GPR-002 · high risk

Review untrusted package installs

Require review before supported package-install actions use an untrusted package.

Decision

review

Matcher

package = untrusted-package

Reviewed

2026-08-09

Safe test cases

matching synthetic case

package = untrusted-packagereview

different benign synthetic case

package = benign-untrusted-packageunmatched

Limitations

  • Package identity and install coverage depend on the active package-manager integration.

Review before applying

This recipe is a starting point, not a universal security policy. Open it in Policy Studio, replace example identifiers where necessary, review scope and blast radius, simulate where supported, and use the normal approval flow before enforcement.

Recipe SHA-256: 1d29a93b6c6cfbc03282b6c7953a8aa01f318f4eeeffeac24bf803d4b0427381

When a policy is saved and delivered through Guard Cloud, it uses the existing Guard policy-bundle compiler. If the policy-bundle signing key is configured, that compiler produces an RSA-PSS-SHA256 signed bundle that local Guard verifies before applying.