Directories
¶
| Path | Synopsis |
|---|---|
|
bench
|
|
|
egress/cmd/bench-egress
command
Command bench-egress is the entry point for pipelock's agent-egress overhead benchmark.
|
Command bench-egress is the entry point for pipelock's agent-egress overhead benchmark. |
|
egress/harness
Package harness implements the egress-overhead benchmark harness.
|
Package harness implements the egress-overhead benchmark harness. |
|
egress/mocks/httpecho
Package httpecho is a deterministic HTTP mock server used by the egress benchmark harness.
|
Package httpecho is a deterministic HTTP mock server used by the egress benchmark harness. |
|
egress/mocks/mcpstdio
command
Command mcpstdio is a deterministic MCP stdio server used by the egress benchmark.
|
Command mcpstdio is a deterministic MCP stdio server used by the egress benchmark. |
|
egress/mocks/sse
Package sse is a deterministic Server-Sent Events mock used by the egress benchmark.
|
Package sse is a deterministic Server-Sent Events mock used by the egress benchmark. |
|
egress/mocks/toolchain
Package toolchain is a deterministic LLM-shape mock for benchmarking tool-use sequences.
|
Package toolchain is a deterministic LLM-shape mock for benchmarking tool-use sequences. |
|
egress/mocks/wsfeed
Package wsfeed is a deterministic WebSocket mock used by the egress benchmark.
|
Package wsfeed is a deterministic WebSocket mock used by the egress benchmark. |
|
cmd
|
|
|
pipelock
command
Package main is the entry point for the Pipelock CLI.
|
Package main is the entry point for the Pipelock CLI. |
|
pipelock-playground-broker
command
Package main is the entry point for pipelock-playground-broker, the public playground front door that leases one private per-visitor VM and reverse proxies the /api/live/* session API to it.
|
Package main is the entry point for pipelock-playground-broker, the public playground front door that leases one private per-visitor VM and reverse proxies the /api/live/* session API to it. |
|
pipelock-playground-demo
command
Package main is the entry point for pipelock-playground-demo, a local demonstration binary that drives a deterministic toy agent through a real Pipelock proxy, captures signed decision receipts into an evidence JSONL, and assembles them into an offline-verifiable Audit Packet.
|
Package main is the entry point for pipelock-playground-demo, a local demonstration binary that drives a deterministic toy agent through a real Pipelock proxy, captures signed decision receipts into an evidence JSONL, and assembles them into an offline-verifiable Audit Packet. |
|
pipelock-playground-live
command
Package main is the entry point for pipelock-playground-live, the gated live-chat playground server.
|
Package main is the entry point for pipelock-playground-live, the gated live-chat playground server. |
|
pipelock-playground-llm-agent
command
Command pipelock-playground-llm-agent runs the live playground's model-backed agent as a standalone subprocess (never in-process with the server, because a jailbroken model can be driven to arbitrary actions).
|
Command pipelock-playground-llm-agent runs the live playground's model-backed agent as a standalone subprocess (never in-process with the server, because a jailbroken model can be driven to arbitrary actions). |
|
pipelock-playground-loadtest
command
Package main is a stdlib-only load-test harness for the playground broker's public /api/live/* flow.
|
Package main is a stdlib-only load-test harness for the playground broker's public /api/live/* flow. |
|
pipelock-playground-toyagent
command
Package main is the entry point for pipelock-playground-toyagent, a deterministic scripted agent used in the Pipelock Playground live demo.
|
Package main is the entry point for pipelock-playground-toyagent, a deterministic scripted agent used in the Pipelock Playground live demo. |
|
pipelock-playground-webtool
command
Package main is the entry point for pipelock-playground-webtool, a minimal HTTP utility used by pipelock-playground-toyagent to make requests that travel through the Pipelock proxy.
|
Package main is the entry point for pipelock-playground-webtool, a minimal HTTP utility used by pipelock-playground-toyagent to make requests that travel through the Pipelock proxy. |
|
pipelock-release-images
command
pipelock-release-images writes the exact container image digests that belong to one Pipelock release.
|
pipelock-release-images writes the exact container image digests that belong to one Pipelock release. |
|
pipelock-release-manifest
command
pipelock-release-manifest generates release.json for "pipelock update" and signs an existing manifest in offline mode.
|
pipelock-release-manifest generates release.json for "pipelock update" and signs an existing manifest in offline mode. |
|
pipelock-replay-capture
command
Package main is the entry point for pipelock-replay-capture, the capture rig for the Playground "Replay Audit Packet gallery".
|
Package main is the entry point for pipelock-replay-capture, the capture rig for the Playground "Replay Audit Packet gallery". |
|
pipelock-verifier
command
Package main is the entry point for pipelock-verifier, a self-contained binary that verifies Pipelock receipts, receipt chains, and Audit Packets.
|
Package main is the entry point for pipelock-verifier, a self-contained binary that verifies Pipelock receipts, receipt chains, and Audit Packets. |
|
pipelock-verifier-wasm
command
|
|
|
internal
|
|
|
aarp
Package aarp implements the Agent Action Receipt Profile (AARP) v0.1 assurance envelope: a separate, independently-signed appraisal artifact that sits alongside a shipped pipelock receipt and reports exactly what a verifier could cryptographically confirm versus what the producer merely claimed.
|
Package aarp implements the Agent Action Receipt Profile (AARP) v0.1 assurance envelope: a separate, independently-signed appraisal artifact that sits alongside a shipped pipelock receipt and reports exactly what a verifier could cryptographically confirm versus what the producer merely claimed. |
|
abom
Package abom generates CycloneDX 1.6 runtime Agent Bill of Materials with declared vs observed views and confidence scoring.
|
Package abom generates CycloneDX 1.6 runtime Agent Bill of Materials with declared vs observed views and confidence scoring. |
|
addressprotect
Package addressprotect detects crypto address poisoning attacks.
|
Package addressprotect detects crypto address poisoning attacks. |
|
ael
Package ael emits native Agent Evidence Levels v0.1 artifacts.
|
Package ael emits native Agent Evidence Levels v0.1 artifacts. |
|
anchor
Package anchor records and verifies external receipt-chain checkpoints.
|
Package anchor records and verifies external receipt-chain checkpoints. |
|
atomicfile
Package atomicfile provides atomic file write operations using temp-file-then-rename to prevent partial writes on crash.
|
Package atomicfile provides atomic file write operations using temp-file-then-rename to prevent partial writes on crash. |
|
audit
Package audit provides structured JSON audit logging for all Pipelock events.
|
Package audit provides structured JSON audit logging for all Pipelock events. |
|
authority
Package authority defines the provider-neutral boundary for verifying an externally issued action authorization at Pipelock's forwarding gates.
|
Package authority defines the provider-neutral boundary for verifying an externally issued action authorization at Pipelock's forwarding gates. |
|
blockreason
Package blockreason emits the X-Pipelock-Block-Reason header set on every pipelock block path.
|
Package blockreason emits the X-Pipelock-Block-Reason header set on every pipelock block path. |
|
capabilitymanifest
Package capabilitymanifest validates the public capability manifest and renders the generated contributor-guide section from it.
|
Package capabilitymanifest validates the public capability manifest and renders the generated contributor-guide section from it. |
|
capabilitymanifest/cmd/generate
command
|
|
|
capture
Package capture defines the types and interfaces used by the policy capture-and-replay system.
|
Package capture defines the types and interfaces used by the policy capture-and-replay system. |
|
cli
Package cli implements the Pipelock command-line interface using cobra.
|
Package cli implements the Pipelock command-line interface using cobra. |
|
cli/contain
Package contain implements the `pipelock contain` family of subcommands for workstation-tier containment.
|
Package contain implements the `pipelock contain` family of subcommands for workstation-tier containment. |
|
cli/envelope
Package envelope implements operator CLI helpers for mediation envelopes.
|
Package envelope implements operator CLI helpers for mediation envelopes. |
|
cli/evidence
Package evidence implements the free single-agent evidence viewer CLI command.
|
Package evidence implements the free single-agent evidence viewer CLI command. |
|
cli/guard
Package guard implements the Guard command plus read-only declaration and compiled-floor inspection.
|
Package guard implements the Guard command plus read-only declaration and compiled-floor inspection. |
|
cli/hermes
Package hermes implements the `pipelock hermes` subcommand tree, which manages pipelock's integration with the Hermes Agent (Nous Research) plugin system.
|
Package hermes implements the `pipelock hermes` subcommand tree, which manages pipelock's integration with the Hermes Agent (Nous Research) plugin system. |
|
cli/keys
Package keys implements the `pipelock keys` operator CLI: a unified view of every signing-key purpose Pipelock recognises, where each key is expected to come from, whether it is present and readable by the calling user, and whether it parses as the expected key type.
|
Package keys implements the `pipelock keys` operator CLI: a unified view of every signing-key purpose Pipelock recognises, where each key is expected to come from, whether it is present and readable by the calling user, and whether it parses as the expected key type. |
|
cli/learn
Package learn provides the `pipelock learn` command tree for the contract-compile observation pipeline.
|
Package learn provides the `pipelock learn` command tree for the contract-compile observation pipeline. |
|
cli/policy
Package policy implements the "pipelock policy" command group, which provides subcommands for capturing live proxy verdicts to disk and replaying them against a candidate config to produce a diff report.
|
Package policy implements the "pipelock policy" command group, which provides subcommands for capturing live proxy verdicts to disk and replaying them against a candidate config to produce a diff report. |
|
cli/scan
Package scan implements the `pipelock scan` command: it inspects files for invisible-Unicode and bidi-control injection (the supply-chain vector that hides instructions in agent-context files).
|
Package scan implements the `pipelock scan` command: it inspects files for invisible-Unicode and bidi-control injection (the supply-chain vector that hides instructions in agent-context files). |
|
cli/selfupdate
Package selfupdate implements the "pipelock update" command: a fail-closed self-updater that fetches a release archive from GitHub, verifies it against the published checksums and the native Ed25519 release manifest, optionally verifies the legacy cosign keyless signature when cosign is available, then atomically replaces the running binary.
|
Package selfupdate implements the "pipelock update" command: a fail-closed self-updater that fetches a release archive from GitHub, verifies it against the published checksums and the native Ed25519 release manifest, optionally verifies the legacy cosign keyless signature when cosign is available, then atomically replaces the running binary. |
|
cli/session
Package session implements the `pipelock session` operator CLI for inspecting and recovering airlocked sessions.
|
Package session implements the `pipelock session` operator CLI for inspecting and recovering airlocked sessions. |
|
cli/setup
Package setup implements init flows.
|
Package setup implements init flows. |
|
cli/support
Package support implements the `pipelock support bundle` command, which collects secret-redacted diagnostics for issue filing.
|
Package support implements the `pipelock support bundle` command, which collects secret-redacted diagnostics for issue filing. |
|
cliutil
Package cliutil provides shared helpers used across CLI subpackages.
|
Package cliutil provides shared helpers used across CLI subpackages. |
|
commitmentkey
Package commitmentkey owns the symmetric keys used to open private evidence commitments.
|
Package commitmentkey owns the symmetric keys used to open private evidence commitments. |
|
config
Package config handles loading, validating, and defaulting Pipelock configuration.
|
Package config handles loading, validating, and defaulting Pipelock configuration. |
|
contract
Package contract defines the typed schemas, canonicalization rules, and verification primitives for v2.4 learn-and-lock policy contracts.
|
Package contract defines the typed schemas, canonicalization rules, and verification primitives for v2.4 learn-and-lock policy contracts. |
|
contract/activation
Package activation contains contract promotion and rollback policy helpers.
|
Package activation contains contract promotion and rollback policy helpers. |
|
contract/inference
Package inference implements the contract-compile inference engine: Wilson lower-bound confidence, conditional opportunity denominators, exposure-floor gates, and numeric-budget statistics.
|
Package inference implements the contract-compile inference engine: Wilson lower-bound confidence, conditional opportunity denominators, exposure-floor gates, and numeric-budget statistics. |
|
contract/inference/aggregate
Package aggregate turns capture entries into deterministic inference inputs.
|
Package aggregate turns capture entries into deterministic inference inputs. |
|
contract/inference/compile
Package compile orchestrates recorder ingest, aggregation, inference, and signed artifact emission for candidate contracts.
|
Package compile orchestrates recorder ingest, aggregation, inference, and signed artifact emission for candidate contracts. |
|
contract/inference/emit
Package emit serializes compiled contracts into deterministic signed transport artifacts.
|
Package emit serializes compiled contracts into deterministic signed transport artifacts. |
|
contract/inference/ingest
Package ingest streams recorder JSONL into typed inference inputs while verifying the recorder hash chain incrementally.
|
Package ingest streams recorder JSONL into typed inference inputs while verifying the recorder hash chain incrementally. |
|
contract/inference/normalize
Package normalize implements the path-normalization layer of the contract-compile inference engine: frequency-weighted entropy bucketing, the 5-gate collapse decision, the reserved-segment blocklist, and per-host cardinality capping with tail-coverage.
|
Package normalize implements the path-normalization layer of the contract-compile inference engine: frequency-weighted entropy bucketing, the 5-gate collapse decision, the reserved-segment blocklist, and per-host cardinality capping with tail-coverage. |
|
contract/privacy
Package privacy enforces the learn-and-lock data-class taxonomy on observation events before they reach the recorder.
|
Package privacy enforces the learn-and-lock data-class taxonomy on observation events before they reach the recorder. |
|
contract/proxydecision
Package proxydecision emits signed EvidenceReceipt v2 proxy_decision records for live proxy enforcement decisions, alongside the legacy v1 ActionReceipt.
|
Package proxydecision emits signed EvidenceReceipt v2 proxy_decision records for live proxy enforcement decisions, alongside the legacy v1 ActionReceipt. |
|
contract/receipt
Package receipt defines the EvidenceReceipt v2 envelope, the typed payload structs, and the payload-kind → validator dispatch registry.
|
Package receipt defines the EvidenceReceipt v2 envelope, the typed payload structs, and the payload-kind → validator dispatch registry. |
|
contract/runtime
Package runtime resolves active learn-and-lock contracts for live sessions and evaluates contract-aware decisions without coupling the proxy runtime to the contract store.
|
Package runtime resolves active learn-and-lock contracts for live sessions and evaluates contract-aware decisions without coupling the proxy runtime to the contract store. |
|
contract/shadow
Package shadow aggregates contract shadow-evaluation deltas and emits signed EvidenceReceipt v2 shadow_delta records into the recorder chain.
|
Package shadow aggregates contract shadow-evaluation deltas and emits signed EvidenceReceipt v2 shadow_delta records into the recorder chain. |
|
contract/store
Package store loads and persists signed active contract manifests.
|
Package store loads and persists signed active contract manifests. |
|
coveragecert
Package coveragecert defines the coverage certificate format (sign and verify) for bounded coverage attestation over a time window.
|
Package coveragecert defines the coverage certificate format (sign and verify) for bounded coverage attestation over a time window. |
|
coveragecertverify
Package coveragecertverify contains the shared CLI verification flow for offline coverage certificates.
|
Package coveragecertverify contains the shared CLI verification flow for offline coverage certificates. |
|
datalabel
Package datalabel defines the MCP receipt data-class labels derived from internal scanner findings.
|
Package datalabel defines the MCP receipt data-class labels derived from internal scanner findings. |
|
decide
Package decide implements a shared decision engine for evaluating agent actions (shell commands, MCP tool calls, file reads) against pipelock's scanning pipeline.
|
Package decide implements a shared decision engine for evaluating agent actions (shell commands, MCP tool calls, file reads) against pipelock's scanning pipeline. |
|
destination
Package destination provides a transport-neutral representation of a network destination and the verdict machinery that decides whether it may be reached.
|
Package destination provides a transport-neutral representation of a network destination and the verdict machinery that decides whether it may be reached. |
|
edition
Package edition defines the multi-agent extension point for pipelock.
|
Package edition defines the multi-agent extension point for pipelock. |
|
emitformat
Package emitformat defines shared event export wire formats.
|
Package emitformat defines shared event export wire formats. |
|
envelope
Package envelope defines the Pipelock mediation envelope: the compact per-request metadata record that travels with every proxied request as an RFC 8941 Structured Fields Dictionary in the Pipelock-Mediation HTTP header, and as a map under the com.pipelock/mediation key in MCP _meta.
|
Package envelope defines the Pipelock mediation envelope: the compact per-request metadata record that travels with every proxied request as an RFC 8941 Structured Fields Dictionary in the Pipelock-Mediation HTTP header, and as a map under the com.pipelock/mediation key in MCP _meta. |
|
evidence/cmd/limitsdoc
command
|
|
|
evidence/completeness
Package completeness analyzes signed receipt chains for bounded lifecycle evidence.
|
Package completeness analyzes signed receipt chains for bounded lifecycle evidence. |
|
evidence/display
Package display builds human-facing representations of evidence strings.
|
Package display builds human-facing representations of evidence strings. |
|
evidencename
Package evidencename parses recorder evidence shard filenames.
|
Package evidencename parses recorder evidence shard filenames. |
|
extract
Package extract provides shared text extraction utilities used by both the HTTP proxy body scanner and the MCP input scanner.
|
Package extract provides shared text extraction utilities used by both the HTTP proxy body scanner and the MCP input scanner. |
|
filescan
Package filescan detects invisible-Unicode and bidi-control characters embedded in files.
|
Package filescan detects invisible-Unicode and bidi-control characters embedded in files. |
|
fleetreceipt
Package fleetreceipt verifies Fleet Receipt Reports: DSSE envelopes wrapping in-toto Statement v1 payloads with Pipelock's fleet-receipt/v1 predicate.
|
Package fleetreceipt verifies Fleet Receipt Reports: DSSE envelopes wrapping in-toto Statement v1 payloads with Pipelock's fleet-receipt/v1 predicate. |
|
gitprotect
Package gitprotect provides git-aware security features for Pipelock, including pre-push secret scanning and branch validation.
|
Package gitprotect provides git-aware security features for Pipelock, including pre-push secret scanning and branch validation. |
|
guard
Package guard turns a validated guard manifest into an enforced filesystem restriction.
|
Package guard turns a validated guard manifest into an enforced filesystem restriction. |
|
health
Package health provides a wedge-detection watchdog for pipelock.
|
Package health provides a wedge-detection watchdog for pipelock. |
|
hitl
Package hitl provides human-in-the-loop terminal approval for pipelock.
|
Package hitl provides human-in-the-loop terminal approval for pipelock. |
|
identitykey
Package identitykey centralizes stable per-actor key construction for stateful proxy detectors.
|
Package identitykey centralizes stable per-actor key construction for stateful proxy detectors. |
|
integrity
Package integrity provides file integrity monitoring for agent workspaces.
|
Package integrity provides file integrity monitoring for agent workspaces. |
|
jcs
Package jcs implements RFC 8785 JSON Canonicalization Scheme (JCS) exactly, using only the standard library.
|
Package jcs implements RFC 8785 JSON Canonicalization Scheme (JCS) exactly, using only the standard library. |
|
jsonscan
Package jsonscan provides a streaming duplicate-key check used on the receipt and flight-recorder verify paths.
|
Package jsonscan provides a streaming duplicate-key check used on the receipt and flight-recorder verify paths. |
|
killswitch
Package killswitch implements an emergency deny-all controller for Pipelock.
|
Package killswitch implements an emergency deny-all controller for Pipelock. |
|
license
Package license provides Ed25519-signed license tokens for gating premium features (multi-agent profiles).
|
Package license provides Ed25519-signed license tokens for gating premium features (multi-agent profiles). |
|
liveproof
Package liveproof holds end-to-end proofs that build and drive the shipped pipelock binary the way a customer does.
|
Package liveproof holds end-to-end proofs that build and drive the shipped pipelock binary the way a customer does. |
|
manifest
Package manifest provides the unified session manifest substrate used by evidence, replay, and attestation features.
|
Package manifest provides the unified session manifest substrate used by evidence, replay, and attestation features. |
|
mcp
Package mcp provides scanning of MCP (Model Context Protocol) JSON-RPC 2.0 responses for prompt injection and inbound generic credentials.
|
Package mcp provides scanning of MCP (Model Context Protocol) JSON-RPC 2.0 responses for prompt injection and inbound generic credentials. |
|
mcp/a2amethods
Package a2amethods is the shared source of truth for A2A JSON-RPC method names used by request classification and A2A session-binding inventory.
|
Package a2amethods is the shared source of truth for A2A JSON-RPC method names used by request classification and A2A session-binding inventory. |
|
mcp/chains
Package chains implements MCP tool call chain pattern detection.
|
Package chains implements MCP tool call chain pattern detection. |
|
mcp/integrity
Package integrity provides binary hash verification for MCP subprocess servers.
|
Package integrity provides binary hash verification for MCP subprocess servers. |
|
mcp/jsonrpc
Package jsonrpc provides shared JSON-RPC 2.0 types used across the mcp sub-packages.
|
Package jsonrpc provides shared JSON-RPC 2.0 types used across the mcp sub-packages. |
|
mcp/policy
Package policy provides MCP tool call policy rules for pre-execution checking.
|
Package policy provides MCP tool call policy rules for pre-execution checking. |
|
mcp/provenance
Package provenance provides cryptographic attestation generation and verification for MCP tool definitions.
|
Package provenance provides cryptographic attestation generation and verification for MCP tool definitions. |
|
mcp/tools
Package tools provides MCP tool description scanning for poisoning detection, rug-pull (drift) detection, and session binding (tool inventory validation).
|
Package tools provides MCP tool description scanning for poisoning detection, rug-pull (drift) detection, and session binding (tool inventory validation). |
|
mcp/transport
Package transport provides message framing for MCP JSON-RPC 2.0 transports.
|
Package transport provides message framing for MCP JSON-RPC 2.0 transports. |
|
mcpwrap
Package mcpwrap rewrites MCP server declarations so that every tool call, response, and description routes through `pipelock mcp proxy` for bidirectional scanning.
|
Package mcpwrap rewrites MCP server declarations so that every tool call, response, and description routes through `pipelock mcp proxy` for bidirectional scanning. |
|
media
Package media implements surgical metadata removal for image responses flowing through pipelock.
|
Package media implements surgical metadata removal for image responses flowing through pipelock. |
|
metrics
Package metrics provides Prometheus instrumentation and a JSON stats endpoint for the Pipelock fetch proxy.
|
Package metrics provides Prometheus instrumentation and a JSON stats endpoint for the Pipelock fetch proxy. |
|
normalize
Package normalize provides Unicode normalization pipelines for security scanning.
|
Package normalize provides Unicode normalization pipelines for security scanning. |
|
playground/broker
Package broker is the always-on front door for the public playground.
|
Package broker is the always-on front door for the public playground. |
|
playground/livechat
Package livechat holds the transport-agnostic access and abuse controls for the public "live chat" playground: an invite-code gate, fail-closed safety limits (rate, concurrency, time, size), and the HTTP/SSE server that wires them to a contained live run.
|
Package livechat holds the transport-agnostic access and abuse controls for the public "live chat" playground: an invite-code gate, fail-closed safety limits (rate, concurrency, time, size), and the HTTP/SSE server that wires them to a contained live run. |
|
playground/llmagent
Package llmagent runs a real model-backed agent for the playground live demo: it calls a chat-completions endpoint, executes the tool calls the model asks for, feeds the results back, and narrates each step.
|
Package llmagent runs a real model-backed agent for the playground live demo: it calls a chat-completions endpoint, executes the tool calls the model asks for, feeds the results back, and narrates each step. |
|
posture
Package posture emits signed posture capsules for the current pipelock state.
|
Package posture emits signed posture capsules for the current pipelock state. |
|
posturebinding
Package posturebinding derives receipt session_open binding fields from a signed posture proof artifact.
|
Package posturebinding derives receipt session_open binding fields from a signed posture proof artifact. |
|
processexec
Package processexec centralizes intentional process replacement after a caller has resolved and validated the executable and arguments.
|
Package processexec centralizes intentional process replacement after a caller has resolved and validated the executable and arguments. |
|
projectscan
Package projectscan implements project directory scanning for the pipelock audit command.
|
Package projectscan implements project directory scanning for the pipelock audit command. |
|
proxy
Package proxy implements the Pipelock fetch proxy HTTP server.
|
Package proxy implements the Pipelock fetch proxy HTTP server. |
|
proxy/baseline
Package baseline implements Profile-then-Lock behavioral baselines for agent sessions.
|
Package baseline implements Profile-then-Lock behavioral baselines for agent sessions. |
|
receipt
Package receipt implements typed action records and self-signed receipts for every proxy decision.
|
Package receipt implements typed action records and self-signed receipts for every proxy decision. |
|
recorder
Package recorder provides a hash-chained, tamper-evident, DLP-redacted evidence log with signed checkpoints and optional encrypted raw escrow.
|
Package recorder provides a hash-chained, tamper-evident, DLP-redacted evidence log with signed checkpoints and optional encrypted raw escrow. |
|
redact
Package redact implements class-preserving, irreversible secret redaction for pipelock request bodies bound for upstream LLM providers.
|
Package redact implements class-preserving, irreversible secret redaction for pipelock request bodies bound for upstream LLM providers. |
|
release
Package release verifies Pipelock release manifests with the embedded Ed25519 release keyring.
|
Package release verifies Pipelock release manifests with the embedded Ed25519 release keyring. |
|
replaycapture
Package replaycapture builds public-safe, signed Audit Packets from controlled synthetic attack scenarios driven through a real Pipelock proxy.
|
Package replaycapture builds public-safe, signed Audit Packets from controlled synthetic attack scenarios driven through a real Pipelock proxy. |
|
report
Package report generates HTML and JSON audit reports from JSONL event logs.
|
Package report generates HTML and JSON audit reports from JSONL event logs. |
|
report/attestation
Package attestation builds signed evidence objects for assess output.
|
Package attestation builds signed evidence objects for assess output. |
|
report/compliance
Package compliance provides structured coverage mappings between Pipelock capabilities and external security frameworks.
|
Package compliance provides structured coverage mappings between Pipelock capabilities and external security frameworks. |
|
reqpolicy
Package reqpolicy implements Pipelock's request_policy layer: explicit, allow-by-default deny/warn safety rails on outbound HTTP API operations.
|
Package reqpolicy implements Pipelock's request_policy layer: explicit, allow-by-default deny/warn safety rails on outbound HTTP API operations. |
|
sandbox
Package sandbox implements unprivileged process containment using Linux kernel primitives: Landlock (filesystem), network namespaces (network isolation), and seccomp (syscall restriction).
|
Package sandbox implements unprivileged process containment using Linux kernel primitives: Landlock (filesystem), network namespaces (network isolation), and seccomp (syscall restriction). |
|
sarif
Package sarif generates SARIF 2.1.0 output for GitHub Code Scanning.
|
Package sarif generates SARIF 2.1.0 output for GitHub Code Scanning. |
|
scanner
Package scanner provides URL scanning for the Pipelock fetch proxy.
|
Package scanner provides URL scanning for the Pipelock fetch proxy. |
|
secperm
Package secperm centralizes the cross-platform decision of whether a file's permission bits are security-meaningful and, if so, whether they are too permissive for a secret-bearing file or directory.
|
Package secperm centralizes the cross-platform decision of whether a file's permission bits are security-meaningful and, if so, whether they are too permissive for a secret-bearing file or directory. |
|
securefile
Package securefile provides bounded, race-resistant reads for local security material such as bearer tokens, private keys, and certificate bundles.
|
Package securefile provides bounded, race-resistant reads for local security material such as bearer tokens, private keys, and certificate bundles. |
|
sentry
Package plsentry provides opt-in Sentry error reporting with event minimization.
|
Package plsentry provides opt-in Sentry error reporting with event minimization. |
|
session
Package session provides shared session types for adaptive enforcement.
|
Package session provides shared session types for adaptive enforcement. |
|
shield
Package shield implements inline HTML/JS rewriting that strips fingerprinting, extension probing, telemetry beacons, and agent traps from response bodies before the browser renders them.
|
Package shield implements inline HTML/JS rewriting that strips fingerprinting, extension probing, telemetry beacons, and agent traps from response bodies before the browser renders them. |
|
signing
Package signing provides Ed25519 key generation, file signing, and signature verification for securing inter-agent communication.
|
Package signing provides Ed25519 key generation, file signing, and signature verification for securing inter-agent communication. |
|
signingflag
Package signingflag provides shared parsing for --trusted-signer CLI flag values.
|
Package signingflag provides shared parsing for --trusted-signer CLI flag values. |
|
skillscan
Package skillscan inventories local agent skill files and flags drift, direct source-to-sink transfers, and bounded advisory co-occurrences.
|
Package skillscan inventories local agent skill files and flags drift, direct source-to-sink transfers, and bounded advisory co-occurrences. |
|
svid
Package svid is a self-contained, vendor-neutral substrate for validating X.509-SVIDs offline against a pinned history of trust bundles.
|
Package svid is a self-contained, vendor-neutral substrate for validating X.509-SVIDs offline against a pinned history of trust bundles. |
|
svidsidecar
Package svidsidecar defines the on-disk --svid sidecar schema shared by the pipelock-verifier CLI and the AARP conformance corpus, plus the parser that turns a sidecar's verifier-pinned `verify` block into aarp.SVIDVerifyOptions.
|
Package svidsidecar defines the on-disk --svid sidecar schema shared by the pipelock-verifier CLI and the AARP conformance corpus, plus the parser that turns a sidecar's verifier-pinned `verify` block into aarp.SVIDVerifyOptions. |
|
testport
Package testport provides TOCTOU-tolerant TCP port selection for tests that must hand a concrete listen address to a server they then start.
|
Package testport provides TOCTOU-tolerant TCP port selection for tests that must hand a concrete listen address to a server they then start. |
|
testposture
Package testposture isolates a test binary from the host's containment posture state.
|
Package testposture isolates a test binary from the host's containment posture state. |
|
tlsfile
Package tlsfile loads X.509 certificate/private-key pairs through a bounded, permission-checked filesystem boundary before handing them to crypto/tls.
|
Package tlsfile loads X.509 certificate/private-key pairs through a bounded, permission-checked filesystem boundary before handing them to crypto/tls. |
|
release-verifier-fixture emits the signed v1 receipt used by the release installer gate.
|
release-verifier-fixture emits the signed v1 receipt used by the release installer gate. |
|
sdk
|
|
|
audit-packet
Package auditpacket holds the canonical Go binding for the Pipelock Audit Packet v0 schema published at sdk/audit-packet/v0.json.
|
Package auditpacket holds the canonical Go binding for the Pipelock Audit Packet v0 schema published at sdk/audit-packet/v0.json. |
|
conformance
Package conformance hosts golden receipt files and cross-implementation tests for the pipelock action receipt format.
|
Package conformance hosts golden receipt files and cross-implementation tests for the pipelock action receipt format. |
|
tests
|
|
|
ws-helper
command
ws-helper: WebSocket pen test helper for pipelock.
|
ws-helper: WebSocket pen test helper for pipelock. |
|
tools
|
|
|
gen-shadow-example
command
gen-shadow-example produces a reproducible verifiable-shadow-rollout example bundle.
|
gen-shadow-example produces a reproducible verifiable-shadow-rollout example bundle. |
Click to show internal directories.
Click to hide internal directories.