~ / rigs / sheeki03 / tirith

sheeki03/tirith

Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.

↗ GitHub ★ 2,750 AGPL-3.0 updated today project Claude CodeCursor
share on X
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
CONTEXT TAX · EVERY TURN
~2.5k tokens
Moderate · median rig: 2.3k · breakdown
GUARDRAILS
3/5
Blocks destructive commands · Pre-tool screening hook · No YOLO mode · details

Copy this rig

# review before running: this installs third-party code
$ claude mcp add tirith-gateway -- tirith gateway run --upstream-bin tirith --upstream-arg mcp-server --config ~/.config/tirith/gateway.yaml
$ npx degit sheeki03/tirith/.claude ./rig-tirith  # inspect, then merge into .claude/

MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.

$ claude mcp add tirith-gateway -- tirith gateway run --upstream-bin tirith --upstream-arg mcp-server --config ~/.config/tirith/gateway.yaml

Merge into .claude/settings.json (project) or ~/.claude/settings.json (user). Hook commands reference scripts in the source repo — copy those too.

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "TIRITH_BIN=\"${HOME}/.cargo/bin/tirith\" python3 \"${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/tirith-check.py\""
          }
        ]
      }
    ]
  }
}

MCP servers (1)

serversourceest. tokens
tirith · "tirith-gateway" binary 2.5k

Hooks (1)

eventmatcherruns
PreToolUseBashTIRITH_BIN="${HOME}/.cargo/bin/tirith" python3 "${CLAUDE_PROJECT_DIR:-.}/.claude/hooks/tirith-check.py"

Similar rigs

copied ✓