~ / guides / guardrails

How real rigs stop agents from deleting prod

Data: 6974 public rigs · updated 2026-10-09

In 2026 several teams learned the hard way that a coding agent with a broad token and no confirmation step can wipe a production database. So we checked what people actually commit to their agent configs.

9%block destructive cmds
4%deny reading secrets
10%use a PreToolUse hook

287 rigs (4%) explicitly run in YOLO mode — bypassPermissions, a blanket Bash(*) allow, or Codex with danger-full-access.

Guardrail score distribution

0/5
5106
1/5
943
2/5
366
3/5
365
4/5
156
5/5
38

The most common deny rules

rulerigs
Read(./.env)84
Read(**/.env)83
Read(~/.ssh/**)79
Bash(rm -rf *)73
Read(**/*.pem)67
Bash(rm -rf /)67
Bash(git push --force:*)67
Bash(sudo *)64
Read(~/.aws/**)62
Bash(rm -rf /*)62
Read(./.env.*)61
Read(.env)60
Bash(git push --force*)60
Bash(rm -rf:*)58
Read(**/.env.*)57

Copy-paste community baseline

The destructive-command and secret-file rules that appear in 2+ rigs. Merge into .claude/settings.json:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(**/.env)",
      "Read(~/.ssh/**)",
      "Bash(rm -rf *)",
      "Read(**/*.pem)",
      "Bash(rm -rf /)",
      "Bash(git push --force:*)",
      "Bash(sudo *)",
      "Read(~/.aws/**)",
      "Bash(rm -rf /*)",
      "Read(./.env.*)",
      "Read(.env)",
      "Bash(git push --force*)",
      "Bash(rm -rf:*)",
      "Read(**/.env.*)",
      "Read(**/*.key)",
      "Bash(sudo:*)",
      "Bash(git reset --hard*)",
      "Bash(git reset --hard:*)",
      "Read(.env.*)"
    ],
    "ask": [
      "Bash(git push:*)",
      "Bash(git push *)",
      "Bash(git commit:*)",
      "Bash(rm *)",
      "Bash(rm:*)",
      "Bash(npm publish:*)",
      "Bash(wget *)",
      "Bash(git rebase *)",
      "Bash(gh pr merge *)",
      "Bash(git commit *)"
    ]
  }
}

Deny rules are pattern-based and can be bypassed by creative shell; pair them with a sandbox and a scoped token. Most useful on top of — not instead of — least-privilege credentials.

Fort Knox rigs to learn from

ruvnet/ruflo
🌊 The original agent harness. Deploy intelligent multi-player swarms, coordinate autonomous workflows, and build conversational AI systems. Features adaptive memory, self-learning intelligence, federation, vector RAG integration, and native
★ 74.1k project Claude CodeCodex 5 mcp 136 skills 80 agents 20 hooks 1d ago
Fort Knox 35.3k tok ·
Donchitos/Claude-Code-Game-Studios
Turn Claude Code into a full game dev studio — 49 AI agents, 72 workflow skills, and a complete coordination system mirroring real studio hierarchy.
★ 25.9k project Claude Code 73 skills 49 agents 12 hooks 1d ago
Fort Knox 11.6k tok ·
FlorianBruniaux/claude-code-ultimate-guide
The most comprehensive Claude Code guide: agentic workflows, hooks, skills, MCP servers, quizzes, and production-ready templates. 430K+ lines.
★ 6,094 project Claude CodeCodexCopilot 8 mcp 80 skills 6 agents 9 hooks 6d ago
Fort Knox 33.8k tok ·
trailofbits/claude-code-config
Opinionated defaults, documentation, and workflows for Claude Code at Trail of Bits
★ 2,120 setup Claude Code 2 hooks 2mo ago
Fort Knox 0 tok ·
happier-dev/happier
Web, Desktop & Mobile client and orchestrator for Codex, Claude Code, OpenCode, Pi, Cursor, Grok, Antigravity, Kimi, Augment Code, Qwen, fully end-to-end encrypted
★ 1,856 project Claude CodeCodexCursor 3 mcp 27 skills 8 agents 2 hooks 5d ago
Fort Knox 28.4k tok ·
feiskyer/claude-code-settings
Curated skills, sub-agents, and config templates that supercharge Claude Code — research, image gen, GitHub automation & more.
★ 1,659 setup Claude CodeCopilot 1 mcp 12 skills 6 agents 12d ago
Fort Knox 11.1k tok ·

All rigs with 4+/5 →

copied ✓