synsema/shell
A shell with a ceiling. Runs one command, without a shell, only if a human-written policy allows it; destructive operations are refused before anything runs, and the refusal comes back as data.
Official lamp — curated in the lamps monorepo.
Pull
lamp pull shell
Ceiling
Profile: native (runs under the native interpreter: the ceiling is the wall)
stdout,env=LAMP_*,file.read={dir}/*,exec=<your list>
Tools
- run
- check
- policy
Pulls
1 pulls, counted once per machine per day. Put the badge in your README:

Version
0.1.0