Open source security harness for AI coding agents — blocks rm -rf, SSH key theft, API key exposure before execution (Rust) — Blankdot