
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@trigguard/cli
Advanced tools
@trigguard/cliExecution authorization for AI agents and automated systems.
Operator CLI for the execution gateway: authorize, verify receipts, login, policy, and escalation.
npx trigguard demo
npm install -g @trigguard/cli
tg login
TrigGuard authorizes execution. It does not execute your deploy, payment, or tool call.
npm install -g @trigguard/cli
tg --help
Monorepo development:
npm run build -w @trigguard/cli
node packages/trigguard-cli/dist/index.js --help
export TRIGGUARD_GATEWAY_URL=https://your-run-url.run.app
export TRIGGUARD_BEARER="$(gcloud auth print-identity-token --audiences=$TRIGGUARD_GATEWAY_URL)"
trigguard authorize --surface deploy.release --json
trigguard verify ./receipt.json --json
tg escalation)Control-plane session required (tg login). JSON (--json) or table output.
tg escalation list [--status PENDING] [--org <orgId>] [--json]
tg escalation show <escalationId> [--org <orgId>] [--json]
tg escalation status <escalationId> [--org <orgId>] [--json]
tg escalation approve <escalationId> [--reason ...] [--org <orgId>] [--json]
tg escalation reject <escalationId> [--reason ...] [--org <orgId>] [--json]
tg escalation cancel <escalationId> [--org <orgId>] [--json]
tg escalation watch <escalationId> [--interval 5] [--org <orgId>] [--json]
Exit codes: 0 ok, 1 error, 2 not found, 3 conflict, 20 still pending (watch).
Map a vendor-shaped payload with a built-in adapter (packages/trigguard-providers), then authorize:
trigguard authorize --provider stripe --input ./payment.json --json
cat payment.json | trigguard authorize --provider stripe --input - --json
Use --surface + optional --context <file.json> when you already have canonical fields and do not need mapAction.
Or TRIGGUARD_USE_GCLOUD=1 to obtain the identity token via gcloud automatically.
| Environment | Auth |
|---|---|
| GitHub Actions | TrigGuard-AI/authorize@v1 (OIDC → GCP) |
| Local / scripts | TRIGGUARD_BEARER or TRIGGUARD_USE_GCLOUD=1 |
npm run build
node dist/index.js dev --port 8787
# or: npx trigguard dev
trigguard doctor — Node version, monorepo detection, optional /health on 127.0.0.1:8787trigguard verify-receipt <file.json> --public-key <hex> — offline verify for Execution Authority flat JSON (same as sdk/node verifyReceipt)--swift uses tg_execution_authority when TG_AUTHORITY_PRIVATE_KEY and a binary are available; otherwise the CLI falls back to the Node mock.See ../../docs/getting-started/local-authority.md.
trigguard verify uses @trigguard/receipt-verify. When you pass a known authority public key, verification is fully offline (no /.well-known fetch):
trigguard verify ./receipt.json --public-key <64-hex-ed25519-raw-or-pem>
trigguard verify ./receipt.json --public-key-file ./authority.pem
Precedence: --public-key → --public-key-file → keys from --keys-url / TRIGGUARD_KEYS_URL (with optional bearer for gated endpoints).
For Execution Authority /decide-shaped receipts, this matches the same canonical signing material as sdk/node / Swift.
FAQs
TrigGuard CLI — session foundation (tg), execution authority (trigguard)
The npm package @trigguard/cli receives a total of 208 weekly downloads. As such, @trigguard/cli popularity was classified as not popular.
We found that @trigguard/cli demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.