01Granular, mode-specific tool allowlists for AI agent interactions
02SafeBash Model Context Protocol (MCP) server with semantic command analysis
03Integrated OS sandbox support (bubblewrap/sandbox-exec) for enhanced isolation
04Robust 7-check security validation pipeline for shell command execution
05Prevention of dangerous download-execute chains and restricted file operations
061 GitHub stars