
Security News
Re-Enabled GitHub Actions Expose Thousands of Repositories to Mini Shai-Hulud
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.
@cleocode/git-shim
Advanced tools
Harness-agnostic git PATH override that fences agent (worker | lead |
subagent) git invocations. Provides two layers of enforcement:
checkout, switch, branch -D, worktree add, reset --hard,
rebase, push --force, etc.).git add MUST stage paths inside the active worktree.git commit -m "<msg>" MUST embed a CLEO task ID
(T<NUM>).git merge MUST be invoked by completeAgentWorktreeViaMerge
(signalled via CLEO_ORCHESTRATE_MERGE=1).git cherry-pick <ref> MUST NOT take a task/T<NUM> source
(cherry-pick from worktree branches is the deprecated integration
path superseded by ADR-062).Every block and every bypass is recorded in
<XDG_DATA_HOME ?? ~/.local/share>/cleo/audit/git-shim.jsonl.
The shim ships as the git bin entry of this package. The orchestrator
materialises a git symlink inside <projectRoot>/.cleo/bin/ (or any
shim directory) via installShimSymlink(...) and prepends that
directory to the spawned agent's PATH.
The shim only enforces when the agent role is restricted:
CLEO_AGENT_ROLE=worker # or lead, subagent
Orchestrators (the absence of CLEO_AGENT_ROLE or
CLEO_AGENT_ROLE=orchestrator) bypass the shim entirely — this keeps
orchestration code paths fast and unencumbered.
| Variable | Set by | Purpose |
|---|---|---|
CLEO_AGENT_ROLE | orchestrator (spawn) | Activates the fence for restricted roles. |
CLEO_WORKTREE_ROOT | orchestrator (spawn) | Explicit worktree path; auto-detected from cwd otherwise. |
CLEO_TASK_ID | orchestrator (spawn) | Active task ID; auto-derived from worktree path otherwise. |
CLEO_ORCHESTRATE_MERGE | completeAgentWorktreeViaMerge (T1587) | Single-purpose grant — allows git merge. See below. |
CLEO_ALLOW_BRANCH_OPS | operator (manual) | Single-shot bypass for the legacy denylist. Audited. |
CLEO_ALLOW_GIT | operator (emergency) | Universal bypass for any T1591 boundary block. Audited. |
CLEO_AUDIT_LOG_PATH | tests | Override audit log location. |
CLEO_REAL_GIT_PATH | tests | Skip PATH walk; use this binary as real git. |
CLEO_SHIM_MARKER | installer (optional) | Path-fragment that identifies the shim dir. Default: .cleo/bin/git-shim. |
CLEO_ORCHESTRATE_MERGE=1 contract (T1587 / ADR-062 integration)packages/core/src/spawn/branch-lock.ts::completeAgentWorktreeViaMerge
is the only sanctioned entry point for git merge on a CLEO task
branch. It MUST set CLEO_ORCHESTRATE_MERGE=1 in the env passed to the
spawned git merge --no-ff process. The shim's boundary (c) refuses any
other git merge invocation from a restricted role.
Concretely (see branch-lock.ts:830):
execFileSync('git', ['merge', '--no-ff', branch, '-m', subject], {
cwd: gitRoot,
encoding: 'utf-8',
stdio: ['pipe', 'pipe', 'pipe'],
env: { ...process.env, CLEO_ORCHESTRATE_MERGE: '1' },
});
If you discover a code path that needs to invoke git merge from
restricted-role context other than completeAgentWorktreeViaMerge,
file a follow-up task — do NOT silently set CLEO_ORCHESTRATE_MERGE=1
elsewhere. The narrow scope of this env var is what makes the boundary
auditable.
--abort, --continue, and --quit flag invocations are exempt —
they do not perform a merge.
For a legitimate emergency (e.g. operator hotfix, incident triage):
# One-off bypass; audit entry written to git-shim.jsonl.
CLEO_ALLOW_GIT=1 git <subcommand> ...
The bypass is logged with full context (subcommand, args, cwd, role, task_id, worktree_path). Reviewers can list bypasses via:
jq 'select(.outcome | startswith("bypassed"))' \
~/.local/share/cleo/audit/git-shim.jsonl
interface AuditRecord {
ts: string; // ISO 8601
outcome: 'blocked' | 'bypassed-allow-git' | 'bypassed-orchestrate-merge';
boundary: 'a' | 'b' | 'c' | 'd' | 'denylist';
code: string; // E_GIT_OP_BLOCKED | E_GIT_BOUNDARY_*
subcommand: string;
args: string[];
cwd: string;
worktree_path: string | null;
task_id: string | null;
role: string | null;
context: Record<string, string>;
}
The schema is project-agnostic: the audit log under
~/.local/share/cleo/audit/ is shared across every CLEO-managed
project on the host.
The git-binary fence (this package) is one layer in a multi-checkpoint pipeline:
| Layer | Package | Catches |
|---|---|---|
| Git binary | @cleocode/git-shim (this) | Direct git invocations from agents |
| Commit-msg hook | @cleocode/core (T1588) | Editor-flow commits (no inline -m) |
| Drift watchdog | @cleocode/core (T1594) | Files modified outside worktree |
| Pre-push reconcile | @cleocode/core (T1595) | Branch state drift before push |
| Sync linter | CI (T1598) | Review-time policy mismatches |
Both T1588 (hook) and T1591 (shim, boundary b) enforce the commit-subject T-ID rule. This is intentional defense in depth: a developer who disables the local hook still trips the shim.
git merge --no-ff (not cherry-pick)completeAgentWorktreeViaMerge (sets CLEO_ORCHESTRATE_MERGE=1)FAQs
Harness-agnostic git shim for CLEO agent branch-protection (T1118)
The npm package @cleocode/git-shim receives a total of 824 weekly downloads. As such, @cleocode/git-shim popularity was classified as not popular.
We found that @cleocode/git-shim demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.

Research
/Security News
A malicious Firefox extension fetches its payload after installation to evade detection, steal Google session cookies, and automate account takeover.

Research
/Security News
The compromise affects MemTensor's MemOS, an open source memory framework for large language models (LLMs) and AI agents. Both npm package @memtensor/memos-cloud-openclaw-plugin and the PyPI package MemoryOS are compromised. They drop cross-platform Go binaries that exfiltrate developer secrets.