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agnt-gg/nope","version":"0.1.1","keywords":["ai-agents","security","guardrails","llm","prompt-injection","ssrf","sandbox","secret-redaction","agent-security","agnt"],"author":{"url":"https://agnt.gg","name":"AGNT"},"license":"MIT","_id":"@agnt-gg/nope@0.1.1","maintainers":[{"name":"agnt_gg","email":"nathan@bizop.io"}],"homepage":"https://github.com/agnt-gg/nope#readme","bugs":{"url":"https://github.com/agnt-gg/nope/issues"},"dist":{"shasum":"b03cce10e9b4db319ba5df4e4b66cc2780f2489a","tarball":"https://registry.npmjs.org/@agnt-gg/nope/-/nope-0.1.1.tgz","fileCount":12,"integrity":"sha512-Futq6gMUCsCwLRWkP4+jRWK4u62DjSOppNtNn06n+Q4FBBqh6WERG9946mNiKOyRCgI7GMlUM+UHARgvRsR7Uw==","signatures":[{"sig":"MEQCIBuipv9dKzreBuCj9Qydi6y6Oyi+ia7La8Om7opfiKFgAiBfT+2+dlQFvH3bEwlPMJ5W0tEFooO6XiSu6KeVvH/Isg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":146472},"main":"./dist/index.js","type":"module","_from":"file:agnt-gg-nope-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"npm run test:unit && npm run test:sandbox-safe","build":"tsc -p tsconfig.json","test:unit":"node test/run-tests.mjs","prepublishOnly":"npm run build && npm test","test:sandbox-safe":"node scripts/safe-sandbox-child.mjs"},"_npmUser":{"name":"agnt_gg","email":"nathan@bizop.io"},"_resolved":"C:\\Users\\Studio\\Documents\\DevelopmentProjects\\AGNT\\repos\\nope\\agnt-gg-nope-0.1.1.tgz","_integrity":"sha512-Futq6gMUCsCwLRWkP4+jRWK4u62DjSOppNtNn06n+Q4FBBqh6WERG9946mNiKOyRCgI7GMlUM+UHARgvRsR7Uw==","repository":{"url":"git+https://github.com/agnt-gg/nope.git","type":"git"},"_npmVersion":"10.9.2","description":"NOPE — Neutralize Operations Prior to Execution. Security guardrails for AI agents with fail-closed execution backends, dangerous-operation rules, secret redaction, prompt-injection scanning, SSRF protection, telemetry, and red-team testing.","directories":{},"_nodeVersion":"22.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/nope_0.1.1_1784018971627_0.818505908114129","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agnt-gg/nope","version":"0.1.2","keywords":["ai-agents","security","guardrails","llm","prompt-injection","ssrf","sandbox","secret-redaction","agent-security","agnt"],"author":{"url":"https://agnt.gg","name":"AGNT"},"license":"MIT","_id":"@agnt-gg/nope@0.1.2","maintainers":[{"name":"agnt_gg","email":"nathan@bizop.io"}],"homepage":"https://github.com/agnt-gg/nope#readme","bugs":{"url":"https://github.com/agnt-gg/nope/issues"},"dist":{"shasum":"4c9f19e0972c99a4140582e61a0c5c7654b9d961","tarball":"https://registry.npmjs.org/@agnt-gg/nope/-/nope-0.1.2.tgz","fileCount":12,"integrity":"sha512-Nvfu4NrhYTNtHbJB+kIfLIeTjRll/mtuGfAXXcHP1ofkja7tgbfc7vh6HgguyMmEbgr6+9GbkYAeNrjOE4Sx5g==","signatures":[{"sig":"MEYCIQCjiNCB52csbaPl6bjxxG7VNr3kleZCcnB6y+nHzrBE+QIhALqVRDW2IPk/G0aRKH7MfAzwhluGhCVzBwSJqfRbqSGo","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":146787},"main":"./dist/index.js","type":"module","_from":"file:agnt-gg-nope-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"test":"npm run test:unit && npm run test:sandbox-safe","build":"tsc -p tsconfig.json","test:unit":"node test/run-tests.mjs","prepublishOnly":"npm run build && npm test","test:sandbox-safe":"node scripts/safe-sandbox-child.mjs"},"_npmUser":{"name":"agnt_gg","email":"nathan@bizop.io"},"_resolved":"C:\\Users\\Studio\\Documents\\DevelopmentProjects\\AGNT\\repos\\nope\\agnt-gg-nope-0.1.2.tgz","_integrity":"sha512-Nvfu4NrhYTNtHbJB+kIfLIeTjRll/mtuGfAXXcHP1ofkja7tgbfc7vh6HgguyMmEbgr6+9GbkYAeNrjOE4Sx5g==","repository":{"url":"git+https://github.com/agnt-gg/nope.git","type":"git"},"_npmVersion":"10.9.2","description":"NOPE — Neutralize Operations Prior to Execution. Security guardrails for AI agents with fail-closed execution backends, dangerous-operation rules, secret redaction, prompt-injection scanning, SSRF protection, telemetry, and red-team testing.","directories":{},"_nodeVersion":"22.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/nope_0.1.2_1784047047011_0.2528914348934945","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agnt-gg/nope","version":"0.1.3","keywords":["ai-agents","security","guardrails","llm","prompt-injection","ssrf","sandbox","secret-redaction","agent-security","agnt"],"author":{"url":"https://agnt.gg","name":"AGNT"},"license":"MIT","_id":"@agnt-gg/nope@0.1.3","maintainers":[{"name":"agnt_gg","email":"nathan@bizop.io"}],"homepage":"https://github.com/agnt-gg/nope#readme","bugs":{"url":"https://github.com/agnt-gg/nope/issues"},"dist":{"shasum":"fd33738892ed19d365d4689f1663b0dc54a37eeb","tarball":"https://registry.npmjs.org/@agnt-gg/nope/-/nope-0.1.3.tgz","fileCount":12,"integrity":"sha512-ac4uzDrfGXWha+059Q3GZs94DG1PPprVf9HqNl40xZGUKTv//qdKyawSMFszDn4L8WnTLxQ2eZ7fk1t3q4K07w==","signatures":[{"sig":"MEUCIQDbOlQVuNS7+xEPiC3KtqtbJsQJg01sM6MONjLUlqNHbQIgIFZJyjDK4OcUbJP4nEPbR/XVCO6pjSBV/25EvTlo6L8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":147431},"main":"./dist/index.js","type":"module","types":"./dist/index.d.ts","engines":{"node":">=18"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"gitHead":"d83f587599f36d7351659abe8830778c66e6cf1f","scripts":{"test":"npm run test:unit && npm run test:sandbox-safe","build":"tsc -p tsconfig.json","test:unit":"node test/run-tests.mjs","prepublishOnly":"npm run build && npm test","test:sandbox-safe":"node scripts/safe-sandbox-child.mjs"},"_npmUser":{"name":"agnt_gg","email":"nathan@bizop.io"},"repository":{"url":"git+https://github.com/agnt-gg/nope.git","type":"git"},"_npmVersion":"10.9.2","description":"NOPE — Neutralize Operations Prior to Execution. Security guardrails for AI agents with fail-closed execution backends, dangerous-operation rules, secret redaction, prompt-injection scanning, SSRF protection, telemetry, and red-team testing.","directories":{},"_nodeVersion":"22.16.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.5.4","@types/node":"^22.5.0"},"_npmOperationalInternal":{"tmp":"tmp/nope_0.1.3_1785305610840_0.11910326780887903","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@agnt-gg/nope","version":"0.1.4","description":"NOPE — Neutralize Operations Prior to Execution. Security guardrails for AI agents with fail-closed execution backends, dangerous-operation rules, secret redaction, prompt-injection scanning, SSRF protection, telemetry, and red-team testing.","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"build":"tsc -p tsconfig.json","test":"npm run test:unit && npm run test:benign && npm run test:sandbox-safe","test:unit":"node test/run-tests.mjs","test:benign":"node test/benign-corpus.mjs","test:sandbox-safe":"node scripts/safe-sandbox-child.mjs","prepublishOnly":"npm run build && npm test"},"keywords":["ai-agents","security","guardrails","llm","prompt-injection","ssrf","sandbox","secret-redaction","agent-security","agnt"],"author":{"name":"AGNT","url":"https://agnt.gg"},"license":"MIT","homepage":"https://github.com/agnt-gg/nope#readme","repository":{"type":"git","url":"git+https://github.com/agnt-gg/nope.git"},"bugs":{"url":"https://github.com/agnt-gg/nope/issues"},"engines":{"node":">=18"},"publishConfig":{"access":"public"},"devDependencies":{"typescript":"^5.5.4","@types/node":"^22.5.0"},"_id":"@agnt-gg/nope@0.1.4","gitHead":"9c4b6c6f94019ce13c3c455f3a5eda6909a7ec81","_nodeVersion":"22.16.0","_npmVersion":"10.9.2","dist":{"integrity":"sha512-sB97dnfIKt0KwglAzG4tEsBiTCfQl4sda3CjxtoEkAi1qy9fls/stzwZQSikwEHxtkU4L7DLMjCVfWe7gBOlOA==","shasum":"b9b3ab777fd0880045d3bfdbde8e26c498156133","tarball":"https://registry.npmjs.org/@agnt-gg/nope/-/nope-0.1.4.tgz","fileCount":12,"unpackedSize":161500,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIGm5ehorLXrxMatEQcLVVVJTnX4KQXzBsK6YVYCVtROaAiB0USi3CKbvf9zJD+U7U1vt1PIGLNfEJtXSJN8SlJuIKg=="}]},"_npmUser":{"name":"agnt_gg","email":"nathan@bizop.io"},"directories":{},"maintainers":[{"name":"agnt_gg","email":"nathan@bizop.io"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/nope_0.1.4_1785991378444_0.640665154599428"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-13T23:56:14.679Z","modified":"2026-08-06T04:42:58.737Z","0.1.0":"2026-07-13T23:56:15.004Z","0.1.1":"2026-07-14T08:49:31.774Z","0.1.2":"2026-07-14T16:37:27.212Z","0.1.3":"2026-07-29T06:13:30.984Z","0.1.4":"2026-08-06T04:42:58.574Z"},"bugs":{"url":"https://github.com/agnt-gg/nope/issues"},"author":{"name":"AGNT","url":"https://agnt.gg"},"license":"MIT","homepage":"https://github.com/agnt-gg/nope#readme","keywords":["ai-agents","security","guardrails","llm","prompt-injection","ssrf","sandbox","secret-redaction","agent-security","agnt"],"repository":{"type":"git","url":"git+https://github.com/agnt-gg/nope.git"},"description":"NOPE — Neutralize Operations Prior to Execution. Security guardrails for AI agents with fail-closed execution backends, dangerous-operation rules, secret redaction, prompt-injection scanning, SSRF protection, telemetry, and red-team testing.","maintainers":[{"name":"agnt_gg","email":"nathan@bizop.io"}],"readme":"# NOPE — Neutralize Operations Prior to Execution\n\nAgent security in one import. Presets to start, fluent builder to customize, one method to scan everything.\n\n```\nnpm install @agnt-gg/nope\n```\n\n---\n\n## Quick Start\n\n```typescript\nimport { NOPE } from '@agnt-gg/nope';\n\nconst nope = NOPE.preset('standard');\n\nnope.check({ command: 'DROP TABLE users;' });\n// → { allowed: false, violations: [{ rule: 'db-drop-table', severity: 'critical' }] }\n\nnope.scan(contextText);                                    // prompt injection\nnope.scan({ name: 'shell', description: 'Run commands' }); // MCP tool\n\nconst safe = nope.wrap(plug.tools);                         // wrap tools\n```\n\n### Presets\n\n| Preset     | Mode   | Threshold | SSRF     | Scanners | Telemetry |\n| ---------- | ------ | --------- | -------- | -------- | --------- |\n| `paranoid` | strict | medium    | enforced | all on   | on        |\n| `standard` | strict | high      | on       | off      | on        |\n| `minimal`  | strict | high      | off      | off      | off       |\n| `audit`    | audit  | low       | on + log | all on   | on        |\n\nPresets accept overrides:\n\n```typescript\nconst nope = NOPE.preset('standard', { auth: { verifyToken: myFn } });\n```\n\n### Fluent builder\n\n```typescript\nconst nope = new NOPE()\n  .withRole('admin', 'critical', 'warn')\n  .withRole('agent', 'medium', 'strict')\n  .withRateLimit('1m', 60, { admin: 200, agent: 30 })\n  .withLockout(5)\n  .withSSRF({ enforced: true })\n  .withScanners({ homograph: true, terminalInjection: true })\n  .withTelemetry({ store: 'memory', retention: '7d' })\n  .withTrust('@agnt-gg/*');\n```\n\n---\n\n## Core API\n\n### check(action, context?)\n\nTest an action against all rules.\n\n```typescript\nnope.check({ command: 'DROP TABLE users;' });\nnope.check({ tool: 'exec', params: { command: 'shutdown -h now' } });\nnope.check({ code: 'eval(userInput)' });\nnope.check({ command: 'shutdown -h now' }, { role: 'developer' });  // identity-aware\n```\n\n### wrap(tools)\n\nWrap tools — inputs checked, outputs sanitized. All layers apply automatically.\n\n```typescript\nconst safe = nope.wrap(plug.tools);\nfor (const t of safe) ai.tool(t.name, t.description, t.input, t.run);\n```\n\nPipeline: external scanner → built-in rules → identity context → trust level → LLM approval → onBlock → execute → sanitize output.\n\n### scan(input)\n\nOne method, dispatches by input type:\n\n```typescript\nnope.scan('ignore previous instructions...');          // → prompt injection\nnope.scan({ name: 'shell', description: '...' });      // → MCP tool scan\nnope.scan({ code: pluginSource });                      // → plugin code scan\nawait nope.scan({ binary: '/usr/local/bin/tirith' });   // → binary checksum\n```\n\n### sanitize(value, toolName?)\n\nScrub secrets from any value. 17 built-in patterns (OpenAI, Anthropic, AWS, GitHub, Stripe, JWT, PEM, etc.).\n\n```typescript\nconst clean = nope.sanitize(toolOutput, 'my-tool');\n```\n\n---\n\n## Configuration\n\nStart with a preset, then layer on what you need. Every feature is opt-in.\n\n### Modes & thresholds\n\n```typescript\nnew NOPE({ mode: 'strict' })          // block violations (default)\nnew NOPE({ mode: 'warn' })            // log but allow\nnew NOPE({ mode: 'audit' })           // silent\nnew NOPE({ threshold: 'critical' })   // only block critical\n```\n\n### Identity & auth\n\nRole-based thresholds, token verification, rate limiting, allow/deny lists, approval memory, lockout.\n\n```typescript\nconst nope = NOPE.preset('standard')\n  .withRole('admin', 'critical', 'warn')\n  .withRole('agent', 'medium', 'strict')\n  .withRateLimit('1m', 60, { admin: 200, agent: 30 })\n  .withLockout(5)\n  .withAuth({\n    verifyToken: async (t) => jwt.verify(t, SECRET),\n    allowlist: ['user_abc'],\n    denylist: ['user_bad'],\n  });\n\nawait nope.checkWithToken(action, 'eyJhbG...');  // auto-verify + check\nnope.recordApproval('user_abc', 'fs-rm-rf', 'always');  // approval memory\n```\n\n### SSRF protection\n\nDNS resolution, redirect chain validation, cloud metadata blocking (AWS, GCP, Azure, Alibaba), IPv6 private ranges, custom blocklists, enforced mode.\n\n```typescript\nnope.withSSRF({\n  enforced: true,\n  customBlocklist: ['evil.internal'],\n  allowlist: ['safe-api.com'],\n});\n\nawait nope.resolveAndCheck('https://suspicious.com');\n// → { safe: false, reason: 'DNS rebinding: resolves to 10.0.0.1' }\n```\n\n### Execution backends\n\nNOPE never silently falls back to host execution. Callers must select a backend explicitly.\n\n- **Docker** is the package's isolation boundary and defaults to no network, dropped capabilities, `no-new-privileges`, CPU/memory limits, and the pinned `alpine:3.20` image.\n- **SSH** transports a command to a separately administered remote host. SSH is transport, not sandboxing.\n- **host-process** is explicitly unsafe and runs as the current OS user. It requires `acknowledgeHostAccess: true` and accepts only an executable plus an argument array—never a shell command string.\n- **WASM** shell execution is unavailable. Native commands are not WASI modules, and NOPE will not downgrade them to host execution.\n\n```typescript\nconst sb = nope.sandbox({\n  backend: 'docker', image: 'node:20-slim',\n  pidsLimit: 256, readonlyRoot: true, user: 'nobody',\n});\nawait sb.exec('echo hello');\n\n// Trusted host automation only — this is not isolation.\nconst host = nope.sandbox({\n  backend: 'host-process',\n  acknowledgeHostAccess: true,\n  executable: process.execPath,\n  args: ['trusted-script.mjs'],\n});\nawait host.exec();\n```\n\n### Scanners\n\nBuilt-in homograph detection, terminal injection scanning, binary verification.\n\n```typescript\nnope.withScanners({ homograph: true, terminalInjection: true });\n```\n\n### Telemetry & dashboard\n\n```typescript\nnope.withTelemetry({ store: 'memory', retention: '7d' });\nnope.report();     // → { totalChecks, blocked, riskScore, topViolations, ... }\nnope.dashboard();  // → self-contained HTML dashboard\n```\n\n### Smart LLM approval\n\n```typescript\nnew NOPE({\n  llmApprove: async (cmd, violations) => {\n    const r = await llm.chat('Safe? ' + cmd);\n    return r.includes('safe') ? 'approve' : 'escalate';\n  },\n});\n```\n\nLLM can only raise severity, never lower. Throws → fail-safe. Verdicts: `approve`, `deny`, `escalate`.\n\n### All config options\n\n| Option            | Default    | Description                                           |\n| ----------------- | ---------- | ----------------------------------------------------- |\n| `mode`            | `'strict'` | strict blocks, warn logs, audit silent                |\n| `threshold`       | `'high'`   | Minimum severity to block                             |\n| `onBlock`         | --         | Override callback (return true to allow)              |\n| `sanitizeOutput`  | `true`     | Scrub secrets from tool output                        |\n| `outputPatterns`  | `[]`       | Additional secret patterns                            |\n| `onSanitize`      | --         | Callback when secrets redacted                        |\n| `llmApprove`      | --         | Smart LLM approval (approve/deny/escalate)            |\n| `externalScanner` | --         | External scanner hook (allow/warn/block)              |\n| `trustedSources`  | `[]`       | Glob patterns for trusted tools                       |\n| `identity`        | --         | Role-based security profiles                          |\n| `ssrf`            | `{}`       | DNS, redirects, enforced mode, blocklists             |\n| `telemetry`       | --         | Event tracking and reporting                          |\n| `auth`            | --         | Token verification, rate limiting, allow/deny, lockout |\n| `scanners`        | `{}`       | Homograph, terminal injection, binary verification    |\n\n---\n\n## Built-in Rules\n\n60+ rules across 10 categories. All active by default.\n\n| Category     | Rules | Covers                                                    |\n| ------------ | ----- | --------------------------------------------------------- |\n| filesystem   | 9     | rm -rf, format, dd, shred, chmod 777, config deletion     |\n| database     | 6     | DROP, TRUNCATE, DELETE/UPDATE without WHERE, GRANT ALL    |\n| system       | 7     | shutdown, kill, iptables flush, crontab, passwd, SELinux  |\n| credentials  | 15    | API keys (OpenAI, AWS, Stripe, etc.), JWT, PEM, SSH, .env |\n| injection    | 5     | eval, exec, Function constructor, curl\\|bash, base64      |\n| exfiltration | 4     | upload secrets, tar pipe, reverse shell, DNS tunneling    |\n| network      | 8     | Private IPs, localhost, cloud metadata, IPv6, headers     |\n| git          | 4     | force push, hard reset, clean, delete remote branch       |\n| packages     | 2     | global install, untrusted npx                             |\n| containers   | 3     | privileged, rm all, host root mount                       |\n\n```typescript\nnope.add('no-prod-db', {\n  description: 'Block production database writes',\n  severity: 'critical',\n  category: 'custom',\n  match: (a) => /prod/i.test(String(a.params?.database || '')),\n});\n\nnope.remove('pkg-global-install');\n```\n\n---\n\n## Capability scoping (v0.1.4)\n\nMost rules detect a dangerous **action**. A few detect dangerous **data**.\nTelling NOPE which is which is the difference between a gate and a nuisance.\n\nBy default the matcher walks every string in every argument, so a rule that\ncatches a destructive command also fires on any argument that merely\n*describes* one — a note, a search query, a document. Declare what your tool\ncan actually do and NOPE will only apply rules that could possibly matter:\n\n```typescript\nnope.check({\n  tool: 'write_file',\n  params: { path: 'runbook.md', content: 'Step 2: reboot the host.' },\n  capabilities: ['fs-write'],   // what this tool can DO\n  sink: { path: 'runbook.md' }, // which args reach an execution sink\n});\n// -> clean. `content` is data; no shell exists to run it.\n\nnope.check({\n  tool: 'execute_shell_command',\n  command: 'sudo reboot',\n  capabilities: ['shell'],\n});\n// -> sys-shutdown. This one can actually do it.\n```\n\n**Capabilities:** `shell`, `code-eval`, `fs-write`, `fs-read`, `sql`, `http`,\n`git`, `container`, `any`.\n\nRules opt in with `appliesTo`. A rule with no `appliesTo` (or `['any']`) is\n**never** scoped — it always runs, always against full `params`. That is how\nthe `credentials` category stays global: a live API key is a leak wherever it\nappears, including in a field no shell will ever see.\n\n```typescript\nnope.add('no-prod-writes', {\n  description: 'Block writes to production',\n  severity: 'critical',\n  category: 'custom',\n  appliesTo: ['sql', 'shell'],   // irrelevant to a tool that cannot write\n  match: (a) => /prod/i.test(String(a.params?.database || '')),\n});\n```\n\n**Omitting `capabilities` keeps the old behaviour.** Every rule runs against\nevery field, so upgrading loses no coverage until you opt in per tool. An\nempty array is different from omitting it: `capabilities: []` declares a tool\nwith no execution sink at all.\n\nViolations now also report **where** they matched, which is what makes a false\npositive obvious on sight:\n\n```typescript\n{ rule: 'sys-shutdown', field: 'params.content', snippet: '…Step 2: reboot the…' }\n```\n\n`snippet` is deliberately omitted for `credentials` rules so a secret is never\ncopied into your logs.\n\n---\n\n## Advanced\n\n### Guard a single function\n\n```typescript\nconst safeExec = nope.guard(async ({ command }) => execSync(command).toString());\nawait safeExec({ command: 'ls' });       // works\nawait safeExec({ command: 'shutdown -h now' }); // throws\n```\n\n### External scanner\n\nRuns before built-in rules. Verdict is authoritative. Fails open if unavailable.\n\n```typescript\nnew NOPE({\n  externalScanner: async (action) => ({\n    action: (await runBinary(action)).exitCode === 0 ? 'allow' : 'block',\n  }),\n});\n```\n\n### Red team testing\n\n50+ built-in attack vectors with fuzzing.\n\n```typescript\nconst r = await nope.redTeam({ attacks: 'all', iterations: 200 });\n// → { passed: 187, failed: 13, coverage: { command: { tested: 48, caught: 45 }, ... } }\n```\n\n### Consent callback\n\n```typescript\nnew NOPE({\n  onBlock: async (violations, action) => {\n    return await prompt('Allow? (y/n)') === 'y';\n  },\n});\n```\n\n\n---\n\n## Sanitization modes (v0.1.0)\n\n`sanitize()` supports three modes via `sanitizeMode` (takes precedence over the legacy `sanitizeOutput` boolean):\n\n| Mode | Behavior |\n| --- | --- |\n| `'enforce'` (default) | Redact matches in place with `[REDACTED:label]` |\n| `'report'` | Detect + fire telemetry/`onSanitize`, return output **unmodified** — used by the `audit` preset for true zero-mutation observation |\n| `'off'` | No output scanning |\n\nBinary safety: strings longer than `maxSanitizeLength` (default 64 KB) or containing long unbroken base64 runs are skipped entirely — redacting inside an encoded image/file payload would silently corrupt it.\n","readmeFilename":"README.md"}