{"_id":"@enclave-vm/ast","_rev":"16-2df86b0914a5df504ffffd1b9b3c9e6a","name":"@enclave-vm/ast","dist-tags":{"latest":"2.15.2"},"versions":{"0.0.1":{"name":"@enclave-vm/ast","version":"0.0.1","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@0.0.1","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"5057a56e63d6353a14b9b774456631893916c092","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-0.0.1.tgz","fileCount":160,"integrity":"sha512-8+eKLhlHROYYNKAbagGkWscRnww69X7rblFuveSPqKEkxOmBJ/iAtvYrrdQmM4xqOl2o9KzoWLdFoigxvW9RSQ==","signatures":[{"sig":"MEQCIDAdzIGuKzQTelJ/7Zux9i5twsqtLjtZ2Juy7/U3dkXxAiAYZXq6ET8CRBqHGI7gKzBdXQ44yXS3Z0C0yY7Y7N1COQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":1143966},"main":"./src/index.js","type":"commonjs","types":"./src/index.d.ts","exports":{".":{"types":"./src/index.d.ts","import":"./src/index.js","default":"./src/index.js"},"./package.json":"./package.json"},"gitHead":"2c673546f09e5cacf7dc469769441bbac9cf7838","_npmUser":{"name":"davidfrontegg","email":"david@frontegg.com"},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.6.2","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_0.0.1_1769635538003_0.6797856894765175","host":"s3://npm-registry-packages-npm-production"}},"2.8.0":{"name":"@enclave-vm/ast","version":"2.8.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.8.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"3f26554081bbca0cedbb3521df937740d3e4633c","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.8.0.tgz","fileCount":59,"integrity":"sha512-OBgKff5cikEnEPNFdt+qwBGFH0f82ctBXlySGbPqOxyL8GOEuX15zXTp6XseYAGiv8RY+YisiSwUdLZonZPuuA==","signatures":[{"sig":"MEQCIEZxlYxJkL/otyZyHN8NYP1Ai9OU1kgHkeBONop7HTNnAiB+7HK7sUAw0PDw1Y0h23mDuKRoO9Gp3pMGKy4dmxEnBg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.8.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":613873},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"6ffaee2ef4607e08766b54df24dd0a5fd06c4b1f","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.8.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.8.0_1769648193669_0.9179953669939218","host":"s3://npm-registry-packages-npm-production"}},"2.9.0":{"name":"@enclave-vm/ast","version":"2.9.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.9.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"ae2a230d5bbe926cbf128a25cff74ff01c5eee60","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.9.0.tgz","fileCount":59,"integrity":"sha512-V1s/liu5PJlkLs1rnkW91kevdj18z+QTVgt6QnfEt82TJKqAb8qU/N3Qha6aGnVUWVEnQ3s/5q1Sj9yIvXTqiw==","signatures":[{"sig":"MEQCIGLwpmYGfRJdw+choyAe3REEeUtEpU5L7500kuN4zR7gAiA+cdRnOkt+E0PQ8USMn/izmKq+kY2t/ZuNw5zP8KCfyg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.9.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":613873},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"0b217fac93b200708f1b73ad2c335046f5cd7cca","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.8.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.9.0_1769648723449_0.5586967829843186","host":"s3://npm-registry-packages-npm-production"}},"2.9.1":{"name":"@enclave-vm/ast","version":"2.9.1","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.9.1","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"b1f75dfdd7e75c749f18e1c22d865bf983ee39aa","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.9.1.tgz","fileCount":59,"integrity":"sha512-fGA9u8ybEcK29Gvh04nIdIX3j5fD6R/uqgoovkQG3kZplCqCONHFLUrHRgPuobonSCuJG5sBh/P+LCgU18NHqQ==","signatures":[{"sig":"MEUCICO9f9TRV2IVbyiBF26kyVKtPjhZSjfP5JBUB8+nPLj7AiEAyKxe7WDPqTYrX7iBUMrhFz4DO3XZ3zu8V8wNuy8ZBRo=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.9.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":613873},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"135008065bab3ce9143faa6d579c0c908079031d","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.8.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.9.1_1769754011679_0.4485134407782567","host":"s3://npm-registry-packages-npm-production"}},"2.9.2":{"name":"@enclave-vm/ast","version":"2.9.2","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.9.2","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"e9c0a8c08ea57175359dd2ab06ea2365f6d184cb","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.9.2.tgz","fileCount":59,"integrity":"sha512-C6wbqRNpqimfAo1D1voS+VlWB27SGhykgWfk1dgMvw5FqJ0uTRT5oex7HVVQXhrVUmTBB8SgxsdS9zOFjvmSuA==","signatures":[{"sig":"MEYCIQCv6CURTtWy8i2RblAVLPhZmSksIkUYTZJ81ogqGvw62QIhAJUNd7GEktuEKaYqs5x3BER37Sla+TdkR4D9R1ZzfW52","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.9.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":613873},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"e13a6dc42b0fe9e7f0e1c4bf40e2a78790bf1847","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.8.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.9.2_1769757403583_0.9187932787421833","host":"s3://npm-registry-packages-npm-production"}},"2.10.0":{"name":"@enclave-vm/ast","version":"2.10.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.10.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"0fe20a63975e580e84189fa79cc4130b1983d5e3","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.10.0.tgz","fileCount":59,"integrity":"sha512-V42hgyU3bbvKA610R1El7oEq8zeMZfyRbzq92lzQhwqFiAsDBf1g9p+SD6X/OEpHXLvbON62GD1p4zhUsv6Mcw==","signatures":[{"sig":"MEQCIBsFmUsqWQzeZpJI8jfCcLrz/O1mSrxE5kCp5YL9H/z9AiAzCYBAThUqjU0zC3Vo0MnlJYhENv2T4b3iWKy69Zm/eg==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.10.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":613293},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"2972333dc6aea77430507a186cba32a491b5cbe1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.8.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.10.0_1769950517710_0.94221925650985","host":"s3://npm-registry-packages-npm-production"}},"2.10.1":{"name":"@enclave-vm/ast","version":"2.10.1","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.10.1","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"4ca1084d6b11361b849e7a70d2625bd0af5a8721","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.10.1.tgz","fileCount":59,"integrity":"sha512-56vuTZFuBj1wHsNWmD2E7U9wgzzoWcCjKRBKX8YbewqZ+SxLSTtIhNSxyRKI8D0MCHUWjB6FVohtQ24Fw3g3Og==","signatures":[{"sig":"MEUCIQDa39nFTJtqqrTEzLfkmUhPTEexlebDBSmZjVgjLivDbwIgb12q9VezR+a1xI3H+4NRdUcOER9iU8yA5jtDX4aclRA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.10.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":618464},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"7a9b981e9986bbd14055247e1474397713e533ff","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.8.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.10.1_1770086073702_0.36250029025960306","host":"s3://npm-registry-packages-npm-production"}},"2.11.0":{"name":"@enclave-vm/ast","version":"2.11.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.11.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"b36fcbd1398bc259d1a011ce3a44af8a22c1975f","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.11.0.tgz","fileCount":59,"integrity":"sha512-xK6RJDCTdAg2ypFIasfK4qBL9vzND7NbOhH/WXNnODZwAnorSfVVV4okvh5D3hecVVu9TVEt96Clc7sm1hWJvQ==","signatures":[{"sig":"MEYCIQDe/U/dcGisLT6kbN57nsvEX4BslRg2sFCb0Yp01E9yvAIhAPs20bwCbuJaSNEIcHDG/yeDx3Uu/mURLFAdbqQJZRiz","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.11.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":621157},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"1dd877cf30d1eafd9ace6c47dea74aa07c5cbc23","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.10.1","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.11.0_1771628182797_0.01169194009475083","host":"s3://npm-registry-packages-npm-production"}},"2.11.1":{"name":"@enclave-vm/ast","version":"2.11.1","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.11.1","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"092a345b2f6f3a0c2840b947de7340c0a350c030","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.11.1.tgz","fileCount":60,"integrity":"sha512-VvctvbTj8oSViX+RF2coimvw3Ts2ORhO3lZBR83E5SoG/L2qHn3LROVUEuuIW9UOcPiqopZsaf+T9CH1dmu+ZQ==","signatures":[{"sig":"MEUCIFryB78MjTxxCgTOdlJbHa6rTMbbjCG/WrtRtwn4iH5xAiEAxL6QQt/FCqfeJJUAQOnCxYXrBfoR3seMew63896qurg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.11.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":634223},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"0ec916f6676df2a5e9792f17f648b9aeefa79394","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.10.1","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.11.1_1771762058030_0.3248032601521018","host":"s3://npm-registry-packages-npm-production"}},"2.12.0":{"name":"@enclave-vm/ast","version":"2.12.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.12.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"8b095246337f8b7e6810f72a56f62e04e14995e5","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.12.0.tgz","fileCount":60,"integrity":"sha512-SZo4eFPzFwhYlTOQy0hSOsf7++VSi9XtPBaR/1ljA9HOAoTU2kzBaptExKpfKbQmqbZ69/cmdGrwSCS3lDkSiQ==","signatures":[{"sig":"MEUCIQD4vvS6ZMvm+j/yFi89xGhBQzS9eGAqMc8pzRVF+YbaqgIgFceHUp4AQXJV5emo6WFs2p586JqZgOD//xZx+zeW3A4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.12.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":634123},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"d20b35221fb22c1430a556b2ccd4f37e44dc21a2","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.10.1","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.12.0_1772025116239_0.6293459425796561","host":"s3://npm-registry-packages-npm-production"}},"2.13.0":{"name":"@enclave-vm/ast","version":"2.13.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.13.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"5f5493d2cea0fdb0133533947bc52190d7d349db","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.13.0.tgz","fileCount":60,"integrity":"sha512-cLUESoUY6b0/2HGCi5esq6TkyKqQF/ymH6aJFuLm1vnPBt9jP7GHMSTCxvl+orHqHqaA672I/fN/86/GVH2F1A==","signatures":[{"sig":"MEYCIQCjQSUmLjGIIZccEmMr2dP0zMzWaQtJ7x1aW06sVDLhbgIhAOOWzfbaHovXvHYjO6rdfxRfrt3BZ7JBkKSpEtyLo9JP","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.13.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":634123},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"01ff760e8fc79f94c76a5db90310bb589fc172a0","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.12.1","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.13.0_1775088212254_0.11265719906206595","host":"s3://npm-registry-packages-npm-production"}},"2.14.0":{"name":"@enclave-vm/ast","version":"2.14.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.14.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"8dddc241e9ba997c5d20023081dd481aed3ffffa","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.14.0.tgz","fileCount":60,"integrity":"sha512-ON1tR4eBM1GVFEFqu4enhQGbcFIfOYMCmXoASTzUDm9qVSNsA1e/3Ogi7EG4/I0SjrnDLsKV8HCD1oMna6zIbg==","signatures":[{"sig":"MEYCIQCoUUz1+53XJHakSiEC/m2myugzwZmSPMCFESqhc/MO+gIhANzZjQhmlqTDGsK6I2adXXhgCYbtnuIlpq+oEViBt7C2","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.14.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":634123},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"8587e0b2cb6004bda168ee1399650fc3fa62b496","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.17.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.14.0_1781818857007_0.2885962724975606","host":"s3://npm-registry-packages-npm-production"}},"2.14.1":{"name":"@enclave-vm/ast","version":"2.14.1","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.14.1","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"1b231f97c890f698c5704dcd59aae3cba961aed0","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.14.1.tgz","fileCount":60,"integrity":"sha512-OECL9nUAFL5gUrQud+yuafVsX1iOViFmn8LAGzNuoV0QkVbfEMqEYtCHm7LoRldydOyqih/l54JYIemUW6aSvg==","signatures":[{"sig":"MEUCIBUCFOLNy4GJmtncvDA+uRd0Ri8O/DAT3d56ecYGXiLdAiEAg1IbSUibSYpnvDgW63USCXSmgh/0I7D85rWwKchadBY=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.14.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":634123},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"c74b1618c7328b3a3a858b49582b2911f549e547","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"11.17.0","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.11.1","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.14.1_1781882163200_0.3524707405224552","host":"s3://npm-registry-packages-npm-production"}},"2.15.0":{"name":"@enclave-vm/ast","version":"2.15.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.15.0","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"07dccac26724579eed084c44ece0b4d63dd28220","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.15.0.tgz","fileCount":60,"integrity":"sha512-JuLdiRVsfyPQX+WXYIX87EEUILJfgkDospJiQSj6G8G0LT9/pfLX9wGJZz+A7S2lcXQUnM2GquRdZyCdMKH+iA==","signatures":[{"sig":"MEUCIQCR4k63vuty1jRati9LhhRh8Uv2sorD8DfqFYbAukz3yQIgOh8IKCJrhDwyrFsk+Wxnh8FSVlu4UYOlNHZv2i0l1to=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.15.0","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":634123},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"1ef5de35c7bab7ee438942b04be59febdd0d34c6","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"12.0.1","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.18.0","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.15.0_1784414762287_0.6987139316622795","host":"s3://npm-registry-packages-npm-production"}},"2.15.1":{"name":"@enclave-vm/ast","version":"2.15.1","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","_id":"@enclave-vm/ast@2.15.1","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","bugs":{"url":"https://github.com/agentfront/enclave/issues"},"dist":{"shasum":"7619ef8fe56c92cd813bf8bd3f02ed199e9aacf3","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.15.1.tgz","fileCount":61,"integrity":"sha512-0Rh5oyVrE/tWnWogXzpO5zrDUNXmJivAH98o0y5zPzg48dprnfk+P/JPnCCzAf92tsmFl4ubpTqB1GGvurIKDg==","signatures":[{"sig":"MEQCIG11pfo0qsoUvN3aaxHZjJKeO+05ACSufFRU27ACRwvOAiAr56xlf3nyD3I1bCufF5nkYGqrD9OcPN6rDpIvQVR0gw==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.15.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":655852},"main":"./index.js","types":"./index.d.ts","module":"./esm/index.mjs","exports":{".":{"types":"./index.d.ts","import":"./esm/index.mjs","default":"./index.js","require":"./index.js"},"./package.json":"./package.json"},"gitHead":"203cb69a796578a78117e8a11d5835c1efc0f8e5","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"repository":{"url":"git+https://github.com/agentfront/enclave.git","type":"git","directory":"libs/ast-guard"},"_npmVersion":"12.0.1","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","directories":{},"_nodeVersion":"24.18.0","dependencies":{"acorn":"8.15.0","astring":"1.9.0","acorn-walk":"8.3.4","@types/estree":"1.0.8"},"_hasShrinkwrap":false,"devDependencies":{"typescript":"^5.9.3"},"_npmOperationalInternal":{"tmp":"tmp/ast_2.15.1_1785026910711_0.8521119432875919","host":"s3://npm-registry-packages-npm-production"}},"2.15.2":{"name":"@enclave-vm/ast","version":"2.15.2","description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","author":{"name":"AgentFront","email":"info@agentfront.dev"},"homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","license":"Apache-2.0","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"repository":{"type":"git","url":"git+https://github.com/agentfront/enclave.git","directory":"libs/ast-guard"},"bugs":{"url":"https://github.com/agentfront/enclave/issues"},"main":"./index.js","module":"./esm/index.mjs","types":"./index.d.ts","exports":{"./package.json":"./package.json",".":{"types":"./index.d.ts","import":"./esm/index.mjs","require":"./index.js","default":"./index.js"}},"dependencies":{"@types/estree":"1.0.8","acorn":"8.15.0","acorn-walk":"8.3.4","astring":"1.9.0"},"devDependencies":{"typescript":"^5.9.3"},"gitHead":"a0c673a05953b8aa1a0f6dd7f2b956b181fcc9ec","_id":"@enclave-vm/ast@2.15.2","_nodeVersion":"24.18.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-nmWtEf44EJ2LA/AFkzhd8AmPy6kk1qgNnWAg012tT3bqfjz7t7l9Vew5eKZyyLkmh6Q5FIvZLKg81zAlWYobiw==","shasum":"a86c422a9188738a96391143380a6f198712fce0","tarball":"https://registry.npmjs.org/@enclave-vm/ast/-/ast-2.15.2.tgz","fileCount":61,"unpackedSize":659538,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@enclave-vm%2fast@2.15.2","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIQDnrEpywUg3/fUURne2Ywp3N7WlnK0k38HxGoeTYRUpfgIgJ8200ZW2MlO5MVV1WVHNlOny4f4ZwxYCNbIvpyBIRL0="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:a3b9789a-ed84-4003-b807-5f12b3b6f08b"}},"directories":{},"maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/ast_2.15.2_1786061095298_0.059246789136800704"},"_hasShrinkwrap":false}},"time":{"created":"2026-01-28T21:25:37.906Z","modified":"2026-08-07T00:04:55.981Z","0.0.1":"2026-01-28T21:25:38.190Z","2.8.0":"2026-01-29T00:56:33.831Z","2.9.0":"2026-01-29T01:05:23.600Z","2.9.1":"2026-01-30T06:20:11.825Z","2.9.2":"2026-01-30T07:16:43.741Z","2.10.0":"2026-02-01T12:55:17.867Z","2.10.1":"2026-02-03T02:34:33.869Z","2.11.0":"2026-02-20T22:56:22.938Z","2.11.1":"2026-02-22T12:07:38.203Z","2.12.0":"2026-02-25T13:11:56.464Z","2.13.0":"2026-04-02T00:03:32.460Z","2.14.0":"2026-06-18T21:40:57.175Z","2.14.1":"2026-06-19T15:16:03.391Z","2.15.0":"2026-07-18T22:46:02.495Z","2.15.1":"2026-07-26T00:48:30.883Z","2.15.2":"2026-08-07T00:04:55.614Z"},"bugs":{"url":"https://github.com/agentfront/enclave/issues"},"author":{"name":"AgentFront","email":"info@agentfront.dev"},"license":"Apache-2.0","homepage":"https://github.com/agentfront/enclave/tree/main/libs/ast-guard","keywords":["ast","validator","javascript","static-analysis","code-validation","acorn","ast-validation","security","code-quality","ast-guard","security-guard"],"repository":{"type":"git","url":"git+https://github.com/agentfront/enclave.git","directory":"libs/ast-guard"},"description":"A production-ready AST security guard for JavaScript - validate, protect, and enforce code safety with extensible rules","maintainers":[{"name":"davidfrontegg","email":"david@frontegg.com"}],"readme":"# AST Guard\n\n[![npm version](https://img.shields.io/npm/v/ast-guard.svg)](https://www.npmjs.com/package/ast-guard)\n[![License](https://img.shields.io/badge/license-Apache--2.0-blue.svg)](LICENSE)\n[![TypeScript](https://img.shields.io/badge/TypeScript-5.0+-blue.svg)](https://www.typescriptlang.org/)\n\n> A production-ready, extensible AST validator for JavaScript with rule-based validation\n\nAST Guard is a powerful static analysis tool for JavaScript code. It provides a flexible, rule-based architecture for validating Abstract Syntax Trees (AST) with comprehensive built-in rules and support for custom validation logic.\n\n## Bank-Grade Security\n\n### Hardened Against All Known Sandbox Escape Exploits\n\n| Metric         | Value                                                |\n| -------------- | ---------------------------------------------------- |\n| CVE Protection | 100% (all known vm2, isolated-vm, node-vm exploits)  |\n| Security Tests | 613 tests, 100% pass rate                            |\n| Code Coverage  | 95%+                                                 |\n| Defense Layers | 4 (AST validation, transformation, proxy, isolation) |\n\n**Protected Against:**\n\n- **vm2 CVEs**: CVE-2023-29017, CVE-2023-30547, CVE-2023-32313, CVE-2023-37466\n- **Constructor chain escapes**: `[].constructor.constructor('code')()`\n- **Prototype pollution**: `__proto__`, `Object.setPrototypeOf`\n- **Reflection API bypasses**: `Reflect.get`, `Reflect.construct`\n- **Global object access**: `window`, `globalThis`, `this`\n\nFor detailed CVE analysis, see [CVE-COVERAGE.md](./docs/CVE-COVERAGE.md). For the full list of 100+ blocked attack vectors, see [SECURITY-AUDIT.md](./docs/SECURITY-AUDIT.md).\n\n## Features\n\n- **Production-Ready**: Comprehensive error handling, type-safe APIs, and battle-tested rules\n- **Extensible**: Plugin architecture with custom rule support\n- **Type-Safe**: Full TypeScript support with strict typing\n- **Zero Dependencies**: Lightweight with only `acorn` and `acorn-walk` as dependencies\n- **Comprehensive Rules**: Built-in rules for common validation scenarios\n- **Security-Focused**: Rules to prevent dangerous code patterns\n- **Performance**: Fast validation with configurable limits\n- **Detailed Reporting**: Rich error messages with source locations\n\n## Installation\n\n```bash\nnpm install ast-guard\n# or\nyarn add ast-guard\n# or\npnpm add ast-guard\n```\n\n## Quick Start\n\n```typescript\nimport { JSAstValidator, DisallowedIdentifierRule, NoEvalRule } from 'ast-guard';\n\n// Create validator with built-in rules\nconst validator = new JSAstValidator([\n  new DisallowedIdentifierRule({ disallowed: ['eval', 'Function'] }),\n  new NoEvalRule(),\n]);\n\n// Validate code\nconst result = await validator.validate(`\n  const x = 1;\n  eval(\"alert('hello')\");\n`);\n\nif (!result.valid) {\n  console.log('Validation failed:');\n  result.issues.forEach((issue) => {\n    console.log(`- [${issue.severity}] ${issue.message} (${issue.code})`);\n    if (issue.location) {\n      console.log(`  at line ${issue.location.line}, column ${issue.location.column}`);\n    }\n  });\n}\n```\n\n## Presets\n\nAST Guard provides pre-configured security presets for quick and easy setup. Choose from five security levels, from maximum lockdown to minimal restrictions.\n\n### Available Presets\n\n| Preset         | Security Level | Description                                          | Use Case                            |\n| -------------- | -------------- | ---------------------------------------------------- | ----------------------------------- |\n| **STRICT**     | Maximum        | Blocks all dangerous patterns, loops, and async      | Untrusted code execution            |\n| **SECURE**     | High           | Blocks most dangerous patterns, allows bounded loops | Semi-trusted code with restrictions |\n| **STANDARD**   | Medium         | Sensible defaults, blocks critical risks only        | Trusted code with safety checks     |\n| **PERMISSIVE** | Low            | Minimal restrictions, only blocks eval               | Internal scripts                    |\n\n### Quick Start with Presets\n\n```typescript\nimport { JSAstValidator, Presets, PresetLevel } from 'ast-guard';\n\n// Option 1: Use the Presets object\nconst lockdownRules = Presets.strict();\nconst validator = new JSAstValidator(lockdownRules);\n\n// Option 2: Use createPreset with level\nimport { createPreset } from 'ast-guard';\nconst securedRules = createPreset(PresetLevel.SECURE);\nconst validator = new JSAstValidator(securedRules);\n\n// Option 3: Use individual preset function\nimport { createStandardPreset } from 'ast-guard';\nconst balancedRules = createStandardPreset();\nconst validator = new JSAstValidator(balancedRules);\n```\n\n### Preset Details\n\n#### STRICT Preset\n\n**Maximum security for untrusted code. Bank-grade protection.**\n\nIncludes all security rules to block known sandbox escape exploits:\n\n- ✅ NoEvalRule - Blocks eval() and Function constructor\n- ✅ NoGlobalAccessRule - Blocks constructor chains, Reflect API, global object access\n- ✅ NoAsyncRule - Blocks async/await patterns\n- ✅ DisallowedIdentifierRule - Blocks dangerous identifiers\n- ✅ ForbiddenLoopRule - Blocks loops (or optionally allow bounded loops)\n- ✅ And more...\n\n```typescript\nimport { Presets } from 'ast-guard';\n\n// Maximum lockdown\nconst rules = Presets.strict();\n\n// With customization\nconst rules = Presets.strict({\n  // Allow specific loops\n  allowedLoops: { allowFor: true, allowForOf: true },\n\n  // Require specific API calls\n  requiredFunctions: ['callTool'],\n  minFunctionCalls: 1,\n  maxFunctionCalls: 10,\n\n  // Validate function arguments\n  functionArgumentRules: {\n    callTool: {\n      minArgs: 2,\n      expectedTypes: ['string', 'object'],\n    },\n  },\n\n  // Add custom blocked identifiers\n  additionalDisallowedIdentifiers: ['window', 'document'],\n});\n```\n\n**Blocks:**\n\n- All eval-like constructs (`eval`, `Function`, `setTimeout` with strings)\n- All loops (for, while, do-while, for-in, for-of)\n- All async/await\n- Dangerous identifiers: `process`, `require`, `global`, `__dirname`, `constructor`, `__proto__`, etc.\n\n#### SECURE Preset\n\nHigh security with some flexibility for semi-trusted code.\n\n```typescript\nimport { Presets } from 'ast-guard';\n\nconst rules = Presets.secured({\n  requiredFunctions: ['callTool'],\n  maxFunctionCalls: 20,\n});\n```\n\n**Blocks:**\n\n- All eval-like constructs\n- Dangerous identifiers: `process`, `require`, `global`, `__dirname`\n- Infinite loops (while, do-while)\n- Async function declarations\n\n**Allows:**\n\n- Bounded for/for-of loops\n- Await expressions (but not async functions)\n\n#### STANDARD Preset\n\nMedium security with sensible defaults for most use cases.\n\n```typescript\nimport { Presets } from 'ast-guard';\n\nconst rules = Presets.balanced({\n  requiredFunctions: ['callTool'],\n  additionalDisallowedIdentifiers: ['window', 'document'], // Browser-specific\n});\n```\n\n**Blocks:**\n\n- eval() and Function constructor\n- Critical identifiers: `process`, `require`, `eval`, `Function`\n- Infinite while/do-while loops\n\n**Allows:**\n\n- All for loops (for, for-in, for-of)\n- Async/await\n- Constructor and prototype access\n\n#### PERMISSIVE Preset\n\nLow security for internal or trusted scripts.\n\n```typescript\nimport { Presets } from 'ast-guard';\n\nconst rules = Presets.naive({\n  requiredFunctions: ['callTool'], // Optional API enforcement\n});\n```\n\n**Blocks:**\n\n- eval() only\n\n**Allows:**\n\n- All loops\n- Async/await\n- All identifiers\n- Constructor and prototype access\n\n### Customizing Presets\n\nAll presets accept options to customize their behavior:\n\n```typescript\nimport { Presets } from 'ast-guard';\n\nconst rules = Presets.secured({\n  // Add more blocked identifiers\n  additionalDisallowedIdentifiers: ['window', 'document', 'localStorage'],\n\n  // Require specific functions\n  requiredFunctions: ['callTool', 'getTool'],\n  minFunctionCalls: 1,\n  maxFunctionCalls: 50,\n\n  // Override default loop restrictions\n  allowedLoops: {\n    allowFor: true,\n    allowWhile: true, // Override: allow while in secured preset\n    allowDoWhile: false,\n    allowForIn: false,\n    allowForOf: true,\n  },\n\n  // Override default async restrictions\n  allowAsync: {\n    allowAsyncFunctions: true, // Override: allow async in secured preset\n    allowAwait: true,\n  },\n\n  // Validate specific function arguments\n  functionArgumentRules: {\n    callTool: {\n      minArgs: 2,\n      maxArgs: 3,\n      expectedTypes: ['string', 'object'],\n      validator: (args) => {\n        // Custom validation\n        if (args[0]?.value === '') {\n          return 'Tool name cannot be empty';\n        }\n        return null;\n      },\n    },\n  },\n});\n```\n\n### Real-World Examples\n\n#### Example 1: Untrusted Code Sandbox\n\n```typescript\nimport { JSAstValidator, Presets } from 'ast-guard';\n\n// Maximum security for untrusted user code\nconst validator = new JSAstValidator(\n  Presets.strict({\n    requiredFunctions: ['callTool'],\n    functionArgumentRules: {\n      callTool: {\n        minArgs: 2,\n        expectedTypes: ['string', 'object'],\n      },\n    },\n  }),\n);\n\nconst userCode = `\n  // User-submitted code\n  callTool(\"getData\", { id: 123 });\n`;\n\nconst result = await validator.validate(userCode, {\n  rules: {\n    'no-eval': true,\n    'disallowed-identifier': true,\n    'forbidden-loop': true,\n    'required-function-call': true,\n    'call-argument-validation': true,\n  },\n});\n\nif (result.valid) {\n  // Safe to execute in sandbox\n  executeInSandbox(userCode);\n}\n```\n\n#### Example 2: Plugin System\n\n```typescript\nimport { JSAstValidator, Presets } from 'ast-guard';\n\n// Balanced security for plugin code\nconst validator = new JSAstValidator(\n  Presets.balanced({\n    requiredFunctions: ['registerPlugin'],\n    additionalDisallowedIdentifiers: ['process', 'require', 'fs'],\n  }),\n);\n\nconst pluginCode = await loadPluginCode();\nconst result = await validator.validate(pluginCode, {\n  rules: {\n    'no-eval': true,\n    'disallowed-identifier': true,\n    'required-function-call': true,\n  },\n});\n```\n\n#### Example 3: Internal Automation Scripts\n\n```typescript\nimport { JSAstValidator, Presets } from 'ast-guard';\n\n// Minimal security for trusted internal scripts\nconst validator = new JSAstValidator(\n  Presets.naive({\n    requiredFunctions: ['execute'],\n  }),\n);\n```\n\n### Preset Comparison Matrix\n\n| Feature              | STRICT | SECURE | STANDARD | PERMISSIVE |\n| -------------------- | ------ | ------ | -------- | ---------- |\n| **eval()**           | ❌     | ❌     | ❌       | ❌         |\n| **Function()**       | ❌     | ❌     | ❌       | ✅         |\n| **for loops**        | ❌     | ✅     | ✅       | ✅         |\n| **while loops**      | ❌     | ❌     | ❌       | ✅         |\n| **async/await**      | ❌     | ⚠️     | ✅       | ✅         |\n| **process**          | ❌     | ❌     | ❌       | ✅         |\n| **require**          | ❌     | ❌     | ❌       | ✅         |\n| **global**           | ❌     | ❌     | ✅       | ✅         |\n| **constructor**      | ❌     | ✅     | ✅       | ✅         |\n| **Unreachable code** | ⚠️     | ⚠️     | ⚠️       | ⚠️         |\n\nLegend: ❌ Blocked (error) | ⚠️ Detected (warning) | ✅ Allowed\n\n### AgentScript Globals by Security Level\n\nThe AgentScript preset uses security-level-aware globals for defense-in-depth:\n\n| Global                                     | STRICT | SECURE | STANDARD | PERMISSIVE |\n| ------------------------------------------ | ------ | ------ | -------- | ---------- |\n| **Core API**                               |        |        |          |            |\n| `callTool`                                 | ✅     | ✅     | ✅       | ✅         |\n| **Data Types**                             |        |        |          |            |\n| `Math`, `JSON`, `Array`                    | ✅     | ✅     | ✅       | ✅         |\n| `Object`, `String`, `Number`, `Date`       | ✅     | ✅     | ✅       | ✅         |\n| **Constants**                              |        |        |          |            |\n| `undefined`, `NaN`, `Infinity`             | ✅     | ✅     | ✅       | ✅         |\n| **Utility Functions**                      |        |        |          |            |\n| `parseInt`, `parseFloat`                   | ❌     | ✅     | ✅       | ✅         |\n| `isNaN`, `isFinite`                        | ❌     | ✅     | ✅       | ✅         |\n| `encodeURI`, `decodeURI`                   | ❌     | ✅     | ✅       | ✅         |\n| `encodeURIComponent`, `decodeURIComponent` | ❌     | ✅     | ✅       | ✅         |\n| **Debugging**                              |        |        |          |            |\n| `console`                                  | ❌     | ❌     | ❌       | ✅         |\n\n**Always Blocked:** `eval`, `Function`, `process`, `require`, `window`, `globalThis`, `constructor`, `__proto__`, `Proxy`, `Reflect`, `Promise`, `setTimeout`, `fetch`, `WebSocket`, `Map`, `Set`, `Symbol`, `RegExp`, and 50+ other dangerous globals.\n\n### AgentScript Preset\n\nThe AgentScript preset is specifically designed for safe AI agent orchestration. It provides security rules tailored for executing LLM-generated code that calls tools via `callTool()`.\n\n```typescript\nimport { JSAstValidator, createAgentScriptPreset } from 'ast-guard';\n\n// Basic usage - secure defaults for AgentScript\nconst rules = createAgentScriptPreset();\nconst validator = new JSAstValidator(rules);\n\n// With requireCallTool - enforce that code must call tools\nconst rules = createAgentScriptPreset({\n  requireCallTool: true, // Require at least one callTool() invocation\n});\n```\n\n**Options:**\n\n| Option                            | Type       | Default                    | Description                                                    |\n| --------------------------------- | ---------- | -------------------------- | -------------------------------------------------------------- |\n| `securityLevel`                   | `string`   | `'STANDARD'`               | Security level: `STRICT`, `SECURE`, `STANDARD`, `PERMISSIVE`   |\n| `requireCallTool`                 | `boolean`  | `false`                    | Require at least one `callTool()` invocation in the code       |\n| `allowedGlobals`                  | `string[]` | (based on securityLevel)   | Override allowed globals (takes precedence over securityLevel) |\n| `additionalDisallowedIdentifiers` | `string[]` | `[]`                       | Additional identifiers to block beyond the default set         |\n| `allowArrowFunctions`             | `boolean`  | `true`                     | Whether to allow arrow functions (for array methods)           |\n| `allowedLoops`                    | `object`   | `{ allowFor, allowForOf }` | Override default loop restrictions                             |\n| `reservedPrefixes`                | `string[]` | `['__ag_', '__safe_']`     | Reserved prefixes that user code cannot use                    |\n| `staticCallTarget`                | `object`   | `{ enabled: true }`        | Configuration for static call target validation                |\n| `callToolValidation`              | `object`   | -                          | Validation rules for callTool arguments                        |\n\n**Example with all options:**\n\n```typescript\nconst rules = createAgentScriptPreset({\n  // Require the code to actually call tools\n  requireCallTool: true,\n\n  // Customize allowed globals\n  allowedGlobals: ['callTool', 'getTool', 'Math', 'JSON', 'Array', 'Object'],\n\n  // Block additional identifiers\n  additionalDisallowedIdentifiers: ['fetch', 'XMLHttpRequest'],\n\n  // Allow arrow functions for array methods (default: true)\n  allowArrowFunctions: true,\n\n  // Allow specific loops (default: for and for-of allowed)\n  allowedLoops: {\n    allowFor: true,\n    allowForOf: true,\n    allowWhile: false, // Block while loops\n    allowDoWhile: false, // Block do-while loops\n    allowForIn: false, // Block for-in loops\n  },\n\n  // Static call target validation\n  staticCallTarget: {\n    enabled: true,\n    allowedToolNames: ['users:list', 'users:get'], // Optional whitelist\n  },\n});\n```\n\nThe AgentScript preset is used internally by the `enclave-vm` package for secure code execution.\n\n## Built-in Rules\n\n### DisallowedIdentifierRule\n\nPrevents usage of specific identifiers (e.g., `eval`, `Function`, `process`).\n\n```typescript\nimport { DisallowedIdentifierRule } from 'ast-guard';\n\nconst rule = new DisallowedIdentifierRule({\n  disallowed: ['eval', 'Function', 'process', 'require'],\n  messageTemplate: 'Access to \"{identifier}\" is forbidden',\n});\n```\n\n### ForbiddenLoopRule\n\nPrevents usage of loop constructs. Configurable to allow specific loop types.\n\n```typescript\nimport { ForbiddenLoopRule } from 'ast-guard';\n\nconst rule = new ForbiddenLoopRule({\n  allowFor: false,\n  allowWhile: false,\n  allowDoWhile: false,\n  allowForOf: true, // Allow for-of loops\n  allowForIn: false,\n  message: 'Loops are not allowed in this context',\n});\n```\n\n### RequiredFunctionCallRule\n\nEnsures specific functions are called at least once.\n\n```typescript\nimport { RequiredFunctionCallRule } from 'ast-guard';\n\nconst rule = new RequiredFunctionCallRule({\n  required: ['callTool'],\n  minCalls: 1,\n  maxCalls: 10,\n  messageTemplate: 'Must call {function} at least once',\n});\n```\n\n**Mode Options:**\n\n- `mode: 'all'` (default) - All functions in `required` must be called\n- `mode: 'any'` - At least one function from `required` must be called\n\n```typescript\n// Require either callTool or invokeAPI to be called\nconst rule = new RequiredFunctionCallRule({\n  required: ['callTool', 'invokeAPI'],\n  mode: 'any',\n  minCalls: 1,\n});\n```\n\n### UnreachableCodeRule\n\nDetects unreachable code (code after return/throw/break/continue).\n\n```typescript\nimport { UnreachableCodeRule } from 'ast-guard';\n\nconst rule = new UnreachableCodeRule();\n// Automatically detects unreachable code\n```\n\n### CallArgumentValidationRule\n\nValidates function call arguments (count and types).\n\n```typescript\nimport { CallArgumentValidationRule } from 'ast-guard';\n\nconst rule = new CallArgumentValidationRule({\n  functions: {\n    callTool: {\n      minArgs: 2,\n      maxArgs: 2,\n      expectedTypes: ['string', 'object'],\n    },\n    getTool: {\n      minArgs: 1,\n      maxArgs: 1,\n      expectedTypes: ['string'],\n      validator: (args, node) => {\n        // Custom validation logic\n        const firstArg = args[0];\n        if (firstArg.type === 'Literal' && firstArg.value === '') {\n          return 'Tool name cannot be empty';\n        }\n        return null; // Valid\n      },\n    },\n  },\n});\n```\n\n### NoEvalRule\n\nPrevents usage of `eval()`, `Function()` constructor, and string-based `setTimeout`/`setInterval`.\n\n```typescript\nimport { NoEvalRule } from 'ast-guard';\n\nconst rule = new NoEvalRule();\n// Blocks: eval(), new Function(), setTimeout(\"code\", ...)\n```\n\n### NoAsyncRule\n\nPrevents usage of async/await constructs.\n\n```typescript\nimport { NoAsyncRule } from 'ast-guard';\n\nconst rule = new NoAsyncRule({\n  allowAsyncFunctions: false,\n  allowAwait: false,\n  message: 'Async code is not supported',\n});\n```\n\n## Custom Rules\n\nCreate your own validation rules by implementing the `ValidationRule` interface:\n\n```typescript\nimport { ValidationRule, ValidationContext, ValidationSeverity } from 'ast-guard';\nimport * as walk from 'acorn-walk';\n\nclass NoConsoleRule implements ValidationRule {\n  readonly name = 'no-console';\n  readonly description = 'Prevents usage of console methods';\n  readonly defaultSeverity = ValidationSeverity.WARNING;\n  readonly enabledByDefault = true;\n\n  validate(context: ValidationContext): void {\n    walk.simple(context.ast as any, {\n      MemberExpression: (node: any) => {\n        if (node.object.type === 'Identifier' && node.object.name === 'console') {\n          context.report({\n            code: 'NO_CONSOLE',\n            message: 'Console usage is not recommended',\n            location: node.loc\n              ? {\n                  line: node.loc.start.line,\n                  column: node.loc.start.column,\n                }\n              : undefined,\n          });\n        }\n      },\n    });\n  }\n}\n\n// Use your custom rule\nconst validator = new JSAstValidator([new NoConsoleRule()]);\n```\n\n## Configuration\n\n### Validator Configuration\n\n```typescript\nconst result = await validator.validate(code, {\n  // Parse options (passed to acorn)\n  parseOptions: {\n    ecmaVersion: 'latest',\n    sourceType: 'script',\n  },\n\n  // Rule configuration\n  rules: {\n    'disallowed-identifier': true, // Enable with default options\n    'no-eval': false, // Disable rule\n    'required-function-call': {\n      // Enable with custom options\n      enabled: true,\n      severity: ValidationSeverity.ERROR,\n      options: { required: ['callTool'] },\n    },\n  },\n\n  // Stop on first error\n  stopOnFirstError: false,\n\n  // Maximum number of issues (0 = unlimited)\n  maxIssues: 100,\n});\n```\n\n### Rule Management\n\n```typescript\nconst validator = new JSAstValidator();\n\n// Register rules\nvalidator.registerRule(new DisallowedIdentifierRule({ disallowed: ['eval'] }));\nvalidator.registerRule(new NoEvalRule());\n\n// Get all rules\nconst rules = validator.getRules();\n\n// Get specific rule\nconst rule = validator.getRule('no-eval');\n\n// Unregister rule\nvalidator.unregisterRule('no-eval');\n```\n\n## Validation Results\n\n```typescript\ninterface ValidationResult {\n  valid: boolean; // true if no errors\n  issues: ValidationIssue[]; // All issues found\n  ast?: acorn.Node; // Parsed AST (if parsing succeeded)\n  parseError?: Error; // Parse error (if parsing failed)\n}\n\ninterface ValidationIssue {\n  code: string; // Unique issue code\n  severity: ValidationSeverity; // ERROR | WARNING | INFO\n  message: string; // Human-readable message\n  location?: SourceLocation; // Source location\n  data?: Record<string, unknown>; // Additional context\n}\n```\n\n## Error Handling\n\nAll errors extend `JSAstValidatorError` with specific error types:\n\n```typescript\nimport {\n  JSAstValidatorError,\n  ParseError,\n  RuleConfigurationError,\n  ConfigurationError,\n  RuleNotFoundError,\n  InvalidSourceError,\n} from 'ast-guard';\n\ntry {\n  const result = await validator.validate(code);\n} catch (error) {\n  if (error instanceof ParseError) {\n    console.error(`Parse error at line ${error.line}:`, error.message);\n  } else if (error instanceof InvalidSourceError) {\n    console.error('Invalid source:', error.message);\n  } else if (error instanceof RuleConfigurationError) {\n    console.error(`Rule ${error.ruleName} misconfigured:`, error.message);\n  }\n}\n```\n\n## Statistics\n\n```typescript\nconst result = await validator.validate(code);\nconst stats = validator.getStats(result, Date.now() - startTime);\n\nconsole.log(`Total issues: ${stats.totalIssues}`);\nconsole.log(`Errors: ${stats.errors}`);\nconsole.log(`Warnings: ${stats.warnings}`);\nconsole.log(`Duration: ${stats.durationMs}ms`);\n```\n\n## Use Cases\n\n### 1. Sandboxed Code Execution\n\nValidate code before executing in a sandboxed environment:\n\n```typescript\nconst validator = new JSAstValidator([\n  new DisallowedIdentifierRule({ disallowed: ['eval', 'Function', 'process'] }),\n  new NoEvalRule(),\n  new ForbiddenLoopRule(), // Prevent infinite loops\n  new RequiredFunctionCallRule({ required: ['callTool'] }),\n]);\n\nconst result = await validator.validate(userCode);\nif (result.valid) {\n  // Safe to execute\n  vm.runInContext(userCode, sandbox);\n}\n```\n\n### 2. API Contract Validation\n\nEnsure code follows API contracts:\n\n```typescript\nconst validator = new JSAstValidator([\n  new RequiredFunctionCallRule({ required: ['callTool'] }),\n  new CallArgumentValidationRule({\n    functions: {\n      callTool: {\n        minArgs: 2,\n        expectedTypes: ['string', 'object'],\n      },\n    },\n  }),\n]);\n```\n\n### 3. Security Analysis\n\nDetect potentially dangerous code patterns:\n\n```typescript\nconst validator = new JSAstValidator([\n  new NoEvalRule(),\n  new DisallowedIdentifierRule({\n    disallowed: ['eval', 'Function', 'require', 'process', 'child_process'],\n  }),\n]);\n```\n\n### 4. Code Quality Checks\n\nDetect code quality issues:\n\n```typescript\nconst validator = new JSAstValidator([\n  new UnreachableCodeRule(),\n  // Add custom rules for your quality standards\n]);\n```\n\n## Testing\n\n```bash\n# Run tests\nnpm test\n\n# Run tests with coverage\nnpm run test:coverage\n```\n\n## Performance\n\n- **Parse time**: ~1-5ms for typical scripts (depends on size)\n- **Validation time**: ~1-10ms per rule (depends on complexity)\n- **Memory**: Minimal overhead, AST is shared across rules\n\n## Comparison\n\n| Feature                | AST Guard      | ESLint       | TypeScript    |\n| ---------------------- | -------------- | ------------ | ------------- |\n| **Focus**              | AST validation | Code linting | Type checking |\n| **Extensible**         | ✅             | ✅           | ⚠️            |\n| **Lightweight**        | ✅             | ❌           | ❌            |\n| **Type-safe**          | ✅             | ⚠️           | ✅            |\n| **Security rules**     | ✅             | ⚠️           | ❌            |\n| **Runtime validation** | ✅             | ❌           | ❌            |\n\n## Defense-in-Depth Architecture\n\nAST Guard provides 4 layers of protection:\n\n```text\nLayer 1: AST Validation\n├── NoEvalRule - Blocks eval(), Function()\n├── NoGlobalAccessRule - Blocks window, globalThis, .constructor\n├── NoAsyncRule - Blocks async/await (optional)\n├── DisallowedIdentifierRule - Blocks dangerous identifiers\n└── ForbiddenLoopRule - Blocks/transforms loops\n\nLayer 2: AST Transformation\n├── Direct identifiers: console → __safe_console\n├── Computed access: obj['eval'] → obj['__safe_eval']\n└── Static string literals transformed\n\nLayer 3: Runtime Proxy Layer\n├── __safe_callTool() - Validates tool calls\n├── __safe_console() - Captures logs\n└── All proxied functions enforce security\n\nLayer 4: Worker Isolation\n├── Separate worker thread\n├── Sandboxed VM context\n└── No access to Node.js globals\n```\n\n### Known Limitations\n\nThese are inherent to **any** static analyzer (not vulnerabilities):\n\n| Limitation                   | Example              | Mitigation                        |\n| ---------------------------- | -------------------- | --------------------------------- |\n| Computed property access     | `obj['constructor']` | `Object.freeze(Object.prototype)` |\n| Runtime string construction  | `'con' + 'structor'` | VM isolation                      |\n| Destructuring property names | `{ constructor: c }` | Freeze prototypes                 |\n\n## Documentation\n\n| Document                                                     | Purpose                                         |\n| ------------------------------------------------------------ | ----------------------------------------------- |\n| [docs/AGENTSCRIPT.md](./docs/AGENTSCRIPT.md)                 | AgentScript language reference for AI agents    |\n| [docs/CVE-COVERAGE.md](./docs/CVE-COVERAGE.md)               | Detailed CVE analysis and protection mechanisms |\n| [docs/SECURITY-AUDIT.md](./docs/SECURITY-AUDIT.md)           | Full list of 67+ blocked attack vectors         |\n| [docs/STDLIB-SECURITY.md](./docs/STDLIB-SECURITY.md)         | Standard library security analysis              |\n| [docs/LOOP-TRANSFORMATION.md](./docs/LOOP-TRANSFORMATION.md) | Future loop transformation design               |\n\n## Roadmap\n\n- [x] Core validator architecture\n- [x] Built-in security rules\n- [x] Argument validation\n- [x] Unreachable code detection\n- [x] Comprehensive test suite (613 tests)\n- [x] CVE protection (vm2, isolated-vm, node-vm)\n- [ ] Loop transformation (design complete)\n- [ ] CLI tool\n- [ ] VS Code extension\n\n## Contributing\n\nContributions are welcome! Please see [CONTRIBUTING.md](../../CONTRIBUTING.md) for details.\n\n## License\n\nApache-2.0\n\n## Credits\n\nBuilt with:\n\n- [acorn](https://github.com/acornjs/acorn) - JavaScript parser\n- [acorn-walk](https://github.com/acornjs/acorn) - AST walker\n- Part of the [FrontMCP](https://github.com/agentfront/frontmcp) ecosystem\n","readmeFilename":"README.md"}