Appliquer les règles d'agents
L'application des règles est le niveau 2 du Contrôle des agents IA de SilentShield : au lieu de seulement enregistrer les visites des agents IA, votre serveur ou votre edge applique activement votre politique par clé — chaque agent est autorisé, limité ou bloqué. Elle s'appuie directement sur le mode observation. Les composants d'enforcement (middleware Next.js, binaire sidecar, Cloudflare Worker) sont actuellement fournis sur demande en accès anticipé — contactez [email protected].
Observer d'abord, appliquer ensuite
Notre recommandation claire : activez d'abord l'observation, laissez-la tourner une à deux semaines et consultez le rapport avant de bloquer quoi que ce soit — le même déploiement par étapes que le mode apprentissage de Wordfence ou un rollout DMARC (none → quarantine → reject). Seul le rapport montre quels services IA visitent réellement votre site et ce qu'un blocage vous coûterait, par exemple des citations dans la recherche IA. Appliquer sans cette vision, c'est décider à l'aveugle.
Comment fonctionne l'application
Tous les enforcers partagent le même contrat : ils récupèrent un bundle de politique pour votre clé API, vérifient sa signature Ed25519 avec les clés publiques épinglées de SilentShield, puis décident localement — autoriser, refuser ou limiter — sans aucun appel sur le chemin de la requête.
Vous récupérez une seule fois les clés de signature épinglées sur https://api.silentshield.io/.well-known/silentshield-agent-keys. Et chaque enforcer fonctionne en fail-open : à la moindre erreur — réseau, signature, bundle expiré — la requête est laissée passer. L'application des règles ne peut jamais mettre votre site hors service.
Variantes de configuration
Go (net/http)
Un enforcer autonome — bibliothèque standard uniquement, sans SDK. Il récupère et vérifie la politique signée en arrière-plan (Ed25519, clés épinglées) et décide à chaque requête ; enveloppez votre handler avec son middleware. Fail-open : toute erreur ou le mode surveillance laisse passer la requête.
// Self-contained SilentShield agent-policy enforcer — stdlib only, no SDK.
// Drop this in, wrap your handler with New(cfg).Middleware, and blocked bots
// get a 403 (throttled ones a 429). Fail-open by design: any error, an
// unverifiable bundle, or monitor mode lets the request through — enforcement
// can never take your site down.
package ssenforce
import (
"bytes"
"crypto/ed25519"
"encoding/base64"
"encoding/json"
"io"
"net"
"net/http"
"strconv"
"strings"
"sync"
"time"
)
// Config for the enforcer. PolicyURL + APIKey + at least one trusted key are
// required; with any missing the enforcer is a no-op (always allow).
type Config struct {
PolicyURL string // https://api.silentshield.io/api/v1/agent/policy
KeysURL string // https://api.silentshield.io/.well-known/silentshield-agent-keys
APIKey string // your publishable site key (x-api-key)
}
type signedBundle struct {
Payload string `json:"payload"`
Alg string `json:"alg"`
Kid string `json:"kid"`
Sig string `json:"sig"`
}
type bundle struct {
FormatVersion int `json:"format_version"`
Mode string `json:"mode"`
QuotaEnabled bool `json:"quota_enabled"`
Rules []rule `json:"rules"`
Agents []agent `json:"agents"`
}
type agent struct {
Slug string `json:"slug"`
Category string `json:"category"`
UATokens []string `json:"ua_tokens"`
CIDRs []string `json:"cidrs"`
}
type rule struct {
Match match `json:"match"`
PathPattern string `json:"path_pattern"`
Methods []string `json:"methods"`
Action string `json:"action"`
RateLimit *rateLimit `json:"rate_limit"`
}
type match struct {
Type string `json:"type"`
Value string `json:"value"`
}
type rateLimit struct {
Requests int `json:"requests"`
WindowSec int `json:"window_sec"`
}
// Enforcer fetches, verifies and caches the signed policy, refreshing every
// 5 minutes in the background, and decides per request.
type Enforcer struct {
cfg Config
enabled bool
mu sync.RWMutex
b *bundle
cidrs map[string][]*net.IPNet
countersMu sync.Mutex
counters map[string]*window
}
type window struct {
bucket int64
count int
}
// New builds an enforcer and starts background refresh. Call once at startup.
func New(cfg Config) *Enforcer {
e := &Enforcer{cfg: cfg, counters: map[string]*window{}}
e.enabled = cfg.PolicyURL != "" && cfg.KeysURL != "" && cfg.APIKey != ""
if !e.enabled {
return e
}
_ = e.refresh() // best-effort initial load
go func() {
t := time.NewTicker(5 * time.Minute)
defer t.Stop()
for range t.C {
_ = e.refresh()
}
}()
return e
}
// Middleware wraps next, blocking disallowed bots. Monitor mode / fail-open
// never block.
func (e *Enforcer) Middleware(next http.Handler) http.Handler {
return http.HandlerFunc(func(w http.ResponseWriter, r *http.Request) {
// Optional: exempt your own trusted traffic (e.g. logged-in users) from
// enforcement. Plug in your own check — it runs first, so a matching
// request is never blocked. Keep it cheap (inspect your session cookie /
// JWT), no I/O.
// if isLoggedIn(r) {
// next.ServeHTTP(w, r)
// return
// }
if block, status, retry := e.decide(r); block {
if retry > 0 {
w.Header().Set("Retry-After", strconv.Itoa(retry))
}
w.WriteHeader(status)
reportBlock(e.cfg.APIKey, r, status) // feed the dashboard's blocked-bots report
return
}
next.ServeHTTP(w, r)
})
}
// reportBlock fire-and-forgets a report that this request was blocked, so the
// SilentShield dashboard's "blocked bots" report has data. Best-effort: its own
// goroutine + timeout, all errors ignored — it never delays the response.
func reportBlock(apiKey string, r *http.Request, status int) {
outcome := "deny"
if status == http.StatusTooManyRequests {
outcome = "throttle"
}
s := map[string]any{"ua": r.UserAgent(), "ip": remoteIP(r), "path": r.URL.Path, "method": r.Method, "outcome": outcome}
body, _ := json.Marshal(map[string]any{"sightings": []any{s}})
go func() {
req, err := http.NewRequest("POST", "https://api.silentshield.io/api/v1/agent/telemetry", bytes.NewReader(body))
if err != nil {
return
}
req.Header.Set("Content-Type", "application/json")
req.Header.Set("x-api-key", apiKey)
if resp, err := (&http.Client{Timeout: 3 * time.Second}).Do(req); err == nil {
resp.Body.Close()
}
}()
}
func (e *Enforcer) decide(r *http.Request) (block bool, status, retry int) {
if !e.enabled {
return false, 0, 0
}
e.mu.RLock()
b, cidrs := e.b, e.cidrs
e.mu.RUnlock()
if b == nil || b.Mode != "enforce" {
return false, 0, 0 // no bundle or monitor → never block
}
slug, category := "", ""
best := 0
ua := strings.ToLower(r.UserAgent())
for _, a := range b.Agents {
for _, tok := range a.UATokens {
tl := strings.ToLower(tok)
if tl != "" && strings.Contains(ua, tl) && len(tl) > best {
best, slug, category = len(tl), a.Slug, a.Category
}
}
}
verified := false
if slug != "" {
ip := net.ParseIP(remoteIP(r))
for _, n := range cidrs[slug] {
if ip != nil && n.Contains(ip) {
verified = true
break
}
}
}
ru := evaluate(b.Rules, slug, category, verified, r.URL.Path, r.Method)
if ru == nil {
return false, 0, 0
}
switch ru.Action {
case "deny":
return true, http.StatusForbidden, 0
case "throttle":
if b.QuotaEnabled && ru.RateLimit != nil {
key := slug
if key == "" {
key = "cat:" + category
}
if ok, ra := e.allowThrottle(key, ru.RateLimit); !ok {
return true, http.StatusTooManyRequests, ra
}
}
}
return false, 0, 0
}
// evaluate walks the rules in order, first match wins (nil → allow).
func evaluate(rules []rule, slug, category string, verified bool, path, method string) *rule {
for i := range rules {
ru := &rules[i]
if !matchApplies(ru.Match, slug, category, verified) {
continue
}
if !pathMatches(ru.PathPattern, path) {
continue
}
if !methodMatches(ru.Methods, method) {
continue
}
return ru
}
return nil
}
func matchApplies(m match, slug, category string, verified bool) bool {
switch m.Type {
case "any":
return true
case "agent_slug":
return slug != "" && slug == m.Value
case "agent_category":
return category != "" && category == m.Value
case "unsigned":
return !verified
}
return false
}
func pathMatches(pattern, path string) bool {
if pattern == "" || pattern == "*" {
return true
}
if strings.HasSuffix(pattern, "*") {
return strings.HasPrefix(path, strings.TrimSuffix(pattern, "*"))
}
return path == pattern
}
func methodMatches(methods []string, method string) bool {
if len(methods) == 0 {
return true
}
for _, m := range methods {
if strings.EqualFold(strings.TrimSpace(m), method) {
return true
}
}
return false
}
func (e *Enforcer) allowThrottle(key string, rl *rateLimit) (bool, int) {
if rl.Requests <= 0 || rl.WindowSec <= 0 {
return true, 0
}
now := time.Now().Unix()
bucket := now / int64(rl.WindowSec)
e.countersMu.Lock()
defer e.countersMu.Unlock()
c := e.counters[key]
if c == nil || c.bucket != bucket {
c = &window{bucket: bucket}
e.counters[key] = c
}
c.count++
if c.count > rl.Requests {
retry := int((bucket+1)*int64(rl.WindowSec) - now)
if retry < 1 {
retry = 1
}
return false, retry
}
return true, 0
}
// refresh fetches + verifies the bundle and swaps it in. On any error the
// previous bundle is kept (fail-open).
func (e *Enforcer) refresh() error {
keys, err := e.fetchKeys()
if err != nil {
return err
}
req, _ := http.NewRequest(http.MethodGet, e.cfg.PolicyURL, nil)
req.Header.Set("x-api-key", e.cfg.APIKey)
resp, err := http.DefaultClient.Do(req)
if err != nil {
return err
}
defer resp.Body.Close()
if resp.StatusCode != http.StatusOK {
return nil // 304/anything else → keep last good bundle
}
raw, err := io.ReadAll(io.LimitReader(resp.Body, 1<<20))
if err != nil {
return err
}
b, err := verifyBundle(raw, keys)
if err != nil {
return err
}
cidrs := map[string][]*net.IPNet{}
for _, a := range b.Agents {
for _, c := range a.CIDRs {
if _, n, err := net.ParseCIDR(c); err == nil {
cidrs[a.Slug] = append(cidrs[a.Slug], n)
}
}
}
e.mu.Lock()
e.b, e.cidrs = b, cidrs
e.mu.Unlock()
return nil
}
func (e *Enforcer) fetchKeys() (map[string]ed25519.PublicKey, error) {
resp, err := http.Get(e.cfg.KeysURL)
if err != nil {
return nil, err
}
defer resp.Body.Close()
var payload struct {
Keys []struct {
Kid string `json:"kid"`
Key string `json:"key"`
} `json:"keys"`
}
if err := json.NewDecoder(resp.Body).Decode(&payload); err != nil {
return nil, err
}
out := map[string]ed25519.PublicKey{}
for _, k := range payload.Keys {
if raw, err := base64.StdEncoding.DecodeString(k.Key); err == nil && len(raw) == ed25519.PublicKeySize {
out[k.Kid] = ed25519.PublicKey(raw)
}
}
return out, nil
}
// verifyBundle checks the Ed25519 signature over the raw payload and returns the
// decoded bundle. The signed bytes are the payload JSON exactly (no hashing).
func verifyBundle(body []byte, keys map[string]ed25519.PublicKey) (*bundle, error) {
var sb signedBundle
if err := json.Unmarshal(body, &sb); err != nil {
return nil, err
}
if sb.Alg != "ed25519" {
return nil, errInvalid
}
pub, ok := keys[sb.Kid]
if !ok {
return nil, errInvalid
}
payload, err := base64.StdEncoding.DecodeString(sb.Payload)
if err != nil {
return nil, err
}
sig, err := base64.StdEncoding.DecodeString(sb.Sig)
if err != nil {
return nil, err
}
if !ed25519.Verify(pub, payload, sig) {
return nil, errInvalid
}
var b bundle
if err := json.Unmarshal(payload, &b); err != nil {
return nil, err
}
if b.FormatVersion > 1 {
return nil, errInvalid // a newer wire format we can't be sure we understand
}
return &b, nil
}
// remoteIP is the source IP for CIDR verification. Behind a trusted proxy,
// restore the real client IP here (do NOT trust a spoofable header for the
// verification decision).
func remoteIP(r *http.Request) string {
ip, _, err := net.SplitHostPort(r.RemoteAddr)
if err != nil {
return r.RemoteAddr
}
return ip
}
type sentinel string
func (s sentinel) Error() string { return string(s) }
const errInvalid = sentinel("invalid bundle")
// Wiring:
// enf := ssenforce.New(ssenforce.Config{
// PolicyURL: "https://api.silentshield.io/api/v1/agent/policy",
// KeysURL: "https://api.silentshield.io/.well-known/silentshield-agent-keys",
// APIKey: "YOUR_API_KEY",
// })
// http.ListenAndServe(":8080", enf.Middleware(mux))Node.js / Express
Le même enforcer pour Node.js, utilisant uniquement le module crypto intégré. Enregistrez-le comme premier middleware afin qu'il s'exécute avant vos routes. Fail-open par conception.
// Self-contained SilentShield agent-policy enforcer for Node.js / Express —
// no SDK, only the built-in `crypto`. Wrap your app with enforcer(cfg) and
// blocked bots get a 403 (throttled ones a 429). Fail-open by design: any
// error, an unverifiable bundle, or monitor mode lets the request through.
const crypto = require("crypto");
// Raw 32-byte Ed25519 public key → a verifiable KeyObject (DER SPKI wrap).
const ED25519_SPKI_PREFIX = Buffer.from("302a300506032b6570032100", "hex");
function toPublicKey(rawBase64) {
const raw = Buffer.from(rawBase64, "base64");
if (raw.length !== 32) return null;
return crypto.createPublicKey({
key: Buffer.concat([ED25519_SPKI_PREFIX, raw]),
format: "der",
type: "spki",
});
}
function ipInCidr(ip, cidr) {
// Node's net has no CIDR test; do a byte-mask compare on the parsed buffers.
const [subnet, bitsStr] = cidr.split("/");
const bits = parseInt(bitsStr, 10);
const a = ipToBuf(ip);
const b = ipToBuf(subnet);
if (!a || !b || a.length !== b.length || bits < 0 || bits > a.length * 8) return false;
const full = Math.floor(bits / 8);
for (let i = 0; i < full; i++) if (a[i] !== b[i]) return false;
const rem = bits % 8;
if (rem === 0) return true;
const mask = (0xff << (8 - rem)) & 0xff;
return (a[full] & mask) === (b[full] & mask);
}
function ipToBuf(ip) {
if (net_isIPv4(ip)) return Buffer.from(ip.split(".").map((n) => parseInt(n, 10)));
try {
// Expand IPv6 to 16 bytes via the built-in parser.
const parts = require("net").isIPv6(ip) ? ip : null;
if (!parts) return null;
return ipv6ToBuf(ip);
} catch {
return null;
}
}
function net_isIPv4(ip) {
return require("net").isIPv4(ip);
}
function ipv6ToBuf(ip) {
// Minimal IPv6 → 16-byte buffer (handles "::" compression).
let [head, tail] = ip.split("::");
const h = head ? head.split(":") : [];
const t = tail ? tail.split(":") : [];
const missing = 8 - (h.length + t.length);
if (missing < 0) return null;
const groups = [...h, ...Array(missing).fill("0"), ...t];
const buf = Buffer.alloc(16);
for (let i = 0; i < 8; i++) {
const v = parseInt(groups[i] || "0", 16);
buf.writeUInt16BE(v, i * 2);
}
return buf;
}
function matchApplies(m, slug, category, verified) {
switch (m && m.type) {
case "any": return true;
case "agent_slug": return slug !== "" && slug === m.value;
case "agent_category": return category !== "" && category === m.value;
case "unsigned": return !verified;
default: return false;
}
}
function pathMatches(pattern, path) {
if (!pattern || pattern === "*") return true;
if (pattern.endsWith("*")) return path.startsWith(pattern.slice(0, -1));
return path === pattern;
}
function methodMatches(methods, method) {
if (!methods || methods.length === 0) return true;
return methods.some((m) => String(m).trim().toUpperCase() === method.toUpperCase());
}
function evaluate(rules, slug, category, verified, path, method) {
for (const r of rules || []) {
if (!matchApplies(r.match || {}, slug, category, verified)) continue;
if (!pathMatches(r.path_pattern || "", path)) continue;
if (!methodMatches(r.methods || [], method)) continue;
return r;
}
return null;
}
function verifyBundle(body, keys) {
let env;
try { env = JSON.parse(body); } catch { return null; }
if (!env || env.alg !== "ed25519") return null;
const pub = keys[env.kid];
if (!pub) return null;
const payload = Buffer.from(env.payload || "", "base64");
const sig = Buffer.from(env.sig || "", "base64");
if (sig.length !== 64) return null;
if (!crypto.verify(null, payload, pub, sig)) return null;
let bundle;
try { bundle = JSON.parse(payload.toString("utf8")); } catch { return null; }
if ((bundle.format_version || 1) > 1) return null;
return bundle;
}
function enforcer(cfg) {
const state = { bundle: null };
const counters = new Map();
async function refresh() {
try {
const keysRes = await fetch(cfg.keysUrl);
const keysJson = await keysRes.json();
const keys = {};
for (const k of keysJson.keys || []) {
const pk = toPublicKey(k.key);
if (pk) keys[k.kid] = pk;
}
if (Object.keys(keys).length === 0) return;
const res = await fetch(cfg.policyUrl, { headers: { "x-api-key": cfg.apiKey } });
if (res.status !== 200) return; // 304/other → keep last good bundle
const bundle = verifyBundle(await res.text(), keys);
if (bundle) state.bundle = bundle;
} catch {
/* fail-open: keep the last good bundle */
}
}
refresh();
setInterval(refresh, 5 * 60 * 1000).unref();
return function (req, res, next) {
try {
// Optional: exempt your own trusted traffic (e.g. logged-in users) from
// enforcement. Plug in your own check — it runs first, so a matching
// request is never blocked. Keep it cheap (inspect your session cookie /
// JWT), no I/O.
// if (isLoggedIn(req)) return next();
const b = state.bundle;
if (!b || b.mode !== "enforce") return next();
const ua = (req.headers["user-agent"] || "").toLowerCase();
let slug = "", category = "", best = 0, cidrs = [];
for (const a of b.agents || []) {
for (const tok of a.ua_tokens || []) {
const tl = String(tok).toLowerCase();
if (tl && ua.includes(tl) && tl.length > best) {
best = tl.length; slug = a.slug; category = a.category; cidrs = a.cidrs || [];
}
}
}
let verified = false;
if (slug) {
const ip = (req.socket && req.socket.remoteAddress) || "";
verified = cidrs.some((c) => ipInCidr(ip.replace(/^::ffff:/, ""), c));
}
const rule = evaluate(b.rules, slug, category, verified, req.path || req.url || "/", req.method);
if (!rule) return next();
if (rule.action === "deny") { res.statusCode = 403; reportBlock(cfg.apiKey, req, "deny"); return res.end("Forbidden"); }
if (rule.action === "throttle" && b.quota_enabled && rule.rate_limit) {
const key = slug || ("cat:" + category);
const { ok, retry } = throttleOk(counters, key, rule.rate_limit);
if (!ok) { res.statusCode = 429; res.setHeader("Retry-After", String(retry)); reportBlock(cfg.apiKey, req, "throttle"); return res.end("Too Many Requests"); }
}
return next();
} catch {
return next(); // fail-open
}
};
}
// reportBlock fire-and-forgets a report that this request was blocked, so the
// SilentShield dashboard's "blocked bots" report has data. Best-effort — errors
// are swallowed and it never delays the response.
function reportBlock(apiKey, req, outcome) {
try {
const s = {
ua: req.headers["user-agent"] || "",
ip: ((req.socket && req.socket.remoteAddress) || "").replace(/^::ffff:/, ""),
path: req.path || req.url || "/",
method: req.method,
outcome,
};
fetch("https://api.silentshield.io/api/v1/agent/telemetry", {
method: "POST",
headers: { "Content-Type": "application/json", "x-api-key": apiKey },
body: JSON.stringify({ sightings: [s] }),
}).catch(() => {}); // best-effort, fail-open
} catch {
/* ignore */
}
}
function throttleOk(counters, key, rl) {
const requests = rl.requests | 0, window = rl.window_sec | 0;
if (requests <= 0 || window <= 0) return { ok: true, retry: 0 };
const now = Math.floor(Date.now() / 1000);
const bucket = Math.floor(now / window);
let c = counters.get(key);
if (!c || c.bucket !== bucket) { c = { bucket, count: 0 }; counters.set(key, c); }
c.count++;
if (c.count > requests) {
const retry = Math.max(1, (bucket + 1) * window - now);
return { ok: false, retry };
}
return { ok: true, retry: 0 };
}
module.exports = { enforcer };
// Wiring (Express):
// const { enforcer } = require("./silentshield-enforcer");
// app.use(enforcer({
// policyUrl: "https://api.silentshield.io/api/v1/agent/policy",
// keysUrl: "https://api.silentshield.io/.well-known/silentshield-agent-keys",
// apiKey: "YOUR_API_KEY",
// }));WordPress
Vous utilisez WordPress ? Le plugin SilentShield embarque l'enforcer à partir de la version 2.10.0 — aucun code nécessaire. Activez-le sous Advanced → « Bloquer les robots d'IA (enforce) » (désactivé par défaut). Il récupère et vérifie la même politique signée côté serveur et bloque pour vous les bots non autorisés.
Next.js et autres hébergements edge / serverless
Le middleware Next.js s'exécute sur le runtime Edge, où vérifier le bundle signé est peu pratique. Pour Next.js — et tout hébergement edge ou serverless — placez le sidecar reverse-proxy (ci-dessous) devant votre application afin que l'application des règles ait lieu avant que la requête ne l'atteigne, ou utilisez l'enforcer Go ou Node.js ci-dessus si vous exploitez votre propre serveur.
Reverse proxy (nginx / Caddy / Traefik)
Un seul petit binaire sidecar dessert les trois proxys : le proxy l'interroge une fois par requête via forward auth. Démarrez-le avec votre clé de site et les clés de confiance :
AGENT_POLICY_URL="https://api.silentshield.io/api/v1/agent/policy" \
AGENT_SITE_KEY="YOUR_API_KEY" \
AGENT_TRUSTED_KEYS='[{"kid":"…","key":"<base64 ed25519 pubkey>"}]' \
AGENT_SIDECAR_LISTEN=":8127" \
./agent-sidecarLe sidecar répond sur GET /auth par 204 (autorisé), 403 (refusé) ou 429 avec Retry-After (limité). Voici comment le raccorder à votre proxy :
location = /_ss_auth {
internal;
proxy_pass http://127.0.0.1:8127/auth;
proxy_pass_request_body off;
proxy_set_header Content-Length "";
proxy_set_header X-Forwarded-Method $request_method;
proxy_set_header X-Forwarded-Uri $request_uri;
proxy_set_header X-Forwarded-Host $host;
proxy_set_header X-Forwarded-For $remote_addr;
proxy_set_header User-Agent $http_user_agent;
proxy_set_header Signature $http_signature;
proxy_set_header Signature-Input $http_signature_input;
proxy_set_header Signature-Agent $http_signature_agent;
}
location / {
auth_request /_ss_auth;
# ... your normal proxy_pass to the origin ...
}example.com {
forward_auth 127.0.0.1:8127 {
uri /auth
copy_headers User-Agent Signature Signature-Input Signature-Agent
# Caddy sends X-Forwarded-Method/-Uri/-Host automatically
}
reverse_proxy origin:8080
}http:
middlewares:
silentshield:
forwardAuth:
address: "http://agent-sidecar:8127/auth"
authRequestHeaders:
- "User-Agent"
- "Signature"
- "Signature-Input"
- "Signature-Agent"Cloudflare Worker
L'enforcer Cloudflare Worker vérifie le bundle de politique via Web Crypto Ed25519 et bloque avant même que les requêtes n'atteignent votre origin :
cd enforcers/cloudflare-worker
npx wrangler secret put AGENT_SITE_KEY
# set AGENT_POLICY_URL + AGENT_TRUSTED_KEYS in wrangler.toml [vars]
npx wrangler deploySDK officiels
Vous préférez un paquet maintenu plutôt que l'extrait à copier-coller ci-dessus ? Installez l'un de nos SDK officiels — le même enforcer, plus les utilitaires verify et observe, tenus à jour :
npm install @forge12interactive/silentshield-sdk-jsgo get github.com/forge12interactive/[email protected]composer config repositories.silentshield vcs https://github.com/forge12interactive/silentshield-sdk-php
composer require forge12interactive/silentshield-sdkLe code source, les tickets et le README complet de chaque SDK sont sur GitHub : silentshield-sdk-js · silentshield-go · silentshield-sdk-php
Limites honnêtes
Les navigateurs agentiques sur des adresses IP résidentielles (Comet, ChatGPT Atlas et similaires) sont techniquement impossibles à distinguer des visiteurs humains. Aucun produit ne peut les identifier de manière fiable — SilentShield ne fait donc délibérément aucune promesse d'application pour cette catégorie.
robots.txt et les signaux de contenu émis sont indicatifs : les crawlers bien élevés les respectent, mais rien ne les y oblige. L'application technique n'a lieu que dans les enforcers de cette page — et même eux agissent de façon conservatrice, en ne refusant que les agents connus formellement identifiés, afin que les visiteurs légitimes ne soient jamais bloqués.
Configurer votre politique
Ce que chaque agent peut faire se configure par clé API dans le hub d'agents : Clés API → sélectionner une clé → Agent. Les préréglages couvrent les cas courants ; chaque modification devient un nouveau bundle signé que vos enforcers récupèrent automatiquement.