{"repo":"sheeki03/tirith","free":true,"listed":false,"github":"https://github.com/sheeki03/tirith","clone":"git clone https://github.com/sheeki03/tirith.git","description":"Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-to-shell, ANSI injection, obfuscated payloads, data exfiltration, and malicious AI skills/configs before they execute.","language":"Rust","stars":2666,"topics":["cli","devtools","homograph-attack","rust","security","shell","supply-chain-security","terminal","unicode","url-security"],"license":"AGPL-3.0","category":"cli-tools","readme_excerpt":"tirith Your browser would catch this. Your terminal won't. Website Docs SKILL.md Changelog Independent open-source project, with hosting supported by the Vercel Open Source Program (Spring 2026 Cohort). --- Can you spot the difference? You can't. Neither can your terminal. Both і characters are Cyrillic (U+0456), not Latin i . The second URL resolves to an attacker's server. The script executes before you notice. Browsers solved this years ago. Terminals still render Unicode, ANSI escapes, and invisible characters without question. AI agents run shell commands and install packages without inspecting what's inside. Tirith stands at the gate. It intercepts commands, pasted content, and scanned files for homograph URLs, obfuscated payloads, credential exfiltration, malicious AI skills/configs, and known-bad packages/domains/IPs from a signed threat intelligence database before they execute. Then activate in your shell profile: [!TIP] eval \"$(tirith init)\" auto-detects your current shell (it inspects the parent process and falls back to $SHELL if needed). The explicit --shell flag is only required when you want to override the detection. That's it. Every command you run is now guarded. Zero friction on clean input. Sub-millisecond overhead. You forget it's there until it saves you. Also available via npm, cargo, mise, apt/dnf, and more. --- See it work Homograph attack, blocked before execution: The command never executes. Pipe-to-shell with clean URL, warned, not blocked: Warnin","default_branch":null,"files":null,"tree":[],"storefront":"/r/sheeki03","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/sheeki03/tirith/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}