GPR-019 · high risk

Review plugin execution

Require review before a named unreviewed plugin or skill-like tool executes.

Decision

review

Matcher

tool = unreviewed-plugin

Reviewed

2026-08-09

Safe test cases

matching synthetic case

tool = unreviewed-pluginreview

different benign synthetic case

tool = benign-unreviewed-pluginunmatched

Limitations

  • Artifact scanning and runtime execution controls are separate and complementary.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: 5d1aa0f2f28d9ad5cd01a9a79866cf71b9c60887534cfc278469818ce704283c

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.