Rule sets
Declarative .rules files that enforce policy on agent tool calls. Content-hash locked, Ed25519-signed by the author, and replayable in the playground. Install with ssg hub pull rules-typescript.
Discover, fork, and install declarative .rules that enforce policy on agent tool-calls before they run. Zero‑latency, zero‑tokens. Rulesets are authored by SigmaShake; community contributions welcome.
TypeScript is a strongly typed programming language that builds on JavaScript. These rules govern type safety, vulnerability prevention, and idiomatic coding patterns for AI agents.
GitHub Actions is a CI/CD platform that allows you to automate your build, test, and deployment pipeline. These rules govern workflow security, secret management, and action configuration for AI agents.
React is a JavaScript library for building user interfaces based on components. These rules govern hook usage, state management, and component lifecycle best practices for AI agents.
Docker is a platform for developing and running applications in containers. These rules guide AI agents in containerizing applications, managing Dockerfiles, and optimizing multi-stage builds and Docker Compose configurations.
Zig is a general-purpose programming language and toolchain for maintaining robust, optimal and reusable software. These rules govern memory management safety and coding best practices for AI agents.
Windows is a major family of operating systems developed by Microsoft. These rules govern system security, administrative safety, and configuration best practices for AI agents.
Declarative .rules files that enforce policy on agent tool calls. Content-hash locked, Ed25519-signed by the author, and replayable in the playground. Install with ssg hub pull rules-typescript.
Signed tarballs that extend the SSG dashboard UI. Workspace, observability, productivity panels, and more — installable on demand with ssg plugins install. Browse the marketplace.
GHOSTMUX persistent terminal - tmux-style multi-session PTY with coding-agent launcher.
Userspace AI-agent compromise monitor — live Safe/Suspicious/Compromised verdict per agent session, with behavioral signal classification and session-level risk scoring.
Approve or deny SSG tool-call prompts from Slack — Block Kit buttons over Socket Mode (no public URL), with an approver allowlist that verifies the human.
Local Whisper voice-to-text (whisper.cpp WASM) with a settable hotkey — dictate in the SSG dashboard or Desktop and turn speech into a .rules file.
Your SSG plan tier and today's eval usage at a glance.
Switch eval mode (ask/allow/deny) and dry-run tool calls against your rules.
.rules to enforced policy in three stepsBrowse signed, versioned rulesets authored by SigmaShake — and submit your own. Each ruleset is fetched directly from GitHub and locked to a content hash.
Run ssg hub pull rules-typescript and the engine pulls, verifies the signature, and writes the ruleset into your project's .sigmashake/ directory.
Every agent tool call is evaluated against the ruleset before execution — zero-latency, zero-tokens. Decisions: ALLOW, DENY, ASK, FORCE, LOG, SHADOW; FORCE returns a safe substitute path.
Every published ruleset is signed with the maintainer's key. The ssg CLI verifies the signature against /api/pubkey before installing.
Each version pins a SHA-256 of the indexed rules. Any edit upstream bumps the hash and the version — no silent overrides.
Every publish, update, and resync appends to an append-only Merkle log cross-anchored with sigmashake-compliance.
Browse OpenAPI 3, llms.txt, sitemap.xml, and security.txt. Stable, agent-friendly endpoints.
Connect any agent to mcp.sigmashake.com/sse — six tools cover eval, search, audit, and publish. No SDK required.
Internal control evidence is collected continuously via sigmashake-compliance with 90-day Object Lock retention. Not a completed SOC 2 attestation.
Got a ruleset that would protect other teams? Every submitted ruleset is signed, versioned, and auditable. Install ssg, point it at your repo, and it's live on the hub — instantly discoverable by every AI agent host.
$ curl -fsSL https://install.sigmashake.com | sh
$ ssg publish
✓ Parsed 14 rules across 3 technologies
✓ Signed & pushed to hub.sigmashake.com
$ ▍