Agent Trust Levels in Destructive Command Guard: How They Affect Rule Evaluation

Agent trust levels in Destructive Command Guard determine whether the evaluator applies permissive whitelisting, standard two-step validation, or restrictive cautious filtering when resolving conflicts between safe and destructive command patterns.

In Dicklesworthstone/destructive_command_guard (dcg), every calling entity—whether a CI job, a local shell script, or an interactive user—is modeled as an agent with an assigned trust tier. This classification, stored in the agent's profile and defined in src/agent.rs, directly governs how the rule evaluation engine in src/evaluator.rs validates incoming commands.

Understanding the TrustLevel Enum and Agent Profiles

The foundation of the trust system resides in src/agent.rs (lines 3110–3195), where the TrustLevel enum and AgentProfile struct are defined. Each agent profile maps to one of three distinct trust variants:

  • High – Reserved for proven, internal agents (e.g., the dcg binary itself or hardened CI pipelines).
  • Medium – The default classification for most external agents.
  • Low – Assigned to unknown or potentially hostile sources (e.g., unverified third-party scripts).

The evaluator retrieves an agent’s effective trust level via the trust_level_for helper method (implemented at lines 3189–3192 in src/agent.rs), which returns the enum variant used during rule resolution.

How Trust Levels Modify Rule Evaluation

The core decision logic lives in src/evaluator.rs (around line 17376), where the engine calls self.trust_level_for(agent_key) to determine which validation path to execute. The trust level dictates precedence when a command matches both a safe pattern and a destructive pattern.

High Trust Agents

Agents classified as High trust follow a permissive evaluation flow. The engine applies the full whitelist of safe patterns first; if the command matches, the evaluator allows execution immediately, effectively bypassing certain destructive-pattern checks that would block lower-trust agents. This enables high-confidence automation to run without false positives on benign but complex commands.

Medium Trust Agents

Medium trust triggers the standard two-step flow: quick-reject heuristics, followed by the safe-pattern whitelist, then the destructive-pattern blacklist, and finally a default-allow fallback. This level provides balanced security—commands matching destructive patterns are denied, and no special exceptions are granted.

Low Trust Agents

For Low trust agents, the engine inserts an extra cautious filter before the normal whitelist evaluation. Even commands that would be considered safe at Medium trust are blocked if they invoke potentially risky utilities, unless the user provides an explicit allow-once code. This strict mode prevents compromised or untrusted scripts from exploiting edge cases in safe-pattern definitions.

Configuration File Trust Implications

Trust extends beyond agents to configuration sources. In src/config.rs (lines 11–42), the system treats automatically discovered .dcg.toml files as untrusted by default. Unless the user explicitly opts-in by setting the DCG_CONFIG environment variable, dcg ignores local configuration files to prevent repository-level config files from elevating project trust unwittingly.

Configuring and Inspecting Agent Trust Levels

You define trust levels in an agent profile TOML and verify behavior via the CLI.

Set an agent’s trust level in .dcg/agents.toml:

[agents.my_ci_job]
trust_level = "high"  # Options: "high", "medium", "low"

Query the effective trust level for troubleshooting:

dcg agent show --agent my_ci_job

Use the explain command to see how trust level influenced a decision:

dcg explain "git reset --hard HEAD"

The JSON output includes the resolved trust_level field, showing why a command was permitted or blocked based on the agent’s classification.

Summary

  • src/agent.rs defines three agent trust levels—High, Medium, and Low—that classify agent reliability.
  • src/evaluator.rs uses trust_level_for to select evaluation logic, allowing High-trust agents to bypass destructive checks when matching safe patterns while forcing Low-trust agents through additional safety filters.
  • Medium is the default trust level, applying standard whitelist-then-blacklist validation.
  • Low trust requires explicit allow-once codes for commands that would otherwise pass at Medium trust.
  • Automatically discovered configuration files in src/config.rs are treated as untrusted unless explicitly opted-in via environment variables.

Frequently Asked Questions

What is the default trust level for new agents?

New agents default to Medium trust unless explicitly configured otherwise in .dcg/agents.toml. This ensures that unidentified callers receive the standard validation flow without overly permissive exceptions.

Can a high-trust agent execute destructive commands?

No. A High-trust agent cannot execute commands that match destructive patterns if they fail the whitelist check. However, because the evaluator checks the whitelist first for High-trust agents, benign commands that technically resemble destructive patterns (but are explicitly allowed) will pass without triggering destructive-pattern blocks.

How do I change an agent's trust level?

Modify the agent’s profile in .dcg/agents.toml and set the trust_level key to "high", "medium", or "low". Changes take effect immediately for subsequent commands without restarting the dcg daemon.

Why is my local .dcg.toml configuration being ignored?

According to src/config.rs, automatically discovered .dcg.toml files are treated as untrusted by default as a security measure. To use a local config, explicitly opt-in by setting the DCG_CONFIG=.dcg.toml environment variable before running dcg.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →