SigmaShake STRIKE
Userspace AI-agent compromise monitor — live Safe/Suspicious/Compromised verdict per agent session, with behavioral signal classification and session-level risk scoring.
Verified
observability
v0.1.3
Install
~/your-project
$ ssg plugins install strike
✓ Verified Ed25519 signature against sigmashakeinc
✓ Installed v0.1.3 into ~/.sigmashake/plugins/strike/
$ Open the dashboard → Plugins to enable
The CLI verifies SHA-256 + Ed25519 signature against the publisher's fingerprint before extracting the tarball. See trust model.
STRIKE adds a live compromise-monitor panel to the SSG dashboard. The STRIKE daemon runs as a separate loopback service and produces a per-session verdict (Safe / Suspicious / Compromised) by classifying behavioral signals from the agent's observable action stream — no kernel components, no process injection, no privileged access required. The plugin page connects to the daemon over the loopback (http://127.0.0.1:*; allowed by the SSG daemon's plugin-route CSP connect-src) and renders the current verdict, signal breakdown, and session history inside the SSG dashboard and SigmaShake Desktop. The value surface — the verdict logic, behavioral detectors, and containment signals — stays gated at the daemon entitlement layer, fail-closed. The plugin artifact is the free on-ramp; no anonymous or unauthenticated path to the verdict value is exposed. UI plugin plus a local sidecar daemon; no server logic is added to SSG core.