GPR-004 · high risk

Review remote install scripts

Require review before a supported shell action invokes a remote installer pattern.

Decision

review

Matcher

command = curl

Reviewed

2026-08-09

Safe test cases

matching synthetic case

command = curlreview

different benign synthetic case

command = benign-curlunmatched

Limitations

  • Exact command matching is intentionally narrow; review adjacent shell and network controls for broader coverage.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: 41c89669234c3d2b55483728dc7cb47d25170769740bdb973b500decf60904ca

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.