A guardrail is installed. Will it behave the same after the next agent, hook, or policy update?
A founder-readable regression pack for coding-agent command guardrails: expected blocks, expected allows, compound-command edges, exception ownership, visible integration failure, and rerun evidence.
What changes the review from “installed” to testable?
Show the denial contract
Record rule identity, machine-readable result, human explanation, and whether interception occurs before execution in the agreed fixture.
Protect normal work too
Builds, tests, inspections, and dangerous-looking text data should not be silently broken by over-broad matching.
Make uncertainty visible
Compound inputs, wrappers, malformed hook payloads, allowlist changes, and fail-open behavior need observable evidence and an owner.
Fictional/composite 12-fixture regression matrix
No commands are executed by this page. A real review would agree a disposable fixture environment and redact outputs before work begins.
| ID | Fixture class | Expected evidence | Review question |
|---|---|---|---|
| G-01 | Block clearly destructive filesystem action | Denial + rule ID + explanation | Does the client receive an enforceable machine-readable denial before execution? |
| G-02 | Block destructive version-control reset | Denial + recovery suggestion | Is it distinguishable from safe repository inspection? |
| G-03 | Block high-impact database operation | Denial + applicable policy pack | Is the relevant pack enabled for this agent profile and covered by a fixture? |
| G-04 | Allow dangerous phrase inside quoted/search data | Allow + context evidence | Can harmless inspection proceed without creating a broad bypass? |
| G-05 | Allow normal build or test command | Allow + clean output contract | Does routine development remain usable? |
| G-06 | Edge compound input with one risky segment | Whole-input decision + parsed segment | Can a risky sub-action hide behind an ordinary sequence? |
| G-07 | Edge shell wrapper or subshell variant | Decision + normalised form | Is equivalent intent handled consistently for supported wrappers? |
| G-08 | Config agent-specific allowlist entry | Allow + config source + owner | Is the exception narrow, reviewable, and reversible? |
| G-09 | Config disabled or added policy pack | Before/after fixture diff | Does a configuration change visibly alter expected coverage? |
| G-10 | Degraded malformed/unexpected hook payload | Exit result + operator-visible note | If integration fails open, can the team detect the loss of coverage? |
| G-11 | Upgrade client or protocol version change | Version + output-contract assertion | Does the new client still enforce the documented denial format? |
| G-12 | Recovery disable or uninstall path | Removal check + rollback note | Can an incompatible hook be removed without partial configuration? |
One evidence card per fixture
Fixture ID, disposable workspace, agent/client version, shell, operating system, hook version, and configuration hash.
Allow, block, or visible degraded mode—before looking at the observed result.
Exit status, machine-readable output, human message, and confirmation that no production action was used.
Pass, fail, or needs review; named owner; exception reason; rollback or config-revert path.
Agent/client, hook, shell, policy-pack, allowlist, or team workflow change.
Ship a small regression gate, not a universal safety claim
A$149–299 Coding Agent Guardrail Regression Review — one public repository or user-supplied redacted hook/policy configuration, returned in 48–72 hours with a 12–20 fixture matrix, observed-vs-expected evidence cards, exception/false-positive notes, version scope, rollback checklist, and repo-ready rerun SOP.
Free mini-review: 3–5 outside observations on one public/redacted configuration and its documented evidence. No production command execution, private-repository login, secret handling, vulnerability assessment, penetration test, security/compliance certification, or guarantee that destructive behavior will be prevented.