GPR-001 · critical risk

Review secret-file reads

Require review before supported agents read common local secret files.

Decision

review

Matcher

path = .env

Reviewed

2026-08-09

Safe test cases

matching synthetic case

path = .envreview

different benign synthetic case

path = benign-.envunmatched

Limitations

  • Path matching is surface-specific and does not replace operating-system access controls.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: aca3865d173ffa07174b07cd1a0b06c92031a9f237871bf3016bdc10174866da

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.