{"_id":"@yottameta/yotta-guardian","_rev":"6-cd9b3f4bcb799e29f085bd0919d14db3","name":"@yottameta/yotta-guardian","dist-tags":{"latest":"0.1.5"},"versions":{"0.1.0":{"name":"@yottameta/yotta-guardian","version":"0.1.0","keywords":["agent-skills","yotta-guardian"],"license":"MIT","_id":"@yottameta/yotta-guardian@0.1.0","maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"homepage":"https://github.com/YottaMeta/yotta-guardian#readme","bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"bin":{"yotta-guardian":"bin/install.js"},"dist":{"shasum":"0e37f103847440b6728014a48042c9adc577bae5","tarball":"https://registry.npmjs.org/@yottameta/yotta-guardian/-/yotta-guardian-0.1.0.tgz","fileCount":18,"integrity":"sha512-UsYnAJJH/52qqTbgRPeZ7ZAUq4oMNTwuE8dnH7ixkJgBwQy//kbM3UQgCVu2/fiTgvgC44y6RvRGd/PGDesRTA==","signatures":[{"sig":"MEUCIFsCdsNpMM3xIspgr0EZWv0C+4vOhColpEW9oDatBGxnAiEA+8VKgjvk/2bLCVbc40DB0FD+KKOF5lWskETymnw56Q8=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":336745},"gitHead":"9136209dd909f4f7515cc0613a521afd4150adfe","_npmUser":{"name":"yottameta","email":"43068183@qq.com"},"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"_npmVersion":"12.0.2","description":"元盾 —— 跨智能体的危险调用拦截护栏：确定性规则引擎 + 可插拔意图验证（不绑模型），拦截危险 exec/write/edit 等工具调用，提供审计日志。触发：代理要执行高风险命令、写敏感路径、改系统配置时。边界：默认只读检查，不自动放行危险操作；规则可配置。","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/yotta-guardian_0.1.0_1787756184850_0.0810469802143452","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@yottameta/yotta-guardian","version":"0.1.1","keywords":["agent-skills","yotta-guardian","security"],"license":"MIT","_id":"@yottameta/yotta-guardian@0.1.1","maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"homepage":"https://github.com/YottaMeta/yotta-guardian#readme","bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"bin":{"yotta-guardian":"bin/install.js"},"dist":{"shasum":"8fe22018988dd3c989a69c73c6e63ab68117df2f","tarball":"https://registry.npmjs.org/@yottameta/yotta-guardian/-/yotta-guardian-0.1.1.tgz","fileCount":16,"integrity":"sha512-WOFOgal6l6dmKV5kP9TYkC14xxaKw8aUHWa1MdQeIheanmkdVUsUJD3TjL8w53604yq38pAjtGBlmbhxNTusTQ==","signatures":[{"sig":"MEUCIBr++8KSD9VNvjodBY9cpdFST/rkv+3XyCfebPSc2qXoAiEAqn9c4oNcdALxRaWqKYX9Bg7Wmt0mhEH67Uiq+83kL6Q=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":282878},"gitHead":"089520320c1139222342f533cb2fbe169c9276bc","_npmUser":{"name":"yottameta","email":"43068183@qq.com"},"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"_npmVersion":"12.0.2","description":"Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/yotta-guardian_0.1.1_1787852214432_0.4888962485037538","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@yottameta/yotta-guardian","version":"0.1.2","keywords":["agent-skills","yotta-guardian","security"],"license":"MIT","_id":"@yottameta/yotta-guardian@0.1.2","maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"homepage":"https://github.com/YottaMeta/yotta-guardian#readme","bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"bin":{"yotta-guardian":"bin/install.js"},"dist":{"shasum":"f5d1fac99f79e0b0d8ac2bcf2737b09c0abc688c","tarball":"https://registry.npmjs.org/@yottameta/yotta-guardian/-/yotta-guardian-0.1.2.tgz","fileCount":16,"integrity":"sha512-XH6J4t8xumRlYomGgQyfT7WFpqCFqhxK8KSiGWg9tJDEJs50v8wif/01n5bOJASftcWLcRdUFUqLjyS/xc3uTw==","signatures":[{"sig":"MEUCIQD/FWwptSQvve2dMSS4/9fVsKFgBt3o5706vVmSsMJyjAIgbtNUBl8EKGTVmuRbkfolC07lBrWFAz6/ATiOXpposfA=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":280318},"gitHead":"94bb090088e5352d13fafff2f7663f6540cdb27e","_npmUser":{"name":"yottameta","email":"43068183@qq.com"},"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"_npmVersion":"12.0.2","description":"Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r","directories":{},"_nodeVersion":"22.23.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/yotta-guardian_0.1.2_1787976111710_0.5387674960258308","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@yottameta/yotta-guardian","version":"0.1.3","keywords":["agent-skills","yotta-guardian","security"],"license":"MIT","_id":"@yottameta/yotta-guardian@0.1.3","maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"homepage":"https://github.com/YottaMeta/yotta-guardian#readme","bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"bin":{"yotta-guardian":"bin/install.js"},"dist":{"shasum":"79fccfccf6466cd8c473d08f6ac30cd9e0b6b849","tarball":"https://registry.npmjs.org/@yottameta/yotta-guardian/-/yotta-guardian-0.1.3.tgz","fileCount":16,"integrity":"sha512-kwU2O/7CYP68r7PfLUQyDeulE4CAa+SmSRVuGqZOE61DKc24QwogDHqjq+NVvpqqecKIIHNRl4NS9MoTTQTfjw==","signatures":[{"sig":"MEUCIHhNBU/4MlWVNuRv35/rHD0YOH7oJLB31i6quQRhaPuSAiEAuHgeJPcbmx+Z9vEm7xfMJE9uCBY0A8oeT6XEQpzh7Vc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@yottameta%2fyotta-guardian@0.1.3","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":263320},"gitHead":"a52493f38284db0f708cba42930a764ca9e615ef","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:193f7abc-feaf-463f-8654-4181d07fb6f5"}},"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"_npmVersion":"11.19.0","description":"Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/yotta-guardian_0.1.3_1789290453780_0.9849947134146522","host":"s3://npm-registry-packages-npm-production"}},"0.1.4":{"name":"@yottameta/yotta-guardian","version":"0.1.4","keywords":["agent-skills","yotta-guardian","security"],"license":"MIT","_id":"@yottameta/yotta-guardian@0.1.4","maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"homepage":"https://github.com/YottaMeta/yotta-guardian#readme","bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"bin":{"yotta-guardian":"bin/install.js"},"dist":{"shasum":"78c07ee5711be04ac8cce27b1d5cf6745077ca79","tarball":"https://registry.npmjs.org/@yottameta/yotta-guardian/-/yotta-guardian-0.1.4.tgz","fileCount":16,"integrity":"sha512-1pNOe69+8M6+0QpRTqyKXkVdhqkfypEsM+3hVbpHpgQMcVqu6XQiIKuebT/PAKPAR18y75uQrF1p7jeUe1mnLw==","signatures":[{"sig":"MEUCIQCTebIDZWRLFcfaobh3na6qBvsFehWq6S3ofFS3cIWpQQIgJSrMCWfyvlU7VDZDkMM8y32Gq26PIRj9LhoQJOZ39Vg=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"sig":"MEYCIQCY6fxGzFrWPoEcjEg642qdIUHBbPuNnGM/PfQagI7engIhAInevpZP+q3RbLk7eqHuW0f+z3LioAS0FhoURB7uTUin","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@yottameta%2fyotta-guardian@0.1.4","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":263439},"gitHead":"064866e3ebe51bb000b9bef67db2d67fe136226f","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:193f7abc-feaf-463f-8654-4181d07fb6f5"}},"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"_npmVersion":"11.19.0","description":"Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r","directories":{},"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/yotta-guardian_0.1.4_1789809343814_0.7118813048765786","host":"s3://npm-registry-packages-npm-production"}},"0.1.5":{"_id":"@yottameta/yotta-guardian@0.1.5","bin":{"yotta-guardian":"bin/install.js"},"bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"dist":{"shasum":"656ccb286d066f915cefc2f11cefd9a5566dfb85","tarball":"https://registry.npmjs.org/@yottameta/yotta-guardian/-/yotta-guardian-0.1.5.tgz","fileCount":16,"integrity":"sha512-Vg61tbzqN5HHRE6/Dbg98bAyrfMXqfDHa7AV8POG2+C5m0RhhvKinPlu1D0n+oTJ4N6U+CHqxiiqrlDjBmPQEg==","signatures":[{"sig":"MEQCIDgsH+GTaJoU5fSdDjShCJIO8X74MxTfHbAyeMJ9LD7aAiAnFa0HZCuL7GuQaHUAEzx4qCdlBGxYv6rJPRBSprDnxQ==","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQC+5UbJ55ZwfBPOSzEV9EvzZ0X1gpcRpxeMZ57bD9c/6QIhALkZ/aFx2NINpgnSrGwjMjyikSL4KUP60EfJaEE5orsd"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@yottameta%2fyotta-guardian@0.1.5","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":269203},"name":"@yottameta/yotta-guardian","gitHead":"2c917c8f98a9a1d8ecdf3503f52fc887f440ec9e","license":"MIT","version":"0.1.5","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:193f7abc-feaf-463f-8654-4181d07fb6f5"}},"homepage":"https://github.com/YottaMeta/yotta-guardian#readme","keywords":["agent-skills","yotta-guardian","security"],"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"_npmVersion":"11.19.0","description":"Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r","directories":{},"maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"_nodeVersion":"24.20.0","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/yotta-guardian_0.1.5_1789833413796_0.06137669403790813"}}},"time":{"created":"2026-08-26T14:56:24.699Z","modified":"2026-09-19T15:56:54.219Z","0.1.0":"2026-08-26T14:56:25.047Z","0.1.1":"2026-08-27T17:36:54.580Z","0.1.2":"2026-08-29T04:01:51.849Z","0.1.3":"2026-09-13T09:07:33.934Z","0.1.4":"2026-09-19T09:15:43.949Z","0.1.5":"2026-09-19T15:56:53.907Z"},"bugs":{"url":"https://github.com/YottaMeta/yotta-guardian/issues"},"license":"MIT","homepage":"https://github.com/YottaMeta/yotta-guardian#readme","keywords":["agent-skills","yotta-guardian","security"],"repository":{"url":"git+https://github.com/YottaMeta/yotta-guardian.git","type":"git"},"description":"Yuandun (元盾) — cross-agent dangerous tool-call guardrail: a deterministic rule engine + pluggable intent verifier (model-agnostic) that evaluates exec/write/edit/read/run/shell calls and provides audit logs. Triggers when an agent is about to run a high-r","maintainers":[{"name":"yottameta","email":"43068183@qq.com"}],"readme":"<p align=\"center\"><b>Language</b>: <a href=\"./README.md\">English</a> · 中文</p>\n\n\n<p align=\"center\">\n  <img src=\"assets/banner.png\" alt=\"yotta-guardian banner\" width=\"100%\" />\n</p>\n\n<h1 align=\"center\">yotta-guardian · 元盾</h1>\n\n<p align=\"center\">YottaMeta 自有的工具调用拦截护栏：<b>确定性规则引擎 + 可插拔意图验证</b>，对 exec / write / edit / read / run / shell 工具调用做安全评估，输出 allow / deny + 命中规则 + 审计日志。适用于代理要执行高风险命令、写入系统敏感路径、或修改系统配置之前的确定性安全检查。</p>\n<p align=\"center\">检测到递归删除、磁盘格式化、提权、防火墙改动、反向 shell、下载即执行、写入系统核心文件等危险操作意图时自动激活——<b>不靠提示词兜底，按规则确定性判定</b>。</p>\n<p align=\"center\">纯 Python 3.8+ 标准库实现，零外部依赖；Windows + Linux + macOS 通用；默认只读评估、可配置放行、审计留痕。</p>\n\n<p align=\"center\">\n  <a href=\"LICENSE\"><img alt=\"License: MIT\" src=\"https://img.shields.io/badge/license-MIT-blue\" /></a>\n  <a href=\"https://agentskills.io/\"><img alt=\"Standard: agentskills.io\" src=\"https://img.shields.io/badge/standard-agentskills.io-orange\" /></a>\n  <a href=\"https://www.npmjs.com/package/@yottameta/yotta-guardian\"><img alt=\"npm package\" src=\"https://img.shields.io/npm/v/@yottameta/yotta-guardian\" /></a>\n  <a href=\"https://github.com/YottaMeta/yotta-guardian\"><img alt=\"GitHub stars\" src=\"https://img.shields.io/github/stars/YottaMeta/yotta-guardian\" /></a>\n  <a href=\"https://github.com/YottaMeta/yotta-guardian/commits/main\"><img alt=\"last commit\" src=\"https://img.shields.io/github/last-commit/YottaMeta/yotta-guardian\" /></a>\n  <a href=\"https://github.com/YottaMeta/yotta-guardian\"><img alt=\"PRs welcome\" src=\"https://img.shields.io/badge/PRs-welcome-brightgreen\" /></a>\n</p>\n\n## 这是什么\n\nAI 代理在自主执行时，一条递归删除、一次磁盘写入、一段下载即执行，就可能造成不可逆损失。元盾把这些危险动作做成确定性规则引擎：对每一次工具调用（exec / write / edit / read / run / shell）做结构化评估——命令文本、argv 级动词与目标分析、敏感路径、写入内容——给出 allow / deny 判定、命中规则与原因，并支持审计日志留痕。\n\n它不是某个平台的专属功能，而是一份与智能体无关的工具包：装进任何支持 Agent Skills 的智能体即可按需调用。默认只读评估，不自动执行也不放行危险操作；意图验证默认不调用任何模型，可通过协议外接任意验证器（如 LLM 网关）。\n\n## 核心价值\n\n- **确定性规则引擎**：文本模式（下载即执行 / 编码执行 / 反向 shell 等）+ argv 级动词/目标分析（rm / dd / mkfs / chmod / chown / 提权 / 防火墙 / 服务 / 持久化等）+ 敏感路径 + 写入内容，四层规则叠加判定。\n- **敏感路径守卫**：/etc/passwd、/etc/sudoers、SSH 授权文件、/boot、/dev 设备、Windows 系统目录与 hosts、注册表启动项等写入即拒。\n- **可插拔意图验证（不绑模型）**：默认零依赖；可启用内置本地启发式（--heuristic），也可通过 stdin/stdout JSON 协议外接任意意图验证器（--verifier / 配置文件）。\n- **三档策略**：default（拒绝 high+）/ strict（拒绝 medium+）/ loose（仅拒绝 critical），按场景取舍。\n- **审计留痕**：JSONL 审计日志 + audit 查询子命令，拒绝/放行全程可追溯。\n- **机器可读**：--json 输出纯净 JSON（含逐条判定、规则、退出码），--batch 批量预检，适合智能体在执行前 gate。\n\n## 核心优势\n\n| 优势 | 说明 |\n|---|---|\n| **零依赖** | Python 3.8+ 标准库，无 daemon / 无数据库 / 无外部扫描器；Windows + Linux + macOS 通用 |\n| **确定性** | 规则判定可复现、可解释，不依赖模型概率；意图验证默认关闭，需显式启用 |\n| **结构化** | 按工具类型（exec / write / edit / read）分别评估命令、路径与内容，不是简单字符串匹配 |\n| **可配置** | --allow / --allow-path / 自定义规则 JSON（policy / deny / allow / verifier） |\n| **可追溯** | 每次判定落 JSONL 审计日志，audit 子命令可按拒绝 / 工具 / 时间过滤 |\n| **生态分发** | GitHub + npm + ClawHub 三源同步发布；npx / git clone / Download ZIP / install.sh 四种安装方式 |\n\n## 功能体系\n\n| 能力 | 说明 |\n|---|---|\n| check | 评估一条或一批工具调用（--batch），文本 / JSON / Markdown 报告三种输出 |\n| audit | 查询审计日志（--tail / --denied / --since / --tool / --json） |\n| rules | 打印内置规则摘要 / 校验自定义规则文件 |\n| version | 打印版本 |\n\n## 快速使用\n\nWindows 用 python，Linux/macOS 用 python3。\n\n```bash\n# 检查一条 exec（0 = 允许）\npython3 scripts/yotta_guardian.py check exec --cmd \"git status\"\n\n# 检查危险命令（默认拒绝，退出码 3）\npython3 scripts/yotta_guardian.py check exec --cmd \"rm -rf /\"\n\n# 检查写操作（写入 /etc/passwd 被拒）\npython3 scripts/yotta_guardian.py check write --path /etc/passwd --content \"...\"\n\n# 批量预检（agent 在执行前把待执行调用列表交给护栏）\npython3 scripts/yotta_guardian.py check --batch calls.json --json\n\n# 审计\npython3 scripts/yotta_guardian.py check exec --cmd \"...\" --audit-log .yotta-guardian/audit.jsonl\npython3 scripts/yotta_guardian.py audit --file .yotta-guardian/audit.jsonl --tail 20\n```\n\n退出码语义（与元安 / 元审家族一致）：0 = 允许；1 = 允许但带警告（建议人工复核）；2 = 拒绝（high）；3 = 拒绝（critical）；4 = 用法错误 / 致命异常。\n\n## 安装\n\n以下四种方式任选，顺序即推荐优先级；技能文件一律从 **npm** 获取（GitHub 无代理较慢，npm 支持镜像）。\n\n### 方式一：npm 一行装（推荐）\n\n```text\n# 可选国内加速：npm config set registry https://registry.npmmirror.com\nnpx -y @yottameta/yotta-guardian --agent <智能体名称>      # 装到指定智能体默认用户级技能目录\nnpx -y @yottameta/yotta-guardian --dir <智能体的技能目录>  # 指到技能目录本身（如 ~/.codex/skills）\n```\n\n- `--agent <name>` 自动装到该智能体默认用户级目录；`--list` 可查看各智能体默认目录。\n- `--dir <路径>` 装到指定的技能目录；未收录的智能体用 `--dir` 指到它的技能目录。\n- npmmirror 未同步新包（404）：加 `--registry=https://registry.npmjs.org/`（国内需代理），或稍等镜像缓存。\n\n### 方式二：git clone（开发者 / 有 git 环境）\n\n```text\ngit clone https://github.com/YottaMeta/yotta-guardian.git <智能体的技能目录>/yotta-guardian\n```\n\n### 方式三：GitHub 下载压缩包（手动 / 无 git 环境）\n\n在 GitHub 仓库 `YottaMeta/yotta-guardian` 点 **Code → Download ZIP**，解压后把 `yotta-guardian` 文件夹放进智能体技能目录。\n\n### 方式四：install.sh（多智能体一键脚本）\n\n```text\nbash install.sh --agent <name>   # 装到指定智能体默认用户级目录\nbash install.sh --dir <path>     # 装到指定目录\nbash install.sh --list           # 列出智能体 -> 默认目录\n```\n\n> 方式一走 npm 源（npmmirror / npmjs），不依赖 GitHub；方式二 / 三走 GitHub，国内无代理可能失败。\n## 使用示例（AI 智能体）\n\n1. 将本仓库的 SKILL.md 接入任意 AI 智能体的技能/规则系统（见上方安装）。\n2. 在执行任何高风险工具调用前，先跑一次 check：\n   ```bash\n   python3 scripts/yotta_guardian.py check exec --cmd \"<待执行命令>\" --json\n   ```\n   退出码 2 / 3 时不要执行，向用户说明命中规则；确有授权再用 --allow / --allow-path / 自定义规则放行。\n3. 一次要执行多条时，用 --batch 批量预检：\n   ```bash\n   python3 scripts/yotta_guardian.py check --batch calls.json --json\n   ```\n4. 写敏感路径 / 修改系统配置前，用 write / edit 检查目标路径与内容。\n5. 高风险操作落审计日志，事后用 audit 查询。\n\n## 开发与校验\n\n- 测试：python scripts/test_yotta_guardian.py（60 项）\n- 基础校验：python tools/validate-skill.py yotta-guardian（在仓库根目录运行）\n- 规则说明：references/rules.md；策略与退出码：references/policies.md；意图验证器协议：references/intent-verifier.md\n\n## 许可证\n\nMIT © YottaMeta —— 详见 [LICENSE](./LICENSE)。\n\n## 致谢\n\n护栏/拦截方向参考开源社区 safe-guardian 类技能思路，实现为 YottaMeta 全新自有代码（详见 [NOTICE](./NOTICE)）。\n","readmeFilename":"README.zh-CN.md"}