pack:
  id: built-in-protections
  version: 1.0.0
  created: 2026-07-28T00:00:00Z
  provenance:
    sources:
      - internal_research
    incident_refs: []
  minimum_engine_version: 0.6.0
  rules:
    - id: THREAT-2026-101
      severity: high
      name: Protected file overwrite
      description: >
        Mirrors Shield's Layer 1 File Guard protected_files policy
        (.env, *.pem, *.key, credentials/secrets/password files,
        package-lock.json, Dockerfile, .thuban-shield/) expressed as a
        rule-pack rule, so the same class of protection is visible and
        extensible through rule packs rather than only through the
        hardcoded policy engine.
      response_level: block
      type: single
      conditions:
        action_type: WRITE
        target_pattern: "**/.env"

    - id: THREAT-2026-102
      severity: critical
      name: Dangerous command execution
      description: >
        Mirrors Shield's checkExecute() dangerous_patterns list
        (rm -rf /, format c:, curl | sh, wget | bash, powershell -enc,
        base64 --decode | sh, etc.) — commands that are almost never
        legitimate in an automated agent context and are strongly
        associated with destructive or malicious intent.
      response_level: block
      type: single
      conditions:
        action_type: EXECUTE
        target_pattern: "*rm -rf*"

    - id: THREAT-2026-103
      severity: high
      name: Credential path access
      description: >
        Mirrors CredentialGuard's credential-shaped path detection
        (.ssh, .aws, .azure, .kube, gcloud, .npmrc, .netrc, id_rsa /
        id_ed25519 / id_ecdsa keys) as a rule-pack rule so credential
        access policy can be tuned or extended via rule packs.
      response_level: warn
      type: single
      conditions:
        action_type: READ
        target_pattern: "**/.ssh/id_rsa"

  signature: ""
