</>MCP Agents Market
Plugin

destructive_command_guard

by Dicklesworthstone5.8kRustUpdated 2026-08-25

The Destructive Command Guard (dcg) is for blocking dangerous git and shell commands from being executed by agents.

Claude CodeCodex CLIGitHub Copilot CLIVS Code Copilot ChatCursorGemini CLI

Destructive Command Guard (dcg) is a high-performance Claude Code plugin that blocks dangerous shell and git commands before AI agents execute them, protecting against accidental data loss. It intercepts commands like `git reset --hard`, `rm -rf`, and database drops through PreToolUse hooks, providing sub-millisecond pattern matching with SIMD acceleration. The plugin includes 50+ security packs covering git, filesystems, databases, containers, cloud platforms, and CI/CD tools, with context-aware scanning that distinguishes executable code from data in comments or heredocs.

Key Features

Zero-config protection blocking catastrophic git/filesystem commands out of the box with core.git and core.filesystem packs
50+ modular security packs covering databases (PostgreSQL, MySQL, MongoDB), cloud platforms (AWS, GCP, Azure), containers (Docker, Kubernetes), and CI/CD tools
Sub-millisecond SIMD-accelerated pattern matching with dual regex engine (O(n) linear + backtracking for lookahead)
Heredoc and inline-script scanning with three-tier AST-based analysis for embedded code in bash -c, python -c, and similar constructs
Smart context classification that won't block 'grep "rm -rf"' (data) but will block actual rm -rf execution
Multi-agent support for Claude Code, Codex CLI, Gemini CLI, GitHub Copilot CLI, VS Code Copilot Chat, Cursor, Hermes, Posit Assistant, Oh My Pi, OpenCode, Crush, and Grok
Actionable denial messages with safer alternatives, repository scanning for CI/CD, and allowlist system for intentional exceptions
Bounded failure policy with explicit indeterminate results and configurable evaluation deadlines (1-3 second budgets) to prevent timeout-as-allow vulnerabilities

Use Cases

  • 01Prevent AI coding agents from running `git reset --hard` or `git clean -f` and destroying uncommitted work during refactoring sessions
  • 02Block accidental `rm -rf` commands targeting home directory or critical project folders when agents attempt cleanup operations
  • 03Protect production databases from destructive operations like DROP TABLE, TRUNCATE, or mass DELETE when agents suggest database migrations
  • 04Guard against force pushes and history rewrites that could overwrite shared branch commits in team repositories
  • 05Scan committed shell scripts, Dockerfiles, CI workflows, and Makefiles for destructive commands during code review and pre-commit hooks
  • 06Apply enterprise security postures like careful_company_running_windows to block data exfiltration channels (email, webhooks, file uploads) on managed workstations

Related Plugins

View more

destructive_command_guard — FAQ

What is Destructive Command Guard?+

It's a PreToolUse hook plugin for AI coding agents (Claude Code, Codex CLI, Copilot, etc.) that intercepts shell commands before execution and blocks destructive operations like git reset --hard, rm -rf, and database drops. It runs locally on your machine with sub-millisecond latency.

How do I install dcg for Claude Code?+

Run the one-line installer: `curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.sh?$(date +%s)" | bash -s -- --easy-mode`. On Windows, use the PowerShell installer. The script downloads the binary, configures hooks for detected agents, and updates your PATH. Restart Claude Code after installation.

Which AI clients does dcg work with?+

It natively supports Claude Code, Codex CLI (0.125.0+), Gemini CLI, GitHub Copilot CLI, VS Code Copilot Chat, Cursor IDE, Hermes Agent, Posit Assistant, Oh My Pi, OpenCode, Crush, and Grok (xAI). Aider and Continue have limited support (git hooks only). The same binary works across all clients through protocol-specific adapters.

Does dcg require API keys or send data anywhere?+

No API keys or network access required. dcg runs entirely locally as a hook subprocess, evaluates commands using offline regex patterns, and never transmits your code or commands. All decisions happen on your machine within 1-3 milliseconds.

Is dcg free and open source?+

Yes, it's free to use with a custom MIT-based license (includes an OpenAI/Anthropic rider). Source code is available on GitHub with prebuilt binaries for Linux (x64/ARM64), macOS (Intel/Apple Silicon), and Windows (x64/ARM64).

What do I do if dcg blocks a command I need to run?+

Use the temporary bypass `DCG_BYPASS=1 <command>`, or run `dcg allow-once <code>` with the short code from the block message for a 24-hour exception. For permanent exceptions, add the rule or command to your allowlist with `dcg allowlist add core.git:reset-hard -r "reason"`. The block message always shows the exact allowlist command to run.

How do I install destructive_command_guard?+

Open the source repository on GitHub and follow its README. destructive_command_guard is a plugin — MCP Agents Market links you directly to the official repo.

Is destructive_command_guard free?+

destructive_command_guard is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.

Related searches