Guardrails for coding agents, across the parts of a stack where a mistake is not recoverable by editing a file.
failproofai policies add chhhee10/stack-guard22 policies in five categories, 20 on by default. Requires failproofai.
| Category | Policies | On by default |
|---|---|---|
| Secrets | 4 | 4 |
| Git | 6 | 5 |
| Database | 4 | 4 |
| Infra | 4 | 4 |
| Supply Chain | 4 | 3 |
failproofai policies show chhhee10/stack-guardThat reads the manifest only — the code is never downloaded, so looking at a pack cannot run a pack.
failproofai policies add chhhee10/stack-guard # the defaults
failproofai policies add chhhee10/stack-guard --category Secrets,Git
failproofai policies add chhhee10/stack-guard --policy block-force-push
failproofai policies add chhhee10/stack-guard --allScope it to particular agents — it guards all twelve otherwise:
failproofai policies add chhhee10/stack-guard --cli claude codexblock-credential-file-read— Block reading ~/.aws/credentials, SSH private keys, kubeconfig, .npmrc and friendsblock-secret-exfil— Block piping a credential file into curl, wget or netcatblock-live-key-in-source— Block writing a real-looking API key or private key into a fileblock-dotenv-commit— Block git add / git commit of a .env file
block-force-push— Block git push --force on any branchblock-force-push— Block git push --force and --force-with-lease on any branchblock-push-to-protected— Block pushing straight to main, master, prod or releaseblock-history-rewrite— Block filter-branch, filter-repo and interactive rebase of pushed commitsblock-destructive-clean— Block git clean -fdx and checkout that discards uncommitted workrequire-branch-before-commit(opt-in) — Warn when committing while HEAD is on a protected branch
block-drop-object— Block DROP TABLE, DROP DATABASE and DROP SCHEMAblock-truncate— Block TRUNCATE on any tableblock-unqualified-write— Block DELETE or UPDATE with no WHERE clauseblock-prod-db-connect— Block psql, mysql and mongosh against a production-looking host
block-terraform-destroy— Block terraform destroy and unattended terraform applyblock-k8s-destructive— Block kubectl delete and cluster-wide apply against a prod contextblock-container-prune— Block docker system prune and volume removalblock-cloud-delete— Block recursive S3 deletes, bucket removal and cloud resource deletion
block-curl-pipe-shell— Block curl | sh and wget | bash install one-linersblock-package-publish— Block npm publish, cargo publish, twine upload and gem pushblock-install-from-url— Block installing dependencies from a raw URL or git remoteblock-lockfile-bypass(opt-in) — Block --force and --no-verify flags that skip a safety check
A policy that denies everything is not a policy. These are all allowed:
git push origin feature/x— onlymain,master,prodandreleaseare blockedpsql localhost— only production-looking hostsDELETE FROM sessions WHERE id = 4— only unqualified writesdocker rm my-container— onlypruneand volume removal
Every policy here is a string match on a command, not a sandbox. An agent that wants around one can get around it. The job is to stop a plausible-looking command running because nobody was watching that turn.
git clone https://github.com/chhhee10/stack-guard && cd stack-guard
failproofai policies -i -c ./git.mjs # enforce that file here, right nowAsk your agent to force-push and watch it get refused. Nothing is published and nobody else is affected.
failproofai publish --dry-run # build and validate, publish nothing
failproofai publish # ship it; the version counts itselfMIT.