S

showtime command protection

Reviews the showtime video-studio CLI's commands that reach beyond the video project: installing tools and models (setup), writing other cod

Reviews the showtime video-studio CLI's commands that reach beyond the video project: installing tools and models (setup), writing other coding agents' configuration (install), deleting files (setup --prune, clean, voice cache --clear), explicit network downloads (audio music|lib|packs fetch, assets media fetch, reference <URL>) and driving a headless browser against a site or a walkthrough script (site capture|component|record, demo record). Project-local commands (new, check, render, qa, export, look, snap, receipt, doctor, guide, status) and --help are not matched and remain automatic. Components that ordinary commands fetch on first use (for example a speech model on the first transcription) are outside this extension; `showtime setup --plan` lists them.

command.showtime · v1.0.0 · Other extensions

By Community contributorExternal · opt-inCommand coverage
Protection rules
10
Permission checks
5
Mapped commands
2

Overview

What this coverage does

Reviews the showtime video-studio CLI's commands that reach beyond the video project: installing tools and models (setup), writing other coding agents' configuration (install), deleting files (setup --prune, clean, voice cache --clear), explicit network downloads (audio music|lib|packs fetch, assets media fetch, reference <URL>) and driving a headless browser against a site or a walkthrough script (site capture|component|record, demo record). Project-local commands (new, check, render, qa, export, look, snap, receipt, doctor, guide, status) and --help are not matched and remain automatic. Components that ordinary commands fetch on first use (for example a speech model on the first transcription) are outside this extension; `showtime setup --plan` lists them.

Key facts

Catalog ID
command.showtime
Version
v1.0.0
Kind
Command coverage
Category
Other extensions
Protection rules
10
Permission checks
5
Mapped commands
2
Maintainer
Community contributor(community, provenance recorded)
Source commit
3f37b9f
Protection model
External · opt-in
External · opt-in

External coverage. It must be enabled through Guard controls; this page does not activate it.

Stated limits

  • Coverage is limited to the reviewed operations and the surrounding Guard policy.
  • A maintainer profile is not a security certification or an official upstream endorsement.

Command mapping

Every command this extension recognizes, with the catalog default floor Guard applies before workspace policy. Search the table, then open an operation for safe variants and the permission ID.

10 operations · 10 reviewed by default These are catalog defaults, not your workspace policy.

10 operations10 reviewed
Default floor

Showing 10 of 10 operations

  • Reviewed Guard intercepts the command for review before it runs.High
    • showtime install --agent codex
    showtime install into an agent
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime install` (skills/showtime/lib/st/cli_install.py), which writes or, with --uninstall, removes a skill link, crew agents and an MCP server entry in another coding agent's configuration. --print and --list change nothing.
    Documented safe variants
    showtime install help (--help)showtime install help (-h)showtime install preview (--print)showtime install listing (--list)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.agent-install
  • Reviewed Guard intercepts the command for review before it runs.High
    • showtime setup --full
    showtime setup install
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime setup` (skills/showtime/setup/setup.py), which installs or updates tools and models in ~/.showtime and downloads what they need. --help, --list, --plan and --estimate return before the installer runs.
    Documented safe variants
    showtime setup help (--help)showtime setup help (-h)showtime setup listing (--list)showtime setup download plan (--plan)showtime setup size estimate (--estimate)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.setup
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime audio downloads
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime audio music fetch`, `audio lib fetch` and `audio packs fetch` (skills/showtime/lib/st/cli_audio.py), which download music tracks, audio-library tiers or sound-effect packs into ~/.showtime now. `audio lib fetch --list-parts` only lists.
    Documented safe variants
    showtime audio fetch help (--help)showtime audio fetch help (-h)showtime audio lib fetch part listing (--list-parts)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.downloads
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime clean
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime clean` (skills/showtime/lib/st/cli_job.py), which deletes the intermediates showtime wrote in a job or project (frame dumps, scratch, audio intermediates, with --all also review packs and logs). Without a terminal it refuses unless --yes is given; --dry-run only lists.
    Documented safe variants
    showtime clean help (--help)showtime clean help (-h)showtime clean preview (--dry-run)showtime clean preview (-n)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.cleanup
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime demo record
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime demo record` (skills/showtime/scripts/demo.mjs), which imports and runs a Node.js walkthrough script that drives a browser against --url or a --serve folder while recording frames.
    Documented safe variants
    showtime demo record help (--help)showtime demo record help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.browser-capture
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime assets media fetch
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime assets media fetch` (skills/showtime/lib/st/cli_capture.py, skills/showtime/lib/st/assets/media.py), which downloads an image or video by search id, or any http(s) URL when --license is given, and writes a license sidecar and credit.
    Documented safe variants
    showtime assets media fetch help (--help)showtime assets media fetch help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.downloads
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime reference from a URL
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime reference <http(s) URL>` (skills/showtime/lib/st/cli_variety.py, skills/showtime/lib/st/variety/reference.py), which downloads a video from a direct link before analysing it. A local file path is not matched.
    Documented safe variants
    showtime reference help (--help)showtime reference help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.downloads
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime setup --prune
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime setup --prune` (skills/showtime/setup/setup.py), which deletes files from older showtime versions that nothing uses any more under ~/.showtime.
    Documented safe variants
    showtime setup help (--help)showtime setup help (-h)showtime setup listing (--list)showtime setup download plan (--plan)showtime setup size estimate (--estimate)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.cleanup
  • Reviewed Guard intercepts the command for review before it runs.Medium
    Matcher metadata only
    showtime site capture, component or record
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime site capture|component|record` (skills/showtime/scripts/site.mjs), which load a URL in headless Chrome, dismiss consent banners and download the page's media. --serve <dir> captures a local static folder over 127.0.0.1 instead.
    Documented safe variants
    showtime site help (--help)showtime site help (-h)showtime site local static folder (--serve)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.browser-capture
  • Reviewed Guard intercepts the command for review before it runs.Low
    Matcher metadata only
    showtime voice cache clear or prune
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `showtime voice cache --clear` and `--prune` (skills/showtime/lib/st/cli_voice.py), which delete cached narration lines; plain `showtime voice cache` only reports its size.
    Documented safe variants
    showtime voice cache help (--help)showtime voice cache help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.showtime.permission.cleanup

Tool state mapping

No per-tool overrides are declared. Command defaults above resolve through the workspace Guard policy unless a later policy layer changes them.

Runtime identity

Catalog ID
command.showtime
Guard enforcement ID
command.showtime
Source path
contributions/extensions/command.showtime.json
Contribution digest
sha256…5e042c

Action classes

showtime dependency installshowtime agent configuration changeshowtime file removalshowtime network downloadshowtime browser automation

Technical profile

No independent profile published

This extension has no current independent technical profile. Catalog facts and any legacy launch remain separate and are not presented as profile evidence.

FAQ

Frequently asked questions

Reviews the showtime video-studio CLI's commands that reach beyond the video project: installing tools and models (setup), writing other coding agents' configuration (install), deleting files (setup --prune, clean, voice cache --clear), explicit network downloads (audio music|lib|packs fetch, assets media fetch, reference <URL>) and driving a headless browser against a site or a walkthrough script (site capture|component|record, demo record). Project-local commands (new, check, render, qa, export, look, snap, receipt, doctor, guide, status) and --help are not matched and remain automatic. Components that ordinary commands fetch on first use (for example a speech model on the first transcription) are outside this extension; `showtime setup --plan` lists them. The listing declares 10 rules and 5 permission checks. 10 operations · 10 reviewed by default. Coverage is limited to these reviewed operations and the surrounding Guard policy.

External · opt-in: External coverage. It must be enabled through Guard controls; this page does not activate it. Enabling state is always controlled through Guard policy, never from this directory.

This listing entered the catalog as a community contribution through a public pull request with recorded provenance. Credit is attribution only. A verified publisher profile and the claim flow verify authority separately; neither is an upstream endorsement or a HOL safety certification.

No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.

10 operations · 10 reviewed by default. Examples: showtime install --agent codex (reviewed by default); showtime setup --full (reviewed by default); showtime audio downloads (reviewed by default); showtime clean (reviewed by default); showtime demo record (reviewed by default); showtime assets media fetch (reviewed by default); showtime reference from a URL (reviewed by default); showtime setup --prune (reviewed by default). The remaining 2 operations are listed in the command mapping table. These are catalog defaults, not your workspace policy.

External coverage. It must be enabled through Guard controls; this page does not activate it. Enablement is managed through your workspace's Guard policy and controls — never from this directory. Open the install guidance for the setup flow, then adjust the command coverage for command.showtime in Guard's policy surface.

The matching action is stopped at Guard's pre-action boundary before it executes, and the decision is recorded with evidence your workspace can review. Exact behavior follows your Guard policy combined with this entry's 10 rules and 5 permission checks.

No. Guard is local-first: interception, decisions, and evidence stay on your machine unless your workspace explicitly configures cloud features. This page is documentation only — it never executes a command or changes protection state.

Guard runs locally alongside the major AI coding agents and MCP-capable harnesses, so this coverage applies wherever Guard intercepts actions. See the supported harness guides at https://hol.org/guard/harnesses for per-tool approval behavior and limitations.

Guard has a free local tier that includes command interception, evidence, and the policy controls this listing documents. Team plans add shared policy, review queues, and audit surfaces. Current plans: https://hol.org/guard/pricing

Open an issue or pull request against the hol-guard repository, where the canonical catalog lives: https://github.com/hashgraph-online/hol-guard Listings are corrected through the same public review process that adds them.

Yes. Community extensions are merged through public pull requests with recorded provenance, and you can claim the publisher page for a contribution you maintain through the Publisher Studio.

The command mapping table is the audit trail for covered commands and catalog default floors. Pair it with the reviewed rule and permission counts, the per-tool state mapping, and the exact source tree linked from View exact source at the reviewed commit. Guard records enforcement decisions with evidence locally, so what ships matches what you reviewed.