destructive_command_guard
The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.
Discover how Destructive Command Guard enforces safety on Windows. Learn about its handling of PowerShell scripts, Windows commands, and path normalization for secure execution.
How the Fallback Scanner Works When Heredoc Parsing Fails in Destructive Command GuardLearn how the fallback scanner secures your commands by masking heredocs when parsing fails in destructive_command_guard, guaranteeing zero false negatives without over-masking.
How to Debug Why a Command Is Being Incorrectly Blocked or Allowed in Destructive Command GuardDebug incorrect command blocks or allows in Destructive Command Guard with the dcg explain command. Get a detailed decision trace to pinpoint blocking triggers.
How the Normalize Module Strips Paths from Git and RM Binaries in Destructive Command GuardDiscover how the normalize module strips paths from git and rm binaries at Destructive Command Guard. Learn how regex patterns ensure accurate destructive command matching.
How to Integrate dcg with MCP Servers: Using the Built-In Model Context ProtocolLearn to integrate dcg with MCP servers easily. Run the dcg mcp-server sub-command to expose essential tools via stdio using rust-mcp-sdk. Streamline your workflow today.
How Destructive Command Guard Prevents Malicious Repository Configs from Weakening ProtectionDiscover how Destructive Command Guard's layered trust model prevents malicious repository configs from weakening protection with strict size limits, symlink validation, and policy restrictions.
How AST-Based Pattern Matching Works for Embedded Scripts in HeredocsLearn how AST-based pattern matching in destructive_command_guard uses ast-grep to parse heredoc scripts, distinguishing code from literals for accurate destructive command detection.
Performance Budget for Hook Evaluation and Deadline Exhaustion in Destructive Command GuardDiscover the 200ms performance budget for hook evaluation in Destructive Command Guard. Learn how deadline exhaustion prevents unsafe commands from executing silently.
How dcg Detects and Handles Different AI Agent Protocols: Claude, Codex, Gemini, and MoreDiscover how dcg detects and handles AI agent protocols like Claude, Codex, and Gemini. Learn how this PreToolUse hook inspects JSON, env vars, and provides specific denial responses.
How the DCG Allow-Once Short Code System Works: Security and ImplementationDiscover how the allow-once short code system from Dicklesworthstone/destructive_command_guard secures command execution with temporary permits and SHA-256 hashes, preventing replay attacks.
How to Create Custom Security Packs Using YAML Files in Destructive Command GuardLearn to create custom security packs in Destructive Command Guard using YAML files. Extend DCG functionality easily without recompilation.
How the Bounded Failure Policy Handles Timeouts and Parse Errors in Destructive Command GuardLearn how the bounded failure policy in Destructive Command Guard handles timeouts and parse errors. It ensures safe command execution by aborting analysis and emitting deterministic rule IDs for confident verification.
Have a question about this repo?
These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:
curl -s "https://instagit.com/install.md" Maintain an open-source project? Get it listed too →