Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
nah — a guard that blocks catastrophic agent actions | Kitploit
Tools/GitHubGitHub/manuelschipper/nah
Privilege EscalationContainer SecurityDynamic Analysis (Sandboxing)Code AnalysisConfiguration AuditingDevSecOpsCommand and ControlSecret DetectionThreat IntelligenceIncident ResponseAI Security
4642530vor 15h 17mVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen
GitHub
manuelschipper/nah

nah

a guard that blocks catastrophic agent actions

Repository anzeigenWebseite
Inhalt in der angeforderten Sprache nicht verfügbar. Englische Version wird angezeigt.

nah

expensive mistakes stop here
a guard that blocks catastrophic agent actions

nahguard.ai • what it blocks • how it compares • how it decides • install • extend • threat model

claude code · codex · cursor · pi · + 11 more

nah is a guard that sits in your coding agent's hook path and reads tool calls before they run. It blocks the calls it can prove are disasters and never approves anything: everything else goes to your runtime's normal permissions.

nah is just one Rust binary: a verdict is deterministic and needs no LLM. Extensions are just programs. Point your agent to nah's docs and ask it to build a custom nah guard.

It knows a disaster when it sees one.

47 guards, 29 on by default, covering seven classes of disaster: execution hijacks, secret theft, filesystem destruction, git disasters, infrastructure, storage, and backup teardown, package-registry operations, and host power and service-stop actions.

GuardBlocks
exec-remoteExecution of a payload visibly obtained from the network.
exec-decodedExecution reached from a visible decode stage.
exec-obfuscatedEncoded, pattern-selected, or unresolved execution.
exec-network-shellShells attached to a network connection, including netcat, socat, and shell redirection.
secrets-envReads of .env files and sensitive basenames, including contents from Git history, plus direct output of catalogued credential environment variables.
secrets-credentialsReads or writes of private-key and credential-store paths, including content reads from Git history; deleting or moving away private keys; metadata or value reads of the macOS keychain.
secrets-exfilA visible flow from a sensitive source to a network stage.
secrets-store-deleteRemaining reviewed secret-store deletion with recoverable or context-dependent semantics. Off by default.
secrets-store-destroyProven permanent secret-store destruction: Vault version/metadata/engine removal, AWS force and SSM deletion, Google whole-secret deletion, Azure purge, Doppler project/configuration deletion, and 1Password vault deletion.
secrets-store-readReviewed value reads across common secret-manager CLIs.
fs-system-treeDeletion, proven root-entry relocation, or recursive permission changes selecting the filesystem root or a system tree.
fs-homeDeletion or recursive permission changes selecting the home root.
fs-outside-workspace-deleteRecursive deletion outside the active project, except under reviewed temporary roots. Off by default.
fs-permission-weakenchmod modes that provably grant world-write or setuid/setgid permission. Off by default.
fs-project-rootConcrete Project-scoped recursive deletion or known recursive permission changes selecting the exact project root or its exact *, .*, or {*,.*} root-wide patterns. find -delete without an explicit start path has no modeled target.
fs-raw-deviceVisible writes to, and whole-device destruction of, raw storage devices, and the sysrq trigger.
fs-volume-destroyDefinite logical-volume, storage-pool, and live ZFS dataset destruction.
fs-forkbombStructurally recognized shell fork-bomb patterns.
fs-auth-identityModification or deletion of reviewed host authentication, identity, and privilege-policy files, including recursive deletion of their parent directories.
fs-shell-profileChanges to reviewed user shell profile paths. Off by default.
fs-startup-managementReviewed persistent systemctl, launchctl, and crontab management commands. Off by default.
fs-startup-persistenceChanges to reviewed service, schedule, login, autostart, and loader startup paths.
git-clean-forceAn effective forced Git clean selecting the project root.
git-force-pushGit force pushes without lease protection and leased force pushes explicitly targeting main or master.
git-hard-resetGit hard resets.
git-history-rewriteSelected unforced Git history rewrites, including rebases, filtering, recovery expiry, aggressive or pruning garbage collection, and leased force pushes, including explicit static refspecs targeting main or master. Off by default.
git-rewrite-forceHistory rewriting that explicitly bypasses safety or backup checks.
git-metadataDestructive writes or deletion selecting durable Git history metadata.
git-path-discardDefinite named-path checkout, restore, and same-path git show overwrites. Off by default.
git-protected-pushPushes whose explicit static refspec targets main or master. Bare pushes remain outside this guard. Off by default.
git-recovery-destroyClearing the full stash collection or immediate repository-wide destruction of Git recovery history.
git-ref-deleteReviewed local and remote ref, stash entry, worktree, and submodule worktree deletion. Off by default.
git-remote-repo-deleteExact GitHub and GitLab whole-repository deletion through their CLIs and REST routes.
git-remote-resource-deleteStatically targeted GitHub and GitLab hosted-resource deletion through reviewed CLI commands and REST routes. Off by default.
git-worktree-discardProject-wide checkout or restore, proven forced branch changes, and forced worktree removal or submodule deinitialization.
db-destroyDropping, truncating, flushing, resetting, or overwriting live database data, and deleting managed databases. Off by default.
infra-container-resetPodman commands that reset the complete local or selected runtime state.
infra-container-volume-deleteBroad unused-volume cleanup through reviewed Docker and Podman prune commands, and Compose down -v/rm -v volume removal. Off by default.
infra-iac-destroyFully visible Terraform, OpenTofu, and Pulumi whole-stack destruction. Off by default.
infra-k8s-deleteStatic namespace, reviewed cluster-resource, and bulk reviewed namespaced-resource deletion through kubectl. Off by default.
storage-backup-destroyComplete backup-repository or all-backup deletion through reviewed Borg, Restic, and Velero commands.
storage-recursive-deleteBroad remote deletion and destination-deleting synchronization through reviewed cloud and sync CLIs. Off by default.
storage-snapshot-deleteReviewed snapshot, archive, volume, and retention deletion. Off by default.
registry-publishReviewed package publication commands. Off by default.
registry-unpublishReviewed package unpublish, irreversible RubyGems yank, and published-name owner changes.
sys-powerFully visible local host shutdown, reboot, halt, and suspend actions.
sys-service-stopReviewed service shutdown, target isolation, Podman stop-all or kill-all, and docker stop or docker kill of every listed container. Off by default.

Run nah docs guards to see the full built-in catalog, with each guard's exact scope and three tested examples, plus current custom guard status.

How it compares against similar tools

nah is the most complete coding agent guard, and stacks well with Auto modes

Tool herunterladen