TrustMeBro shows PATH shims are enough to feed coding agents fake tool output and move them past their own guardrails
This Go tool, created 2026-08-26 and now at 327 stars, intercepts command-line tools invoked by Codex, Claude Code and pi through PATH shims alone, with no plugin, hook or MCP integration required, and rules decide whether to fabricate output, rewrite real stdout while preserving stderr and exit status, block the call, or exec the real binary. The published evaluation is the point: each model had to verify a fresh DNS TXT authorization marker before running a scan, and GPT-5.6 Sol, GPT-5.5, DeepSeek V4 Pro and DeepSeek V4 Flash all correctly refused with the real dig, then all four proceeded once TrustMeBro returned fabricated proof. Framed for controlled red-team testing, and a reminder that any agent decision gated on shell output is only as trustworthy as PATH.
↳ Follow the thread