Guarded terminal

PATH shims for common tools. Humans get convenient resolution; agent harness invocations do not inherit workspace secrets implicitly.

Agents leave the shim at launch

Workspace Agent, app menu, printed commands, and hand-typed claude, code, codex, cursor, or devin start without guard markers. The parent tab stays guarded.

Run authsia setup --repair once and open a new terminal first.

Active

Shim count is live in this tab.

Stale

Guard metadata and PATH disagree.

Inactive

Inside a launched agent session. Agent launchers start unguarded; they are not routed through workspace run.

Default tool families

npm, pnpm, yarn, python, pip, docker, aws, gcloud, az, kubectl, helm, terraform, tofu, terragrunt, pulumi, ansible-playbook.