[{"data":1,"prerenderedAt":4},["ShallowReactive",2],{"readme:numbat":3},"\u003Ch1>numbat\u003C\u002Fh1>\n\u003Cp>Endpoint visibility into AI agent activity, with local detection, optional\npre-action blocking, and forensic reconstruction.\u003C\u002Fp>\n\u003Cp>numbat observes supported desktop, CLI, IDE, and gateway agents through local\nhooks and plugins, OTLP\u002FHTTP logs, and on-disk session artifacts. Live and\nat-rest activity is normalized into one event model and evaluated by the same\nCEL rule engine. Detection runs locally; records can be written to stdout or a\nlocal file and optionally delivered over HTTP.\u003C\u002Fp>\n\u003Cp>The \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Fblob\u002FHEAD\u002Fdocs\u002Fagent-coverage.md#matrix\" rel=\"nofollow ugc noopener\">coverage matrix\u003C\u002Fa> is authoritative for each\nhost and surface. Blocking is off by default and limited to supported\nsynchronous pre-action hooks; see the \u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Fblob\u002FHEAD\u002Fdocs\u002Fenforcement.md\" rel=\"nofollow ugc noopener\">enforcement guide\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Features\u003C\u002Fh2>\n\u003Cul>\n\u003Cli>\u003Cstrong>Live monitoring\u003C\u002Fstrong> through hooks, plugins, and OTLP\u002FHTTP log exporters.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Endpoint-local detection\u003C\u002Fstrong> with built-in CEL rules, multi-step sequence rules,\nand custom YAML rules.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Opt-in blocking\u003C\u002Fstrong> through supported pre-action hooks. Enforce mode is\ndisabled by default and applies only to rules marked \u003Ccode>enforce: true\u003C\u002Fcode>; all\nshipped rules are monitor-only.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Forensic reconstruction\u003C\u002Fstrong> from supported on-disk session artifacts, without\nprior numbat instrumentation.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Versioned NDJSON records\u003C\u002Fstrong> for events, findings, enforcement decisions,\nindicators, and scan summaries. Events and findings retain source references;\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Fblob\u002FHEAD\u002Fdocs\u002Fschema\u002Fv0.3.0\u002F\" rel=\"nofollow ugc noopener\">JSON Schemas\u003C\u002Fa> define the wire format.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Read-only artifact scanning\u003C\u002Fstrong> with secret redaction. Normal record output\nnever includes a complete raw transcript; adding raw evidence files to a case\nbundle is opt-in.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Inventory and investigation tools\u003C\u002Fstrong> for read-only agent discovery,\nper-session timelines, and portable case bundles with SHA-256 manifests.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Single-binary distribution\u003C\u002Fstrong> for macOS, Linux, and Windows, built without\ncgo.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Ch2>Quick start\u003C\u002Fh2>\n\u003Ch3>Install\u003C\u002Fh3>\n\u003Cp>\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Freleases\" rel=\"nofollow ugc noopener\">Download a release\u003C\u002Fa> for macOS, Linux,\nor Windows on amd64 or arm64. Each release includes SHA-256 checksums. You can\nalso install with Go 1.26.6 or newer:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>go install github.com\u002Fperplexityai\u002Fnumbat\u002Fcmd\u002Fnumbat@latest\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cdetails>\n\u003Csummary>Build a static binary from a checkout\u003C\u002Fsummary>\u003Cp>macOS or Linux:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>CGO_ENABLED=0 go build -trimpath -o numbat .\u002Fcmd\u002Fnumbat\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cp>Windows PowerShell:\u003C\u002Fp>\n\u003Cpre>\u003Ccode class=\"language-powershell\">$env:CGO_ENABLED = \"0\"\ngo build -trimpath -o numbat.exe .\u002Fcmd\u002Fnumbat\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003C\u002Fdetails>\u003Ch3>Inventory and scan\u003C\u002Fh3>\n\u003Cp>These read-only commands do not install hooks or change agent configuration:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>numbat agents\n# scan all discovered parser-backed agents\nnumbat scan\n# or limit automatic discovery to Codex\nnumbat scan --agent codex\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Monitor and enforce\u003C\u002Fh3>\n\u003Cp>Install live monitoring for any agent with\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Fblob\u002FHEAD\u002Fdocs\u002Fagent-coverage.md#matrix\" rel=\"nofollow ugc noopener\">live-capture support\u003C\u002Fa>; the commands below use\nCodex as a concrete example. Hooks start in monitor-only mode. \u003Ccode>--emit all\u003C\u002Fcode>\nwrites events, findings, indicators, and applicable enforcement decisions to\n\u003Ccode>~\u002F.numbat\u002Frecords.ndjson\u003C\u002Fcode>.\u003C\u002Fp>\n\u003Cpre>\u003Ccode>numbat hook install --agent codex --emit all\nnumbat hook status --agent codex\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Cblockquote>\n\u003Cp>\u003Cstrong>Hook trust:\u003C\u002Fstrong> Requirements vary by agent and scope. For the Codex user hook\nabove, review and trust its current definition in \u003Ccode>\u002Fhooks\u003C\u002Fcode> (CLI) or\nSettings &gt; Hooks (app), including after changes such as \u003Ccode>--enforce\u003C\u002Fcode>. Codex\nhooks installed with \u003Ccode>--managed\u003C\u002Fcode> are trusted by policy. \u003Ccode>hook status\u003C\u002Fcode> verifies\nconfiguration, not execution or delivery. See the\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Fblob\u002FHEAD\u002Fdocs\u002Fdeployment.md#hook-trust-and-activation\" rel=\"nofollow ugc noopener\">deployment guide\u003C\u002Fa> for other\nagents and scopes.\u003C\u002Fp>\n\u003C\u002Fblockquote>\n\u003Cp>All shipped rules are monitor-only. To enforce a detection, copy its complete\n\u003Ca href=\"https:\u002F\u002Fgithub.com\u002Fperplexityai\u002Fnumbat\u002Fblob\u002FHEAD\u002Frules\u002F\" rel=\"nofollow ugc noopener\">shipped YAML\u003C\u002Fa> into a controlled operator directory, keep the same id,\nadd \u003Ccode>enforce: true\u003C\u002Fcode>, and bump its version. Validate and install that effective\npolicy for a supported pre-action hook:\u003C\u002Fp>\n\u003Cpre>\u003Ccode>numbat rules check --rules-dir .\u002Fnumbat-policy\nnumbat hook install --agent codex --emit all \\\n  --rules-dir .\u002Fnumbat-policy --enforce\n\u003C\u002Fcode>\u003C\u002Fpre>\n\u003Ch3>Example output\u003C\u002Fh3>\n\u003Cdetails>\n\u003Csummary>\u003C\u002Fsummary>\u003C\u002Fdetails>",1787581367615]