Public sample • workflow regression review, not a security certification

A guardrail is installed. Will it behave the same after the next agent, hook, or policy update?

A founder-readable regression pack for coding-agent command guardrails: expected blocks, expected allows, compound-command edges, exception ownership, visible integration failure, and rerun evidence.

12–20agreed allow/block/edge fixtures in a paid review
A$149–299one public repo or supplied redacted configuration
48–72hmatrix, evidence cards, exceptions, rerun and rollback notes

What changes the review from “installed” to testable?

Expected block

Show the denial contract

Record rule identity, machine-readable result, human explanation, and whether interception occurs before execution in the agreed fixture.

Expected allow

Protect normal work too

Builds, tests, inspections, and dangerous-looking text data should not be silently broken by over-broad matching.

Edge and degraded mode

Make uncertainty visible

Compound inputs, wrappers, malformed hook payloads, allowlist changes, and fail-open behavior need observable evidence and an owner.

Public source signal: destructive_command_guard publicly documents pre-execution hooks across multiple coding-agent clients, context-aware allow/block behavior, agent-specific allowlists and packs, machine-readable output, CI scan mode, fail-open behavior, and protocol/E2E testing. This page turns that category signal into a generic LaunchReady review format; it is not an assessment or endorsement of that project.

Fictional/composite 12-fixture regression matrix

No commands are executed by this page. A real review would agree a disposable fixture environment and redact outputs before work begins.

IDFixture classExpected evidenceReview question
G-01Block clearly destructive filesystem actionDenial + rule ID + explanationDoes the client receive an enforceable machine-readable denial before execution?
G-02Block destructive version-control resetDenial + recovery suggestionIs it distinguishable from safe repository inspection?
G-03Block high-impact database operationDenial + applicable policy packIs the relevant pack enabled for this agent profile and covered by a fixture?
G-04Allow dangerous phrase inside quoted/search dataAllow + context evidenceCan harmless inspection proceed without creating a broad bypass?
G-05Allow normal build or test commandAllow + clean output contractDoes routine development remain usable?
G-06Edge compound input with one risky segmentWhole-input decision + parsed segmentCan a risky sub-action hide behind an ordinary sequence?
G-07Edge shell wrapper or subshell variantDecision + normalised formIs equivalent intent handled consistently for supported wrappers?
G-08Config agent-specific allowlist entryAllow + config source + ownerIs the exception narrow, reviewable, and reversible?
G-09Config disabled or added policy packBefore/after fixture diffDoes a configuration change visibly alter expected coverage?
G-10Degraded malformed/unexpected hook payloadExit result + operator-visible noteIf integration fails open, can the team detect the loss of coverage?
G-11Upgrade client or protocol version changeVersion + output-contract assertionDoes the new client still enforce the documented denial format?
G-12Recovery disable or uninstall pathRemoval check + rollback noteCan an incompatible hook be removed without partial configuration?

One evidence card per fixture

Scope the environment.
Fixture ID, disposable workspace, agent/client version, shell, operating system, hook version, and configuration hash.
State the expectation first.
Allow, block, or visible degraded mode—before looking at the observed result.
Capture redacted evidence.
Exit status, machine-readable output, human message, and confirmation that no production action was used.
Assign the difference.
Pass, fail, or needs review; named owner; exception reason; rollback or config-revert path.
Set the rerun trigger.
Agent/client, hook, shell, policy-pack, allowlist, or team workflow change.

Ship a small regression gate, not a universal safety claim

A$149–299 Coding Agent Guardrail Regression Review — one public repository or user-supplied redacted hook/policy configuration, returned in 48–72 hours with a 12–20 fixture matrix, observed-vs-expected evidence cards, exception/false-positive notes, version scope, rollback checklist, and repo-ready rerun SOP.

Free mini-review: 3–5 outside observations on one public/redacted configuration and its documented evidence. No production command execution, private-repository login, secret handling, vulnerability assessment, penetration test, security/compliance certification, or guarantee that destructive behavior will be prevented.