71 packages matching “TOCTOU”
@fengrru/txn-fs
v0.1.1 · 1 month ago
Transactional filesystem Git-style transactions with three-way merge, TOCTOU validation, and rollback
No known vulnerabilities
tar
v7.5.22 · 1 month ago
tar for node
No known vulnerabilities
pi-edit
v1.1.0 · 2 months ago
Claude Code-style editing discipline for Pi — read-before-write, TOCTOU protection, bash steering, post-edit diagnostics, schema-error recovery
No known vulnerabilities
@armalo/telemetry
v0.1.0 · 4 months ago
Continuous behavioral telemetry for AI agents. Drop in, stream tool calls + sessions to Armalo Trust Oracle. Closes the L4 TOCTOU gap.
No known vulnerabilities
@openclaw/fs-safe
v0.18.0 · 13 hours ago
Capability-style filesystem roots for Node.js apps that handle untrusted relative paths.
No known vulnerabilities
@deepseek-ai/dsh-fs-sandbox
v0.0.1-rc.1 · 1 month ago
Sandbox-enforcing implementation of the DeepSeek Harness filesystem seam: fences write/edit by the per-call sandbox mode (read-only denies mutation, workspace-write contains it to the workspace + temp roots) while reads pass through
No known vulnerabilities
ssrf-fetch
v0.1.0 · 2 months ago
A drop-in fetch() that blocks SSRF: refuses loopback/private/link-local/CGNAT targets and pins the connection to the validated IP to defeat DNS rebinding (TOCTOU).
No known vulnerabilities
@coderifts/agent-guard
v17.3.5 · 11 hours ago
Fail-closed guard for AI agent tool calls — preflight contract changes before they execute. Security core frozen (agent-guard-api v1.0); v1.1 adds client-side enforcement: receipt→envelope binding, decision↔action reconciliation, safe_for_agent + degraded
No known vulnerabilities
@solana/mpp
v0.7.0 · 2 months ago
Solana payment method for the MPP protocol
No known vulnerabilities
@cosmicdrift/kumiko-http
v0.295.0 · 1 day ago
SSRF-safe egress fetch for Kumiko: a single egress(policy) entry point that enforces external/internal/tenant-supplied host policy, DNS-rebinding-safe resolve-then-pin, and no external runtime dependencies.
No known vulnerabilities
ciphersweet-js
v2.0.6 · 3 years ago
Searchable encryption for Node.js projects
No known vulnerabilities
@lmzhen/dsh-evolution-core
v0.8.0 · 1 hour ago
Shared stores, prompts, signals and lifecycle logic for the dsh-evolution plugin family (community build)
No known vulnerabilities
@yeesy369/dsh-browser-playwright
v0.8.1 · 28 days ago
Playwright-backed Service Provider for the dsh-browser capability seam.
No known vulnerabilities
ssrf-guard
v1.0.0 · 29 days ago
SSRF protection: validate URLs, pin resolved IPs to the socket, eliminating the DNS-rebind window
No known vulnerabilities
cda-schematron-validator
v1.1.12 · 3 years ago
Fork of Eric Wadkins' javascript implementation of schematron testing for C-CDA XML documents. This includes bug fixes and some house keeping.
No known vulnerabilities
@blueprime/cross-store
v0.2.2 · 1 month ago
Validated cross-store (@Resolve) references between TimescaleDB and another database.
No known vulnerabilities
@unieai/uad-fs-sandbox
v0.1.21 · 22 days ago
Sandbox-enforcing implementation of the DeepSeek Harness filesystem seam: fences write/edit by the per-call sandbox mode (read-only denies mutation, workspace-write contains it to the workspace + temp roots) while reads pass through
No known vulnerabilities
@monotykamary/dsh-fs-sandbox
v0.1.9 · 20 days ago
Sandbox-enforcing implementation of the DeepSeek Harness filesystem seam: fences write/edit by the per-call sandbox mode (read-only denies mutation, workspace-write contains it to the workspace + temp roots) while reads pass through
No known vulnerabilities
@ictechgy/context-guard
v0.14.0 · 17 days ago
ContextGuard CLI helpers for keeping AI coding agent context focused and local-first.
No known vulnerabilities
opencode-bash-classifier
v0.5.1 · 1 month ago
Execution-boundary command safety classifier for OpenCode's native Bash tool: static per-segment review plus a tool-enhanced OpenAI-compatible model reviewer.
No known vulnerabilities