Originally published on rohitraj.tech
Destructive Command Guard (dcg) trended on GitHub in July 2026 (Rust, MIT, 2.3k stars) as a sub-millisecond PreToolUse hook that blocks your AI coding agent from running rm -rf, git reset --hard, force pushes and DROP TABLE before they execute. It wires into Claude Code, Cursor, Codex and Copilot in one install. But Adversa AI's GuardFall research bypassed the command guards in 10 of 11 popular agents. This is the builder's read: how dcg works, how to install it, whether these guards actually hold, how dcg stacks up against agent-guardrails, Shellfirm and SigmaShake, and exactly how I'd wire real agent safety into a production workflow — guard plus sandbox, not guard alone.
Read the full version with code samples, diagrams, and architecture details: Stop Your AI Coding Agent Running rm -rf: Command Guardrails Compared (2026)
More engineering notes: rohitraj.tech/en/notes
Top comments (0)