How real rigs stop agents from deleting prod
Data: 6974 public rigs · updated 2026-10-09
In 2026 several teams learned the hard way that a coding agent with a broad token and no confirmation step can wipe a production database. So we checked what people actually commit to their agent configs.
9%block destructive cmds
4%deny reading secrets
10%use a PreToolUse hook
287 rigs (4%) explicitly run in YOLO mode — bypassPermissions, a blanket Bash(*) allow, or Codex with danger-full-access.
Guardrail score distribution
| 0/5 | 5106 | |
| 1/5 | 943 | |
| 2/5 | 366 | |
| 3/5 | 365 | |
| 4/5 | 156 | |
| 5/5 | 38 |
The most common deny rules
| rule | rigs |
|---|---|
| Read(./.env) | 84 |
| Read(**/.env) | 83 |
| Read(~/.ssh/**) | 79 |
| Bash(rm -rf *) | 73 |
| Read(**/*.pem) | 67 |
| Bash(rm -rf /) | 67 |
| Bash(git push --force:*) | 67 |
| Bash(sudo *) | 64 |
| Read(~/.aws/**) | 62 |
| Bash(rm -rf /*) | 62 |
| Read(./.env.*) | 61 |
| Read(.env) | 60 |
| Bash(git push --force*) | 60 |
| Bash(rm -rf:*) | 58 |
| Read(**/.env.*) | 57 |
Copy-paste community baseline
The destructive-command and secret-file rules that appear in 2+ rigs. Merge into .claude/settings.json:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(~/.aws/**)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(.env)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/.env.*)",
"Read(**/*.key)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(npm publish:*)",
"Bash(wget *)",
"Bash(git rebase *)",
"Bash(gh pr merge *)",
"Bash(git commit *)"
]
}
} Deny rules are pattern-based and can be bypassed by creative shell; pair them with a sandbox and a scoped token. Most useful on top of — not instead of — least-privilege credentials.
Fort Knox rigs to learn from
ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
Fort Knox 0 tok ·
happier-dev/happier
Web, Desktop & Mobile client and orchestrator for Codex, Claude Code, OpenCode, Pi, Cursor, Grok, Antigravity, Kimi, Augment Code, Qwen, fully end-to-end encrypted
Fort Knox 28.4k tok ·
feiskyer/claude-code-settings
Curated skills, sub-agents, and config templates that supercharge Claude Code — research, image gen, GitHub automation & more.
Fort Knox 11.1k tok ·