{"_id":"@askalf/redstamp","_rev":"4-cc1ee2cc84cedf9cbb5f01d8a9767ff1","name":"@askalf/redstamp","dist-tags":{"diag":"0.0.2-diag.0","latest":"0.0.3"},"versions":{"0.0.1":{"name":"@askalf/redstamp","version":"0.0.1","license":"MIT","_id":"@askalf/redstamp@0.0.1","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"dist":{"shasum":"0f33f27b7b4cc39f0a39070ac364221d9bd4735a","tarball":"https://registry.npmjs.org/@askalf/redstamp/-/redstamp-0.0.1.tgz","fileCount":2,"integrity":"sha512-X8TpMebfZogQui260+MrplGOLv1ljapD5wqX7VeQIs2h88g9DFgCWb7ledwPANSJDaBrmCWCDLBag4JGXy1Z0w==","signatures":[{"sig":"MEUCIQDthQVx4wWooQuy4jG3bnjZ+rz6w7WdcCLdNE9Z+KRbAAIgeU9Vo7Lj4KMzUZnjTvit/a9yXq+Bvu/ocduSTuRScAs=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":373},"_npmUser":{"name":"askalf","email":"support@askalf.org"},"_npmVersion":"12.0.1","description":"runtime tool-call firewall — name reservation for the rename of warden (Own Your Stack). Real release imminent: https://github.com/askalf/warden","directories":{},"_nodeVersion":"22.22.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/redstamp_0.0.1_1783729315336_0.02980156407560486","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Not distributed on npm — npm's content scan rejects redstamp's detection-signature corpus. Install the signed release: https://github.com/askalf/redstamp/releases"},"0.0.2-diag.0":{"name":"@askalf/redstamp","version":"0.0.2-diag.0","license":"MIT","_id":"@askalf/redstamp@0.0.2-diag.0","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"homepage":"https://github.com/askalf/redstamp#readme","bugs":{"url":"https://github.com/askalf/redstamp/issues"},"dist":{"shasum":"37d6d1e9dc1289ccfbc28db3eb05c7197e8d8460","tarball":"https://registry.npmjs.org/@askalf/redstamp/-/redstamp-0.0.2-diag.0.tgz","fileCount":3,"integrity":"sha512-BaoN/mnyrGHiaStOYp8YFTlxxDT8yVvKCTu6zAAh3WFk60vXA6GqPdAA0qH/CbXlkb4nCVbXz3OYeQL7lRgMlg==","signatures":[{"sig":"MEUCID3xEIDoiAQS5cqvBWnGWjw9HFOBFvoBPn6jVUNbL0YvAiEAyR8aNP0vsLXAyUwkdGrFLNqZopPWWhVk1anwWwSElBE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@askalf%2fredstamp@0.0.2-diag.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":1570},"gitHead":"0a67719dcbecc695e21b6fe39430ec9ecd9ada7f","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:92b9b1cb-5574-41b9-a330-1a45ab48fd3d"}},"repository":{"url":"git+https://github.com/askalf/redstamp.git","type":"git"},"_npmVersion":"11.16.0","description":"registry diagnostic canary — minimal-content PUT probe, not a release; install @askalf/redstamp@latest instead","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/redstamp_0.0.2-diag.0_1783733413893_0.2683036568925332","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Not distributed on npm — npm's content scan rejects redstamp's detection-signature corpus. Install the signed release: https://github.com/askalf/redstamp/releases"},"0.0.3":{"name":"@askalf/redstamp","version":"0.0.3","keywords":["agent","security","mcp","llm","guardrails","ai-safety","firewall","own-your-stack"],"author":{"name":"askalf"},"license":"MIT","_id":"@askalf/redstamp@0.0.3","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"homepage":"https://github.com/askalf/redstamp#readme","bugs":{"url":"https://github.com/askalf/redstamp/issues"},"dist":{"shasum":"fab7381746251522e4d4b064e664d9f78dc5cb82","tarball":"https://registry.npmjs.org/@askalf/redstamp/-/redstamp-0.0.3.tgz","fileCount":4,"integrity":"sha512-flacdl/HZm6DcikF8tBTCoiIXbwDWKy1117QrP4EAzNoTDq3qGIiro/VBdS8E8uuUzMtrNl6HWt7leoXgrR+eg==","signatures":[{"sig":"MEUCIEfkU3zfxxATUZUEb3OKXjRDPxbMn9a9Q2p/YIcwa0CTAiEAuuhnaCRmFY0iwR9zg5Ju3wwwQaFYrpQynw/hcyOGHV8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":5564},"type":"module","engines":{"node":">=20"},"exports":{".":"./index.mjs"},"gitHead":"441167d0833f3238c82d888c2486aebec6c32464","_npmUser":{"name":"askalf","email":"support@askalf.org"},"repository":{"url":"git+https://github.com/askalf/redstamp.git","type":"git"},"_npmVersion":"12.0.2","description":"POINTER PACKAGE — redstamp is not distributed on npm. Install the Sigstore-signed release from https://github.com/askalf/redstamp/releases. A deterministic firewall for AI agent tool calls (Own Your Stack).","directories":{},"_nodeVersion":"22.22.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/redstamp_0.0.3_1785618889543_0.5938887059339415","host":"s3://npm-registry-packages-npm-production"},"deprecated":"Not distributed on npm — npm's content scan rejects redstamp's detection-signature corpus. Install the signed release: https://github.com/askalf/redstamp/releases"}},"time":{"created":"2026-07-11T00:21:55.053Z","modified":"2026-08-01T21:17:06.026Z","0.0.1":"2026-07-11T00:21:55.468Z","0.0.2-diag.0":"2026-07-11T01:30:14.021Z","0.0.3":"2026-08-01T21:14:49.673Z"},"bugs":{"url":"https://github.com/askalf/redstamp/issues"},"author":{"name":"askalf"},"license":"MIT","homepage":"https://github.com/askalf/redstamp#readme","keywords":["agent","security","mcp","llm","guardrails","ai-safety","firewall","own-your-stack"],"repository":{"url":"git+https://github.com/askalf/redstamp.git","type":"git"},"description":"POINTER PACKAGE — redstamp is not distributed on npm. Install the Sigstore-signed release from https://github.com/askalf/redstamp/releases. A deterministic firewall for AI agent tool calls (Own Your Stack).","maintainers":[{"name":"askalf","email":"support@askalf.org"}],"readme":"# @askalf/redstamp\r\n\r\n> ### ⚠️ This npm package is a pointer. redstamp is not distributed here.\r\n>\r\n> The real thing lives at **[github.com/askalf/redstamp](https://github.com/askalf/redstamp)** and is actively released — see the version badge below.\r\n\r\n[![release](https://img.shields.io/github/v/release/askalf/redstamp?logo=github)](https://github.com/askalf/redstamp/releases/latest)\r\n[![ci](https://github.com/askalf/redstamp/actions/workflows/ci.yml/badge.svg)](https://github.com/askalf/redstamp/actions/workflows/ci.yml)\r\n[![OpenSSF Scorecard](https://api.scorecard.dev/projects/github.com/askalf/redstamp/badge)](https://scorecard.dev/viewer/?uri=github.com/askalf/redstamp)\r\n[![signed release](https://img.shields.io/badge/release-sigstore_signed-brightgreen?logo=github)](https://github.com/askalf/redstamp/releases/latest)\r\n[![dependencies: 0](https://img.shields.io/badge/dependencies-0-brightgreen)](https://github.com/askalf/redstamp/blob/master/package.json)\r\n[![license: MIT](https://img.shields.io/badge/license-MIT-blue)](https://github.com/askalf/redstamp/blob/master/LICENSE)\r\n\r\n**redstamp is a deterministic firewall for AI agent tool calls** — it sits between an agent and its tools and, on every action, classifies risk, enforces policy, and blocks secret-exfiltration and prompt-injection before the call runs. Same tool call, same verdict, every time, offline, with no model in the decision path. It ships as a Claude Code hook, a background daemon, an MCP middleware proxy, and a library. Zero dependencies.\r\n\r\n## Install\r\n\r\nReleases are **Sigstore-signed tarballs** published on GitHub:\r\n\r\n```sh\r\n# fetch the latest signed release + its provenance\r\ngh release download --repo askalf/redstamp --pattern 'redstamp.tgz*'\r\n\r\n# verify provenance BEFORE installing — exits non-zero if it isn't ours\r\ngh attestation verify redstamp.tgz --owner askalf\r\n\r\nnpm i -g ./redstamp.tgz\r\n```\r\n\r\nThen follow the [setup guide](https://github.com/askalf/redstamp#readme) to wire it in as a Claude Code hook, a daemon, or an MCP proxy.\r\n\r\n## Why isn't it on npm?\r\n\r\nredstamp detects prompt-injection, secret-exfiltration, and destructive-command patterns — so its source necessarily *contains* a large corpus of those patterns, held as detection data. That is the same shape as an antivirus definition file, and npm's automated content scan reads it as malware and rejects the upload. An allowlist review was declined.\r\n\r\nWe won't obfuscate, encode, or split those signatures to get past a scanner. That is detection evasion, and it would destroy the plain-source auditability that ought to be the reason you trust a security tool at all.\r\n\r\nSo redstamp is distributed as signed release tarballs with provenance you can verify yourself — a stronger integrity guarantee than an unsigned registry install. This package exists only so that this page tells you where to go.\r\n\r\n---\r\n\r\nPart of **[Own Your Stack](https://github.com/askalf)** — own your AI infrastructure instead of renting it by the token.\r\n","readmeFilename":"README.md"}