Skip to content

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 

Repository files navigation

stack-guard

Guardrails for coding agents, across the parts of a stack where a mistake is not recoverable by editing a file.

failproofai policies add chhhee10/stack-guard

22 policies in five categories, 20 on by default. Requires failproofai.

Category Policies On by default
Secrets 4 4
Git 6 5
Database 4 4
Infra 4 4
Supply Chain 4 3

Look before you install

failproofai policies show chhhee10/stack-guard

That reads the manifest only — the code is never downloaded, so looking at a pack cannot run a pack.

Take part of it

failproofai policies add chhhee10/stack-guard                        # the defaults
failproofai policies add chhhee10/stack-guard --category Secrets,Git
failproofai policies add chhhee10/stack-guard --policy block-force-push
failproofai policies add chhhee10/stack-guard --all

Scope it to particular agents — it guards all twelve otherwise:

failproofai policies add chhhee10/stack-guard --cli claude codex

What is in it

Secrets

  • block-credential-file-read — Block reading ~/.aws/credentials, SSH private keys, kubeconfig, .npmrc and friends
  • block-secret-exfil — Block piping a credential file into curl, wget or netcat
  • block-live-key-in-source — Block writing a real-looking API key or private key into a file
  • block-dotenv-commit — Block git add / git commit of a .env file

Git

  • block-force-push — Block git push --force on any branch
  • block-force-push — Block git push --force and --force-with-lease on any branch
  • block-push-to-protected — Block pushing straight to main, master, prod or release
  • block-history-rewrite — Block filter-branch, filter-repo and interactive rebase of pushed commits
  • block-destructive-clean — Block git clean -fdx and checkout that discards uncommitted work
  • require-branch-before-commit (opt-in) — Warn when committing while HEAD is on a protected branch

Database

  • block-drop-object — Block DROP TABLE, DROP DATABASE and DROP SCHEMA
  • block-truncate — Block TRUNCATE on any table
  • block-unqualified-write — Block DELETE or UPDATE with no WHERE clause
  • block-prod-db-connect — Block psql, mysql and mongosh against a production-looking host

Infra

  • block-terraform-destroy — Block terraform destroy and unattended terraform apply
  • block-k8s-destructive — Block kubectl delete and cluster-wide apply against a prod context
  • block-container-prune — Block docker system prune and volume removal
  • block-cloud-delete — Block recursive S3 deletes, bucket removal and cloud resource deletion

Supply Chain

  • block-curl-pipe-shell — Block curl | sh and wget | bash install one-liners
  • block-package-publish — Block npm publish, cargo publish, twine upload and gem push
  • block-install-from-url — Block installing dependencies from a raw URL or git remote
  • block-lockfile-bypass (opt-in) — Block --force and --no-verify flags that skip a safety check

The near-misses are the point

A policy that denies everything is not a policy. These are all allowed:

  • git push origin feature/x — only main, master, prod and release are blocked
  • psql localhost — only production-looking hosts
  • DELETE FROM sessions WHERE id = 4 — only unqualified writes
  • docker rm my-container — only prune and volume removal

What it does not do

Every policy here is a string match on a command, not a sandbox. An agent that wants around one can get around it. The job is to stop a plausible-looking command running because nobody was watching that turn.

Editing them

git clone https://github.com/chhhee10/stack-guard && cd stack-guard
failproofai policies -i -c ./git.mjs      # enforce that file here, right now

Ask your agent to force-push and watch it get refused. Nothing is published and nobody else is affected.

failproofai publish --dry-run             # build and validate, publish nothing
failproofai publish                       # ship it; the version counts itself

Licence

MIT.

About

failproofai policy pack — 22 guardrails across secrets, git, database, infra and supply chain. Install: failproofai policies add chhhee10/stack-guard

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors