gixt executes code from gists. Trust is trust-on-first-use (TOFU) keyed by commit: the currently approved revision does not re-prompt, while a changed revision does. There is no “trust my own gists always” special case.
Approvals are stored in trust.json under your gixt config directory.
sha) you’re running was approved before, gixt runs it without prompting.y records that commit as trusted.-y / --yes skips the prompt for a single run without persisting trust.Running your own gists still prompts on first use or after a change. To take an explicit snapshot of all gists you currently own:
gixt auth login # required once
gixt trust mine # fetch and approve every exact current commit
The snapshot includes public and secret gists, and the trust store is saved only after every revision is fetched. Progress is reported on stderr as revisions complete. Revision requests use at most three workers and honor GitHub rate-limit delays; a failed snapshot leaves the existing trust store unchanged. A gist changed after the snapshot has a different commit and prompts again. Taking another snapshot replaces the previously approved commit for each gist.
Managing approvals:
gixt trust list — show approved gists and commits (the “why am I being prompted again?” tool).gixt trust remove <target> — revoke one approval.gixt trust clear — revoke everything.When stdin is not a terminal (pipes, scripts, CI), gixt refuses to prompt and exits with:
error: refusing to prompt on non-interactive input; pass -y to run untrusted code
gixt run --view <target> prints the gist files without executing or changing trust.gixt run --dry-run <target> shows the command without executing or changing trust.gixt gist show <target> shows metadata and the file list.gixt trust clear revokes every approval.gixt trust remove <target> revokes one.trust.json from the config directory also resets everything.