Human Execution Boundary

The line a website
can't make you cross.

A fake CAPTCHA or error page pressures you into copying a "verification command" and running it on your own computer. It's a scam — that command quietly hijacks your machine. ExecFence catches the trap and warns you first.

Local-first · private · never reads or uploads your clipboard · one permission

How the scam works — and where ExecFence steps in

Every step below is normal on its own. That's why antivirus misses it. ExecFence watches the one place the chain goes wrong.

1

A fake check

A page shows a CAPTCHA, a "security check," or a broken-page error.

2

A command to run

It hands you a "verification command" and pressures you to run it yourself, outside the browser.

3

The trap

The command it put on your clipboard quietly downloads and runs someone else's program.

4

ExecFence blocks it

The instant those combine, ExecFence warns you in plain words — before anything runs.

Built to be quiet — and private

Loud only on tricks

Silent on the pages developers really copy commands from — GitHub, Homebrew, package managers. It only speaks up when a page is trying to fool you.

Explains itself

Every warning tells you what the page asked and what the command would actually do — reach the internet? download a program? run it? — in plain English.

Private by design

Everything is checked on your own computer. It never reads your system clipboard and never uploads what you copy. One permission, no browsing history.

You stay in control

Clear the tricked clipboard, close the tab, inspect the command, or continue anyway. ExecFence warns — it never locks you out.

See it work, right now

Install ExecFence (developer mode — no store needed), then open the safe demo. It's a harmless copy of a real scam page: the moment you copy the command, ExecFence throws the warning. Everything on it is inert and points only at addresses that don't exist.

▶ Open the live demo