2026-10-11 18:01 UTC

Independent use will determine whether dirblock and envblock can reliably prevent coding agents and compromised developer tools from accessing filesystem credentials and environment secrets without disrupting normal workflows.

state: expiredheat: lowuncertainty: highconvergesscott: mediumagentic-security credential-isolation developer-toolingRoku OSS

What is this?

Dirblock and envblock are presented as small whitelist-based guards intended to restrict access to sensitive filesystem directories and environment variables, particularly for coding agents and developer tools. The earliest cited repository artifact is an initial commit by Pat Brouillette, while the case attributes the project to Roku OSS; the supplied material does not clarify that relationship or provide independent test results. The broader snippets establish that coding agents and compromised extensions can expose `.env` files, credentials, SSH keys, and tokens, but they do not establish whether these specific guards are reliable or workflow-safe.

Why it matters to Scott

Dirblock and envblock independently implement Scott’s structural-containment position: enforce filesystem and credential boundaries outside the agent rather than relying on model compliance. Independent workflow testing could inform whether these lightweight whitelist guards are useful components for SiloOS and the Ask terminal agent, or whether reliable isolation requires the fuller padded-cell architecture; the radar tracks adjacent coding-agent secret-access failures, but not this specific project.
ip:framework.siloosip:concept.runtime-containmentdev:project.silo-osdev:project.askradar:claude-code-denied-read-secret-bypassradar:concept.coding-agent-securityradar:concept.agent-sandboxing
queries asked of Scott's wikis
  • coding-agent filesystem sandboxing and permission boundaries
  • environment-secret isolation for developer tools
  • default-deny versus whitelist agent harnesses
  • prompt-injection containment for local coding agents
  • capability-based access controls in development workflows
  • secure credential brokering without agent exposure

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Dirblock+envblock – tiny whitelist guards for dirs and env secretspfrench4211
🟧 echo.github ⭐The earliest public artifact is the repository’s initial commit, authored by Pat Brouillette. Its README describes dirblock as “A Linux daemPat Brouillette——
🟧 hnReal-time MCP interceptor that blocks .env reads and dangerous commands agentseddyflores112

Interpretation history

Decision trace