tripwire_guard

Optional deterministic honeytoken tripwires for compromise detection.


What it mitigates


ProfileenabledonTrip
localtrue for productionkill_switch
standardopt-in for high-risk agentsdeny or kill_switch
unboundedoptionalalert

Minimal config

moduleConfig:
  tripwire_guard:
    enabled: true
    fileTokens:
      - "${workspace}/.tripwire/**"
    envTokens:
      - "RADIUS_TRIPWIRE_SECRET"
    onTrip: kill_switch

Design guidance