destructive_command_guard

The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.

71 articles 3.8k View on GitHub ↗
71 articles
How dcg Handles Windows-Specific Commands and PowerShell Scripts

Discover how Destructive Command Guard enforces safety on Windows. Learn about its handling of PowerShell scripts, Windows commands, and path normalization for secure execution.

how-to-guide
Jul 22, 2026
How the Fallback Scanner Works When Heredoc Parsing Fails in Destructive Command Guard

Learn how the fallback scanner secures your commands by masking heredocs when parsing fails in destructive_command_guard, guaranteeing zero false negatives without over-masking.

internals
Jul 22, 2026
How to Debug Why a Command Is Being Incorrectly Blocked or Allowed in Destructive Command Guard

Debug incorrect command blocks or allows in Destructive Command Guard with the dcg explain command. Get a detailed decision trace to pinpoint blocking triggers.

how-to-guide
Jul 22, 2026
How the Normalize Module Strips Paths from Git and RM Binaries in Destructive Command Guard

Discover how the normalize module strips paths from git and rm binaries at Destructive Command Guard. Learn how regex patterns ensure accurate destructive command matching.

deep-dive
Jul 22, 2026
How to Integrate dcg with MCP Servers: Using the Built-In Model Context Protocol

Learn to integrate dcg with MCP servers easily. Run the dcg mcp-server sub-command to expose essential tools via stdio using rust-mcp-sdk. Streamline your workflow today.

how-to-guide
Jul 22, 2026
How Destructive Command Guard Prevents Malicious Repository Configs from Weakening Protection

Discover how Destructive Command Guard's layered trust model prevents malicious repository configs from weakening protection with strict size limits, symlink validation, and policy restrictions.

how-to-guide
Jul 22, 2026
How AST-Based Pattern Matching Works for Embedded Scripts in Heredocs

Learn how AST-based pattern matching in destructive_command_guard uses ast-grep to parse heredoc scripts, distinguishing code from literals for accurate destructive command detection.

deep-dive
Jul 22, 2026
Performance Budget for Hook Evaluation and Deadline Exhaustion in Destructive Command Guard

Discover the 200ms performance budget for hook evaluation in Destructive Command Guard. Learn how deadline exhaustion prevents unsafe commands from executing silently.

performance
Jul 22, 2026
How dcg Detects and Handles Different AI Agent Protocols: Claude, Codex, Gemini, and More

Discover how dcg detects and handles AI agent protocols like Claude, Codex, and Gemini. Learn how this PreToolUse hook inspects JSON, env vars, and provides specific denial responses.

internals
Jul 22, 2026
How the DCG Allow-Once Short Code System Works: Security and Implementation

Discover how the allow-once short code system from Dicklesworthstone/destructive_command_guard secures command execution with temporary permits and SHA-256 hashes, preventing replay attacks.

internals
Jul 22, 2026
How to Create Custom Security Packs Using YAML Files in Destructive Command Guard

Learn to create custom security packs in Destructive Command Guard using YAML files. Extend DCG functionality easily without recompilation.

how-to-guide
Jul 22, 2026
How the Bounded Failure Policy Handles Timeouts and Parse Errors in Destructive Command Guard

Learn how the bounded failure policy in Destructive Command Guard handles timeouts and parse errors. It ensures safe command execution by aborting analysis and emitting deterministic rule IDs for confident verification.

deep-dive
Jul 22, 2026

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →