{"_id":"@apinindy/aiignore","name":"@apinindy/aiignore","dist-tags":{"alpha":"0.1.0-alpha.1","latest":"0.1.0-alpha.1"},"versions":{"0.1.0-alpha.1":{"name":"@apinindy/aiignore","version":"0.1.0-alpha.1","description":"Reference implementation and conformance suite for the experimental aiignore policy specification","author":{"name":"Alex","email":"alex@alexdoes.it","url":"https://alexdoes.it"},"license":"MIT","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"},"./schema":"./schema/aiignore.schema.json","./decision-schema":"./schema/decision.schema.json","./audit-event-schema":"./schema/audit-event.schema.json","./readiness-report-schema":"./schema/readiness-report.schema.json","./implementation-conformance-report-schema":"./schema/implementation-conformance-report.schema.json","./conformance-schema":"./schema/conformance-report.schema.json","./conformance-signature-envelope-schema":"./schema/conformance-signature-envelope.schema.json","./conformance-vectors-schema":"./schema/conformance-vectors.schema.json","./parser-vectors-schema":"./schema/parser-vectors.schema.json","./harness-vectors-schema":"./schema/harness-vectors.schema.json","./conformance-manifest-schema":"./schema/conformance-manifest.schema.json","./requirements-traceability-schema":"./schema/requirements-traceability.schema.json","./conformance-manifest":"./conformance/manifest-v0.1.json","./requirements-traceability":"./conformance/requirements-v0.1.json","./vectors/decisions":"./test/conformance/v0.1.json","./vectors/security":"./test/conformance/security-v0.1.json","./vectors/options":"./test/conformance/options-v0.1.json","./vectors/limits":"./test/conformance/limits-v0.1.json","./vectors/parser":"./test/parser-conformance/v0.1.json","./vectors/codex-sandbox":"./conformance/vectors/codex-sandbox-v0.1.json","./profiles/recommended":"./profiles/recommended.aiignore.yaml"},"repository":{"type":"git","url":"git+https://github.com/ap-in-indy/aiignore.git"},"bugs":{"url":"https://github.com/ap-in-indy/aiignore/issues"},"homepage":"https://ap-in-indy.github.io/aiignore/","keywords":["ai","agents","security","policy","ignore","sandbox"],"bin":{"aiignore":"dist/cli.js"},"publishConfig":{"access":"public"},"sideEffects":false,"scripts":{"clean":"node scripts/clean.mjs","build":"npm run clean && tsc -p tsconfig.build.json","postbuild":"node scripts/prepare-dist.mjs","check":"tsc -p tsconfig.json --noEmit","test":"vitest run","test:watch":"vitest","coverage":"vitest run --coverage","fuzz:smoke":"node test/fuzz/fuzz.mjs --iterations 2000","fuzz:extended":"node test/fuzz/fuzz.mjs --iterations 25000","lint":"eslint .","test:testbed":"node testbed/run.mjs && node testbed/gemini/run.mjs && node testbed/hooks/run.mjs","plugin:validate":"node scripts/validate-plugin.mjs && node scripts/validate-gemini-extension.mjs","workflow:validate":"node scripts/validate-workflows.mjs","license:validate":"node scripts/validate-licenses.mjs","security-metadata:validate":"node scripts/validate-security-metadata.mjs","project-policy:validate":"node scripts/validate-project-policy.mjs","hosting-policy:validate":"node scripts/audit-github-hosting.mjs --validate-policy","hosting:audit":"node scripts/audit-github-hosting.mjs","security:secrets":"bash scripts/scan-secrets.sh","manifest:validate":"node scripts/validate-conformance-manifest.mjs","requirements:validate":"node scripts/validate-requirements-traceability.mjs","site:build":"node scripts/build-site.mjs","publication:verify":"node scripts/verify-publication.mjs","package:validate":"node scripts/validate-package.mjs","artifact:validate":"node scripts/validate-artifact.mjs","verify":"npm run check && npm run lint && npm run coverage && npm run build && npm run fuzz:smoke && node dist/cli.js validate examples/complete.aiignore.yaml && node dist/cli.js conformance test/conformance/v0.1.json && node dist/cli.js conformance test/conformance/security-v0.1.json && node dist/cli.js conformance test/conformance/options-v0.1.json && node dist/cli.js conformance test/conformance/limits-v0.1.json && node dist/cli.js parser-conformance test/parser-conformance/v0.1.json && npm run test:testbed && npm run plugin:validate && npm run workflow:validate && npm run license:validate && npm run security-metadata:validate && npm run project-policy:validate && npm run hosting-policy:validate && npm run requirements:validate && npm run manifest:validate && npm run site:build && npm run package:validate && npm run artifact:validate"},"engines":{"node":">=20.19"},"dependencies":{"ajv":"^8.20.0","minimatch":"^10.2.5","re2js":"^2.8.6","yaml":"^2.9.0"},"devDependencies":{"@eslint/js":"^9.39.5","@types/node":"^26.1.1","@vitest/coverage-v8":"^4.1.10","eslint":"^9.39.2","globals":"^17.7.0","typescript":"^6.0.3","typescript-eslint":"^8.53.1","vitest":"^4.1.10"},"_id":"@apinindy/aiignore@0.1.0-alpha.1","gitHead":"2216bf6af1dd150b35471fed2f72764e1ffe39f8","_nodeVersion":"24.5.0","_npmVersion":"11.5.1","dist":{"integrity":"sha512-fVj8OoyaHSKyQ/4pDqg7gdnNWrXFnA3dVUSTNx1wYilvxy7yBM1g24kDwJIqwVE8LWO/vQoia9WKHfo+Srhr3w==","shasum":"49684eb622600e235cf1ebacf223789c1791f420","tarball":"https://registry.npmjs.org/@apinindy/aiignore/-/aiignore-0.1.0-alpha.1.tgz","fileCount":160,"unpackedSize":710253,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIBQOAkiEyx65eacF5jhyuBd0ZU/3Sk8BlNxVo8BqdyA1AiEAswkuIxTFyq9cJj4smYNwrRS7swRaLFE4D1z44RJ2BZU="}]},"_npmUser":{"name":"apinindy","email":"alex@alexdoes.it"},"directories":{},"maintainers":[{"name":"apinindy","email":"alex@alexdoes.it"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/aiignore_0.1.0-alpha.1_1784559720082_0.8119437821077369"},"_hasShrinkwrap":false}},"time":{"created":"2026-07-20T15:01:59.881Z","0.1.0-alpha.1":"2026-07-20T15:02:00.270Z","modified":"2026-07-20T15:02:00.513Z"},"maintainers":[{"name":"apinindy","email":"alex@alexdoes.it"}],"description":"Reference implementation and conformance suite for the experimental aiignore policy specification","homepage":"https://ap-in-indy.github.io/aiignore/","keywords":["ai","agents","security","policy","ignore","sandbox"],"repository":{"type":"git","url":"git+https://github.com/ap-in-indy/aiignore.git"},"author":{"name":"Alex","email":"alex@alexdoes.it","url":"https://alexdoes.it"},"bugs":{"url":"https://github.com/ap-in-indy/aiignore/issues"},"license":"MIT","readme":"# aiignore\n\naiignore is an experimental, harness-neutral policy specification for making\nagent access to files, environment variables, networks, and sensitive strings\nexplicit and testable. Structured policies live in `.aiignore.yaml`.\n\nThis repository contains the draft specification, JSON Schema, TypeScript\nreference implementation, conformance vectors, and experimental adapters for\nOpenAI Codex and Gemini CLI.\n\n> **Status: pre-standard alpha.** The format and APIs may change. Do not claim\n> security compliance until the relevant harness passes the conformance suite\n> at the enforcement level you require.\n\n> **Filename compatibility:** JetBrains and Qwen already interpret exact\n> `.aiignore` as gitignore-style path exclusions. This draft reserves that\n> filename for compatibility and uses `.aiignore.yaml` for structured policy.\n> Never put YAML in `.aiignore`.\n\n## Why this exists\n\nExisting files such as `.cursorignore`, `.aiexclude`, `.continueignore`, and\ngitignore-style `.aiignore` implementations usually control indexing or\nselected tools. They are useful, but they are not a portable access-control\nboundary. An agent can often reach the same content through a shell command,\nan environment variable, a symlink, an MCP tool, Git history, or an approved\nnetwork destination.\n\nThis proposal separates policy from enforcement and defines three conformance\nlevels:\n\n1. **Context** — excluded from indexing and automatic model context.\n2. **Tool** — all covered harness tools consult the policy engine.\n3. **Sandbox** — filesystem and network denial is enforced below the model and\n   inherited by subprocesses.\n\nOnly level 3 is intended to support a strong isolation claim, and only for the\nresources a platform can enforce completely.\n\n## Quick start\n\nInstall the exact prerelease intentionally rather than accepting future alpha\nchanges implicitly:\n\n```sh\nnpm install --ignore-scripts --save-dev @apinindy/aiignore@0.1.0-alpha.1\nnpx aiignore init\nnpx aiignore validate\nnpx aiignore doctor\n```\n\nTo evaluate the draft directly from source instead:\n\n```sh\ngit clone https://github.com/ap-in-indy/aiignore.git\ncd aiignore\nnpm ci --ignore-scripts\nnpm run build\ncp profiles/recommended.aiignore.yaml .aiignore.yaml\nnode dist/cli.js validate\nnode dist/cli.js doctor\n```\n\n`aiignore init` validates the packaged recommended profile before creating the\nfile and refuses to overwrite any existing path or case variant of the reserved\n`.aiignore` compatibility filename.\n\nStart in audit or a non-production sandbox. Review every rule and every adapter\ngap before enforcement.\n\nFor a plain-language walkthrough, common pitfalls, and the difference between\npolicy validity and real enforcement, see\n[`docs/getting-started.md`](docs/getting-started.md).\n\n## Example policy\n\n```yaml\naiignore: \"0.1\"\n\ndefaults:\n  files: allow\n  environment: allow\n  network: deny\n  strings: allow\n\nrules:\n  files:\n    - id: private-files\n      effect: deny\n      paths: [\"**/.env*\", \"secrets/**\", \"**/*.pem\"]\n      except: [\"**/.env.example\"]\n\n  environment:\n    - id: credential-variables\n      effect: drop\n      names: [\"*_TOKEN\", \"*_SECRET\", \"*_PASSWORD\", \"AWS_*\", \"GITHUB_TOKEN\"]\n      except: [\"PUBLIC_*\", \"*_TOKEN_TTL\"]\n\n  network:\n    - id: documentation\n      effect: allow\n      urls: [\"https://docs.example.com/**\", \"https://registry.npmjs.org/**\"]\n\n  strings:\n    - id: private-key-material\n      effect: redact\n      scopes: [tool_output, network_request, log]\n      patterns:\n        - type: regex\n          value: \"-----BEGIN [A-Z ]*PRIVATE KEY-----\"\n      replacement: \"[REDACTED:private-key-material]\"\n```\n\nSee [`spec/aiignore.md`](spec/aiignore.md) for normative behavior and\n[`examples/complete.aiignore.yaml`](examples/complete.aiignore.yaml) for a complete\npolicy.\n\n[`profiles/recommended.aiignore.yaml`](profiles/recommended.aiignore.yaml) is a\nconservative incident-derived starting point for credential files, ambient\nsecret variables, and common secret string shapes. Audit and tune it for local\nfalse positives before enforcement.\n\n## Reference CLI\n\nRequires Node.js 20.19 or newer.\n\n```sh\nnpm ci --ignore-scripts\nnpm run build\nnode dist/cli.js validate examples/complete.aiignore.yaml\nnode dist/cli.js doctor --policy examples/complete.aiignore.yaml\nnode dist/cli.js init --path .aiignore.yaml\nnode dist/cli.js check file secrets/api-key.txt --operation read --policy examples/complete.aiignore.yaml\nnode dist/cli.js check env GITHUB_TOKEN --policy examples/complete.aiignore.yaml\nnode dist/cli.js check network https://attacker.example/upload --policy examples/complete.aiignore.yaml\nprintf 'token=example' | node dist/cli.js scan --scope tool_output --policy examples/complete.aiignore.yaml\nnode dist/cli.js run --policy examples/complete.aiignore.yaml -- codex\nnode dist/cli.js compile codex --policy examples/complete.aiignore.yaml --report\nnode dist/cli.js compile gemini --policy examples/complete.aiignore.yaml --report\nnode dist/cli.js conformance test/conformance/v0.1.json\nnode dist/cli.js parser-conformance test/parser-conformance/v0.1.json\n# See docs/implementers.md for complete implementation-report generation.\n# See docs/conformance-signatures.md before using sign-report or verify-report.\n```\n\nAll decision commands support `--json` and return exit status `0` for allow or\naudit and `3` for deny/drop. Validation errors return `2`.\n\n`run` starts a child process with dropped/redacted environment variables and\nadds `AIIGNORE_POLICY_SHA256` for attestation. It does not, by itself, install\nfilesystem or network isolation; use a harness adapter or OS sandbox for those\nresources.\n\nThe Codex compiler emits a permission profile. The Gemini compiler emits a\ngenerated context-ignore file plus a settings fragment. Both include explicit\ncompilation gaps and return status `4` for a partial export unless\n`--allow-partial` is supplied. Their hooks are supplemental: see the\n[`Codex`](integrations/codex/README.md) and\n[`Gemini CLI`](integrations/gemini/README.md) adapter guides before making an\nassurance claim.\n\n## Validation snapshot\n\nThe current release candidate passes 253 reference tests, 107 portable decision\nvectors, and 56 portable parser vectors. CI covers Node 20 and 24 on Linux plus\nNode 24 on macOS and Windows. Package validation checks executable mode,\nrequired artifacts, forbidden development files, size, two-pack byte\nreproducibility, and clean installed runtime/type consumption; the release\nworkflow adds checksums, a CycloneDX SBOM, and provenance attestation. Every\nverification run also performs deterministic parser/decision robustness\nfuzzing, with a larger rotating-seed campaign on every pull request and weekly\nschedule. A versioned\nconformance manifest binds the exact specification, schemas, and vector bytes\nthat comprise the draft 0.1 interoperability bundle.\n\nVerified implementation and harness reports use a detached Ed25519 envelope. The verifier requires\nthe expected signer identity and public-key SHA-256 from an independent trust\nchannel; it never trusts the embedded identity or key by itself.\n\nThese results establish reference and decision compatibility only. They do not\nprove that every execution path in a harness is mediated.\n\n## Project documents\n\n- [`docs/concept.md`](docs/concept.md) — goals, threat model, and roadmap\n- [`docs/getting-started.md`](docs/getting-started.md) — safe first policy,\n  readiness diagnostic, representative checks, and adapter review\n- [`docs/architecture.md`](docs/architecture.md) — actors, components, trust\n  boundaries, external interfaces, and failure modes\n- [`docs/implementers.md`](docs/implementers.md) — portable implementation\n  sequence, pseudocode, canonicalization, and adapter checklist\n- [`docs/enterprise-deployment.md`](docs/enterprise-deployment.md) —\n  administrator-controlled deployment architecture and release gates\n- [`docs/dependency-management.md`](docs/dependency-management.md) — lockfile,\n  license, vulnerability, provenance, and update requirements\n- [`docs/fuzzing.md`](docs/fuzzing.md) — fuzz targets, invariants, reproduction,\n  corpus, and security triage\n- [`docs/conformance-signatures.md`](docs/conformance-signatures.md) — detached\n  report signing, trust pins, verification, rotation, and revocation\n- [`docs/conformance-policy.md`](docs/conformance-policy.md) — evidence classes,\n  report acceptance, claim scope, correction, and withdrawal\n- [`docs/versioning.md`](docs/versioning.md) — package, language, schema, vector,\n  manifest, report, compatibility, and end-of-life rules\n- [`docs/credential-management.md`](docs/credential-management.md) — project\n  credentials, signing keys, OIDC, access, rotation, and compromise response\n- [`docs/security-baseline.md`](docs/security-baseline.md) — transparent OSPS\n  baseline self-assessment and unresolved controls\n- [`docs/intellectual-property.md`](docs/intellectual-property.md) — current\n  license, DCO, patent-policy, and trademark limitations\n- [`docs/release-checklist.md`](docs/release-checklist.md) — separate private\n  push, public visibility, and package-publication gates\n- [`docs/maintainer-release-runbook.md`](docs/maintainer-release-runbook.md) —\n  repository protections, tag signing, two-phase publication, independent\n  verification, and bad-release response\n- [`docs/public-hosting.md`](docs/public-hosting.md) — machine-audited GitHub\n  rulesets, security products, Pages, workflow permissions, and release environment\n- [`docs/test-coverage.md`](docs/test-coverage.md) — syntax, option, decision,\n  CLI, and adapter coverage matrix\n- [`docs/requirements-traceability.md`](docs/requirements-traceability.md) —\n  machine-checked mapping from all normative sections to evidence and limits\n- [`rfcs/README.md`](rfcs/README.md) — normative proposal process and template\n- [`docs/research/harness-selection.md`](docs/research/harness-selection.md) —\n  evidence for the first harness adapter\n- [`docs/research/incidents.md`](docs/research/incidents.md) — incidents and\n  derived security requirements\n- [`docs/research/existing-formats.md`](docs/research/existing-formats.md) —\n  comparison with vendor-specific ignore mechanisms\n- [`docs/research/adversarial-test-results.md`](docs/research/adversarial-test-results.md) —\n  adversarial probes, remediations, regressions, and remaining harness gaps\n- [`spec/aiignore.md`](spec/aiignore.md) — normative draft specification\n- [`spec/registries.md`](spec/registries.md) — closed protocol-token registry\n  and allocation policy\n- [`spec/errata.md`](spec/errata.md) — immutable draft errata and correction index\n- [`schema/aiignore.schema.json`](schema/aiignore.schema.json) — machine-readable schema\n- [`schema/decision.schema.json`](schema/decision.schema.json) — exact portable\n  decision-result contract\n- [`schema/audit-event.schema.json`](schema/audit-event.schema.json) — minimal\n  secret-safe audit-event contract\n- [`schema/readiness-report.schema.json`](schema/readiness-report.schema.json) —\n  secret-safe operator diagnostic contract that cannot claim enforcement\n- [`schema/implementation-conformance-report.schema.json`](schema/implementation-conformance-report.schema.json) —\n  exact parser/decision interoperability-report contract, with offline complete\n  manifest-membership verification in the CLI and library\n- [`schema/conformance-report.schema.json`](schema/conformance-report.schema.json) —\n  scoped live harness-enforcement result schema\n- [`schema/conformance-signature-envelope.schema.json`](schema/conformance-signature-envelope.schema.json) —\n  detached Ed25519 report-signature envelope schema\n- [`schema/conformance-vectors.schema.json`](schema/conformance-vectors.schema.json) —\n  language-neutral decision-vector schema\n- [`schema/parser-vectors.schema.json`](schema/parser-vectors.schema.json) —\n  language-neutral valid/invalid parser-vector schema\n- [`schema/harness-vectors.schema.json`](schema/harness-vectors.schema.json) —\n  language-neutral live harness-test-plan schema\n- [`schema/conformance-manifest.schema.json`](schema/conformance-manifest.schema.json) —\n  exact versioned artifact-bundle schema\n- [`schema/requirements-traceability.schema.json`](schema/requirements-traceability.schema.json) —\n  requirements evidence/limitation catalog schema\n- [`conformance/manifest-v0.1.json`](conformance/manifest-v0.1.json) — canonical\n  draft 0.1 specification/schema/vector membership and SHA-256 bindings\n- [`conformance/requirements-v0.1.json`](conformance/requirements-v0.1.json) —\n  machine-readable normative-section, evidence, and residual-limit inventory\n- [`conformance/vectors`](conformance/vectors) — content-addressed live harness\n  test plans used by machine-readable reports\n- [`conformance/results`](conformance/results) — versioned provisional harness results\n- [`SECURITY.md`](SECURITY.md) — vulnerability reporting and security claims\n- [`security-insights.yml`](security-insights.yml) — OpenSSF Security Insights\n  2.2.0 machine-readable security metadata\n\n## Security posture\n\nAn `.aiignore.yaml` file is not intrinsically a security boundary, just as\n`.gitignore` does not prevent a file from being read or force-added. A compliant\nharness must mediate every path to the protected resource. See\n[`SECURITY.md`](SECURITY.md) before deploying this prototype.\n\n## License\n\nMIT License. Contributions are accepted under the same license and use a\nDeveloper Certificate of Origin sign-off.\n","readmeFilename":"README.md","_rev":"1-748d16c38a2fe10e3a4d9cc4bdae2a1f"}