About this project
dcg (Destructive Command Guard) is a high-performance hook for AI coding agents that intercepts destructive commands before they execute, blocking them with clear explanations and safer alternatives. It protects against catastrophic operations like `git reset --hard`, `rm -rf ./src`, or `DROP TABLE users` that could destroy hours of uncommitted work.
**Supported agents:** Claude Code, Codex CLI 0.125.0+, Gemini CLI, GitHub Copilot CLI, VS Code Copilot Chat, Cursor IDE, Hermes Agent, Posit Assistant, Grok (xAI), Antigravity CLI, OpenCode, Oh My Pi, Crush, Pi, Aider (limited), and Continue (detection only).
**Key features:**
- Zero-config protection for dangerous git/filesystem commands out of the box
- 50+ modular security packs covering databases, Kubernetes, Docker, AWS/GCP/Azure, Terraform, CI/CD, secrets management, and more
- Sub-millisecond latency via SIMD-accelerated filtering
- Heredoc/inline script scanning (catches `python -c "os.remove(...)"` and embedded shell scripts)
- Smart context detection (won't block `grep "rm -rf"` but blocks `rm -rf /`)
- Rich terminal output with denial panels, rule context, and suggestions on stderr
- Agent-safe streams: machine-readable hook output on stdout, rich UI on stderr
- Native Codex support with minimal stdout JSON denial
- Graceful degradation for CI, pipes, and dumb terminals
- Scan mode for pre-commit hooks and CI integration
- Bounded failure policy with explicit review/block outcomes
- Explain mode (`dcg explain "command"`) showing why something is blocked
**Installation:** Quick install via curl script (Linux, macOS, Windows WSL) or PowerShell installer for native Windows. Auto-detects platform, downloads the right binary, and configures supported agent hooks.
**Configuration:** Uses TOML config at `~/.config/dcg/config.toml`. Packs can be enabled/disabled by category or individual pack ID. Agent-specific profiles allow different trust levels, allowlists, and pack sets per agent.
**Default protection (no config):** `core.filesystem` (dangerous recursive rm), `core.git` (destructive git commands), and `system.disk` (mkfs, dd-to-device, fdisk, etc.) are always enabled. On Windows, `windows.filesystem` and `windows.system` packs are also on by default.
**Escape hatches:** `DCG_BYPASS=1` env var for single-command bypass, `dcg allow-once <code>` for one-time approval, permanent allowlist entries, or removing the hook entirely.
**Origins:** Started as a Python script by Jeffrey Emanuel, ported to Rust by Darin Gordon with performance optimizations, then substantially expanded with the modular pack system, heredoc scanning, three-tier architecture, context classification, allowlists, scan mode, and dual regex engine.
**Pack categories include:** storage (S3, GCS, MinIO, Azure Blob), remote (rsync, scp, ssh), database (PostgreSQL, MySQL, MongoDB, Redis, SQLite, Snowflake, Supabase, Databricks, BigQuery), containers (Docker, Compose, Podman), Kubernetes (kubectl, helm, kustomize), cloud (AWS, Azure, GCP), CDN (Cloudflare Workers, CloudFront, Fastly), API gateway (Apigee, AWS, Kong), infrastructure (Ansible, Atmos, Pulumi, Terraform), system (disk, permissions, services), CI/CD (CircleCI, GitHub Actions, GitLab CI, Jenkins), and secrets management (AWS Secrets, Doppler, Infisical, 1Password, Vault, plus opt-in secret_disclosure pack).
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.