{"_id":"@bytebuild/elyra-guardrails","_rev":"4-e3f946c967d2c30cbe7ea9adc47ccfe1","name":"@bytebuild/elyra-guardrails","dist-tags":{"latest":"0.2.0"},"versions":{"0.1.0":{"name":"@bytebuild/elyra-guardrails","version":"0.1.0","keywords":["elyra-package","elyra-extension","elyra","guardrails","security"],"author":{"name":"bytebuild","email":"git-jad@outlook.com"},"license":"MIT","_id":"@bytebuild/elyra-guardrails@0.1.0","maintainers":[{"name":"bytebuild","email":"git-jad@outlook.com"}],"homepage":"https://github.com/git-jad/elyra-guardrails#readme","bugs":{"url":"https://github.com/git-jad/elyra-guardrails/issues"},"dist":{"shasum":"5ed1a87fa8c466823f216782098ea78c9a192f19","tarball":"https://registry.npmjs.org/@bytebuild/elyra-guardrails/-/elyra-guardrails-0.1.0.tgz","fileCount":63,"integrity":"sha512-t1hlEKXiq7fg86k1+zSCMwzbfkv5QmT6x/F+U265LbVgns5OGVFZRmDz9jTsugRFBUPXGtAk+hmKgYwl0C0XwQ==","signatures":[{"sig":"MEQCID/s8OeQ1hzpfmf6Ig3IVaV6pGit64Lq5e1JnngZzlFgAiBT6fzg0gjeLf0I/JfU4TOSYxOkL/KQF7M5HiNIyi6TUw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":210649},"type":"module","elyra":{"extensions":["./extensions/path-access/index.ts","./extensions/guardrails/index.ts","./extensions/permission-gate/index.ts"]},"gitHead":"8c686106be902d6674fe889c55cd5ef48e105e62","private":false,"scripts":{"lint":"biome check","test":"vitest run","format":"biome check --write","prepare":"[ -d .git ] && husky || true","release":"pnpm changeset publish","version":"changeset version","changeset":"changeset","typecheck":"tsc --noEmit","gen:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o schema.json","test:watch":"vitest","check:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o /tmp/pi-guardrails-schema-check.json && diff -q schema.json /tmp/pi-guardrails-schema-check.json","check:lockfile":"pnpm install --frozen-lockfile --ignore-scripts"},"_npmUser":{"name":"bytebuild","email":"git-jad@outlook.com"},"repository":{"url":"git+https://github.com/git-jad/elyra-guardrails.git","type":"git"},"_npmVersion":"10.9.8","description":"Security guardrails for the Elyra coding agent: file-protection policies, outside-workspace path access control, and dangerous-command prompts. Port of @aliou/pi-guardrails.","directories":{},"_nodeVersion":"22.22.3","dependencies":{"@aliou/sh":"^0.1.0","@earendil-works/pi-tui":"npm:@elyracode/tui@^0.9.9","@aliou/pi-utils-settings":"^0.15.1","@earendil-works/pi-coding-agent":"npm:@elyracode/coding-agent@^0.9.9"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.26.1","devDependencies":{"husky":"^9.1.7","memfs":"^4.57.2","vitest":"^4.1.4","typescript":"^5.9.3","@types/node":"^25.0.10","@biomejs/biome":"^2.4.15","@changesets/cli":"^2.27.11","@sinclair/typebox":"^0.34.48","@aliou/biome-plugins":"^0.8.1","ts-json-schema-generator":"^2.9.0"},"_npmOperationalInternal":{"tmp":"tmp/elyra-guardrails_0.1.0_1781453796964_0.008213608965693009","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@bytebuild/elyra-guardrails","version":"0.1.1","keywords":["elyra-package","elyra-extension","elyra","guardrails","security"],"author":{"name":"bytebuild","email":"git-jad@outlook.com"},"license":"MIT","_id":"@bytebuild/elyra-guardrails@0.1.1","maintainers":[{"name":"bytebuild","email":"git-jad@outlook.com"}],"homepage":"https://github.com/git-jad/elyra-guardrails#readme","bugs":{"url":"https://github.com/git-jad/elyra-guardrails/issues"},"dist":{"shasum":"fd2f686b17e7d63bff10f4973aaf488cbac46bbb","tarball":"https://registry.npmjs.org/@bytebuild/elyra-guardrails/-/elyra-guardrails-0.1.1.tgz","fileCount":63,"integrity":"sha512-+h7vFVee0d9xswLReffYOuZg8ohahgTdxb20skRg+cKYn3o9r1Dd+YaC9oZShE3gP6MYUha0B08J9QqArSWseQ==","signatures":[{"sig":"MEQCIFBp6TVe4bqCRKNf5LQEyQ3WvziCofYMFRr+bz0lna8mAiAg3I8Wi6XnrSTPHUElueTorHnhIK7AtlP+teuTkIgJaw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":210649},"type":"module","elyra":{"extensions":["./extensions/path-access/index.ts","./extensions/guardrails/index.ts","./extensions/permission-gate/index.ts"]},"gitHead":"80c0f3b2b895673ce66a85effd67e31941040dac","private":false,"scripts":{"lint":"biome check","test":"vitest run","format":"biome check --write","prepare":"[ -d .git ] && husky || true","release":"pnpm changeset publish","version":"changeset version","changeset":"changeset","typecheck":"tsc --noEmit","gen:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o schema.json","test:watch":"vitest","check:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o /tmp/pi-guardrails-schema-check.json && diff -q schema.json /tmp/pi-guardrails-schema-check.json","check:lockfile":"pnpm install --frozen-lockfile --ignore-scripts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a5431221-642a-48be-964c-dfa625c53313"}},"repository":{"url":"git+https://github.com/git-jad/elyra-guardrails.git","type":"git"},"_npmVersion":"11.17.0","description":"Security guardrails for the Elyra coding agent: file-protection policies, outside-workspace path access control, and dangerous-command prompts. Port of @aliou/pi-guardrails.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@aliou/sh":"^0.1.0","@earendil-works/pi-tui":"npm:@elyracode/tui@^0.9.9","@aliou/pi-utils-settings":"^0.15.1","@earendil-works/pi-coding-agent":"npm:@elyracode/coding-agent@^0.9.9"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.26.1","devDependencies":{"husky":"^9.1.7","memfs":"^4.57.2","vitest":"^4.1.4","typescript":"^5.9.3","@types/node":"^25.0.10","@biomejs/biome":"^2.4.15","@changesets/cli":"^2.27.11","@sinclair/typebox":"^0.34.48","@aliou/biome-plugins":"^0.8.1","ts-json-schema-generator":"^2.9.0"},"_npmOperationalInternal":{"tmp":"tmp/elyra-guardrails_0.1.1_1781461283893_0.5213983710332495","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@bytebuild/elyra-guardrails","version":"0.1.2","keywords":["elyra-package","elyra-extension","elyra","guardrails","security"],"author":{"name":"bytebuild","email":"git-jad@outlook.com"},"license":"MIT","_id":"@bytebuild/elyra-guardrails@0.1.2","maintainers":[{"name":"bytebuild","email":"git-jad@outlook.com"}],"homepage":"https://github.com/git-jad/elyra-guardrails#readme","bugs":{"url":"https://github.com/git-jad/elyra-guardrails/issues"},"dist":{"shasum":"6e74e4b7330002d9837a9d00227645d85229e541","tarball":"https://registry.npmjs.org/@bytebuild/elyra-guardrails/-/elyra-guardrails-0.1.2.tgz","fileCount":63,"integrity":"sha512-ngAqk9qeD+UXxn8MvvKT0xxsKhso3cYXFQI9EXqB5r/Iq4G+GX9njq6bVBcjK6pu7kF1yyCSmpcWHx6193rtdQ==","signatures":[{"sig":"MEUCIQDKuccohHYs0oUtWt7TjZDCH74xz/g/69B5IenI4DgZfwIgEZ1cwyQxcp9/KsEp3VERHZ/gTRWAmFMFqoKWah6DwZw=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":210454},"type":"module","elyra":{"extensions":["./extensions/path-access/index.ts","./extensions/guardrails/index.ts","./extensions/permission-gate/index.ts"]},"gitHead":"9e7a6a9b1606b98f945afec1aa5a0a543aa926f3","private":false,"scripts":{"lint":"biome check","test":"vitest run","format":"biome check --write","prepare":"[ -d .git ] && husky || true","release":"pnpm changeset publish","version":"changeset version","changeset":"changeset","typecheck":"tsc --noEmit","gen:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o schema.json","test:watch":"vitest","check:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o /tmp/pi-guardrails-schema-check.json && diff -q schema.json /tmp/pi-guardrails-schema-check.json","check:lockfile":"pnpm install --frozen-lockfile --ignore-scripts"},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a5431221-642a-48be-964c-dfa625c53313"}},"repository":{"url":"git+https://github.com/git-jad/elyra-guardrails.git","type":"git"},"_npmVersion":"11.17.0","description":"Security guardrails for Elyra Code: file-protection policies, outside-workspace path access control, and dangerous-command prompts. Port of @aliou/pi-guardrails.","directories":{},"_nodeVersion":"24.16.0","dependencies":{"@aliou/sh":"^0.1.0","@earendil-works/pi-tui":"npm:@elyracode/tui@^0.9.9","@aliou/pi-utils-settings":"^0.15.1","@earendil-works/pi-coding-agent":"npm:@elyracode/coding-agent@^0.9.9"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"packageManager":"pnpm@10.26.1","devDependencies":{"husky":"^9.1.7","memfs":"^4.57.2","vitest":"^4.1.4","typescript":"^5.9.3","@types/node":"^25.0.10","@biomejs/biome":"^2.4.15","@changesets/cli":"^2.27.11","@sinclair/typebox":"^0.34.48","@aliou/biome-plugins":"^0.8.1","ts-json-schema-generator":"^2.9.0"},"_npmOperationalInternal":{"tmp":"tmp/elyra-guardrails_0.1.2_1781471610846_0.5309338489866415","host":"s3://npm-registry-packages-npm-production"}},"0.2.0":{"name":"@bytebuild/elyra-guardrails","version":"0.2.0","description":"Security guardrails for Elyra Code: file-protection policies, outside-workspace path access control, and dangerous-command prompts. Port of @aliou/pi-guardrails.","license":"MIT","type":"module","private":false,"author":{"name":"bytebuild","email":"dev-jad@outlook.com"},"keywords":["elyra-package","elyra-extension","elyra","guardrails","security"],"homepage":"https://github.com/git-jad/elyra-guardrails#readme","bugs":{"url":"https://github.com/git-jad/elyra-guardrails/issues"},"repository":{"type":"git","url":"git+https://github.com/git-jad/elyra-guardrails.git"},"elyra":{"extensions":["./extensions/path-access/index.ts","./extensions/guardrails/index.ts","./extensions/permission-gate/index.ts"]},"publishConfig":{"access":"public"},"dependencies":{"@aliou/pi-utils-settings":"npm:@bytebuild/elyra-utils-settings@^0.1.0","@aliou/sh":"^0.1.0","@earendil-works/pi-coding-agent":"npm:@elyracode/coding-agent@^0.9.9","@earendil-works/pi-tui":"npm:@elyracode/tui@^0.9.9"},"devDependencies":{"@aliou/biome-plugins":"^0.8.1","@biomejs/biome":"^2.4.15","@changesets/cli":"^2.27.11","@sinclair/typebox":"^0.34.48","@types/node":"^25.0.10","husky":"^9.1.7","memfs":"^4.57.2","ts-json-schema-generator":"^2.9.0","typescript":"^5.9.3","vitest":"^4.1.4"},"scripts":{"typecheck":"tsc --noEmit","gen:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o schema.json","check:schema":"ts-json-schema-generator --path src/shared/config/types.ts --type GuardrailsConfig --no-type-check -o /tmp/pi-guardrails-schema-check.json && diff -q schema.json /tmp/pi-guardrails-schema-check.json","test":"vitest run","test:watch":"vitest","lint":"biome check","format":"biome check --write","check:lockfile":"pnpm install --frozen-lockfile --ignore-scripts","prepare":"[ -d .git ] && husky || true","changeset":"changeset","version":"changeset version","release":"pnpm changeset publish"},"packageManager":"pnpm@10.26.1","gitHead":"2628bba336949727579ea22166ad3f4bd44acc9b","_id":"@bytebuild/elyra-guardrails@0.2.0","_nodeVersion":"24.16.0","_npmVersion":"11.17.0","dist":{"integrity":"sha512-lYt+9u4LZkCrQlLNfowaWeCvT43zF8/RTTM0Hax6y5EajPHmeOR+jllH0H240PSkHSqK/7jI8NW1whOtKxO0zQ==","shasum":"e52f25e4580d8952be39623d66fe4a5f5bbd5da2","tarball":"https://registry.npmjs.org/@bytebuild/elyra-guardrails/-/elyra-guardrails-0.2.0.tgz","fileCount":65,"unpackedSize":223047,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCICOO9yVJp5pYVf6ubDX0+eCGI9gMknBljeej/Q1eJeHlAiB+hpN3hwBHnwz+YLucxwN/QIljuDfQaceaIUMrkMc8tQ=="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a5431221-642a-48be-964c-dfa625c53313"}},"directories":{},"maintainers":[{"name":"bytebuild","email":"dev-jad@outlook.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/elyra-guardrails_0.2.0_1782308035589_0.23831045155050523"},"_hasShrinkwrap":false}},"time":{"created":"2026-06-14T16:16:36.780Z","modified":"2026-06-24T13:33:55.856Z","0.1.0":"2026-06-14T16:16:37.129Z","0.1.1":"2026-06-14T18:21:24.053Z","0.1.2":"2026-06-14T21:13:30.988Z","0.2.0":"2026-06-24T13:33:55.738Z"},"bugs":{"url":"https://github.com/git-jad/elyra-guardrails/issues"},"author":{"name":"bytebuild","email":"dev-jad@outlook.com"},"license":"MIT","homepage":"https://github.com/git-jad/elyra-guardrails#readme","keywords":["elyra-package","elyra-extension","elyra","guardrails","security"],"repository":{"type":"git","url":"git+https://github.com/git-jad/elyra-guardrails.git"},"description":"Security guardrails for Elyra Code: file-protection policies, outside-workspace path access control, and dangerous-command prompts. Port of @aliou/pi-guardrails.","maintainers":[{"name":"bytebuild","email":"dev-jad@outlook.com"}],"readme":"![elyra-guardrails](.github/banner.svg)\n\n# Guardrails for Elyra Code\n\nGuardrails adds safety checks to [Elyra Code](https://elyracode.com) so agents are less likely to read secrets, write protected files, access paths outside the workspace, or run dangerous shell commands by accident.\n\n> **Port notice.** This is a community port of [`@aliou/pi-guardrails`](https://github.com/aliou/pi-guardrails) to Elyra Code. All credit for the original design and implementation goes to its authors. The walkthrough recordings below come from the upstream project; the UI and flows are equivalent under Elyra Code.\n\nThis package installs three Elyra Code extensions:\n\n- **guardrails** for file protection policies, settings, onboarding, and examples.\n- **path-access** for controlling access outside the current workspace.\n- **permission-gate** for confirming or blocking risky shell commands.\n\n## Install\n\n```bash\nelyra install npm:@bytebuild/elyra-guardrails\n```\n\nInstalls write to global settings (`~/.elyra/agent/settings.json`) by default. Add `-l` to write to project settings (`.elyra/settings.json`) so the package is shared with your team.\n\n## First run\n\nAfter installing, run the onboarding command to choose a starting setup:\n\n```text\n/guardrails:onboarding\n```\n\n[![Guardrails onboarding walkthrough](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/onboarding.gif)](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/onboarding.mp4)\n\nYou can change everything later with:\n\n```text\n/guardrails:settings\n```\n\n## Included extensions\n\n### guardrails\n\nThe `guardrails` extension owns file protection policies and the user-facing commands.\n\nUse it to protect files like `.env`, private keys, local credentials, generated logs, database dumps, or any project-specific path you do not want the agent to read or modify without clear intent.\n\n[![Guardrails policies and settings walkthrough](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/policies.gif)](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/policies.mp4)\n\nUseful commands:\n\n```text\n/guardrails:settings\n/guardrails:onboarding\n/guardrails:examples\n```\n\n### path-access\n\nThe `path-access` extension checks tool calls that target paths outside the current working directory.\n\nIt can allow, block, or ask before the agent accesses files elsewhere on your machine. In ask mode, you can allow one file or a directory once, for the session, or always.\n\nGranted paths are stored in `pathAccess.allowedPaths` as explicit `{ kind, path }` entries: `file` matches the exact path, `directory` matches the directory and its descendants. Edit them through `/guardrails:settings` (Path Access → Allowed paths, Tab toggles file/directory) or directly in the settings file. Paths support `~/` for home. Existing configs using the legacy string form (trailing `/` for directories) are migrated automatically.\n\n[![Guardrails path access prompt walkthrough](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/path-access.gif)](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/path-access.mp4)\n\n### permission-gate\n\nThe `permission-gate` extension detects dangerous bash commands before they run.\n\nIt catches built-in risky patterns like recursive deletes, privileged commands, disk formatting, broad permission changes, and configured custom patterns. You can allow once, allow for the session, deny, or configure auto-deny rules.\n\n[![Guardrails permission gate walkthrough](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/permission-gate.gif)](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/permission-gate.mp4)\n\n## Configuration\n\nMost configuration should happen through the interactive settings UI:\n\n```text\n/guardrails:settings\n```\n\nAdvanced users can edit the settings file directly:\n\n- `~/.elyra/agent/extensions/guardrails.json`\n\nGuardrails writes a `$schema` field to saved settings files, so modern editors provide autocomplete and validation. The generated schema is committed at [`schema.json`](schema.json).\n\n> **Scope note (Elyra port).** Configuration is **global-only** in this port. Project-scoped config is disabled because the upstream settings library hardcodes a `.pi/` project directory that does not fit Elyra's `.elyra/` convention. Session-only (\"memory\") overrides remain available through the settings UI. See [SYNC.md](SYNC.md) for details and the path to restoring project scope.\n\n## Examples\n\nUse the examples command to add common policy and command presets without replacing your existing config:\n\n```text\n/guardrails:examples\n```\n\n[![Guardrails examples command walkthrough](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/examples.gif)](https://assets.aliou.me/github/aliou/pi-guardrails/v0.12.0/examples.mp4)\n\nThe available presets live in [`extensions/guardrails/commands/settings/examples.ts`](extensions/guardrails/commands/settings/examples.ts).\n\n## Similar but different\n\nElyra Code is designed to make agent safety extensible. Guardrails focuses on deterministic, configurable file policies, outside-workspace path access, and dangerous-command prompts. It is a deterministic guardrail layer, not a hard sandbox: extensions still run with your own permissions.\n\nSee the upstream [`@aliou/pi-guardrails`](https://github.com/aliou/pi-guardrails) for the original Pi ecosystem and a list of related packages.\n\n## Credits\n\n`@bytebuild/elyra-guardrails` is a port of [`@aliou/pi-guardrails`](https://github.com/aliou/pi-guardrails) by Aliou, which targets the Pi coding agent. This fork adapts it for Elyra Code. Licensed under [MIT](LICENSE).\n\n## Development\n\n```bash\npnpm test         # Run tests\npnpm test:watch   # Run tests in watch mode\npnpm typecheck    # Type check\npnpm lint         # Lint\npnpm format       # Format\npnpm gen:schema   # Regenerate schema.json\npnpm check:schema # Verify schema.json is current\n```\n","readmeFilename":"README.md"}