GPR-013 · high risk

Review package-manager configuration access

Require review when supported file-read surfaces access package-manager configuration that can redirect installs.

Decision

review

Matcher

path = .npmrc

Reviewed

2026-08-09

Safe test cases

matching synthetic case

path = .npmrcreview

different benign synthetic case

path = benign-.npmrcunmatched

Limitations

  • Configuration filenames differ by ecosystem and workspace.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: c3d1d51616f5648a7f07f51e381d619b750e00944437b9dece53de07dbf9a836

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.