VAIBot Guard — local policy enforcement + tamper-evident audit daemon for AI agent tool calls. The universal decision authority the codex/claudecode/openclaw plugins route through.
LPM treats this as warn-only first-party agent extension lifecycle risk. No unconsented install-time attack behavior was found. An explicit user `install` command can create a VAIBot-owned persistent local policy service that audits guarded actions and may transmit configured receipts.
Package source references child process execution.
scripts/vaibot-guard.mjsView on unpkg · L11A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/vaibot-guard.mjsView on unpkg · L10Source writes installer persistence such as shell profile or service configuration.
scripts/vaibot-guard.mjsView on unpkg · L10This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/vaibot-guard-service.mjsView on unpkgPackage source references child process execution.
scripts/vaibot-guard.mjsView on unpkg · L11A single source file combines environment access, network access, and code or shell execution; review context before blocking.
scripts/vaibot-guard.mjsView on unpkg · L10Source writes installer persistence such as shell profile or service configuration.
scripts/vaibot-guard.mjsView on unpkg · L10This package version adds a dangerous source file absent from the previous stored version; route for source-aware review.
scripts/vaibot-guard-service.mjsView on unpkg