Data gone in a second
The agent "cleans up" and deletes a folder, resets the database or drops a table.
✕ rm -rf · DROP TABLE · db reset01 Guardrails for AI coding agents
Claude Code, Cursor and Copilot can delete files, push over your work and read your secrets. Answer a few plain-English questions and get rules your agent reads and locks it can't break, so it asks before anything risky and stops instead of looping.
Auto mode is now Claude Code's default. Your deny rules still hold in it. How?
02 Sound familiar?
These happen when an agent has more access than the job needs and nobody told it where the edges are.
The agent "cleans up" and deletes a folder, resets the database or drops a table.
✕ rm -rf · DROP TABLE · db resetA secret ends up in frontend code, a commit, or the agent's chat log.
✕ Read(.env) · keys stay server-sideA force push or hard reset wipes out your work, or your teammate's.
✕ push --force · reset --hardHalf-finished code goes live because deploying was one command away.
✕ vercel --prod · firebase deployThe build goes green because the failing test was skipped, weakened or removed.
rule · never weaken a testSame error, same fix, twenty times, burning your time and your tokens.
rule · stop after 2 tries, then explain03 How it works
A markdown file is a suggestion: the agent reads it and usually follows it. A deny rule is a lock: Claude Code refuses the action, whatever the agent decides.
Your AI tool, your stack, what your app stores, and how much freedom the agent gets. Plain English, about two minutes.
Short, specific files built only from what you picked. Nothing generic, nothing you don't need.
Download a ZIP, unzip it into your project, and follow the checklist. Test any lock right here first.
CLAUDE.md or AGENTS.md, plus short topic files. Kept short on purpose, because long instruction files get ignored.
## Ask me first - Installing or upgrading packages - Creating or applying database migrations ## When something fails - Same error after 2 attempts: stop and explain
For Claude Code: a .claude/settings.json with deny and ask rules. They apply in every permission mode, including auto mode.
{
"permissions": {
"deny": ["Read(.env)", "Bash(git push --force*)"],
"ask": ["Bash(git push *)", "Bash(npm install *)"]
}
}
04 The generator
Watch the protection summary update as you answer. Nothing leaves your browser.
05 Questions
The short list. The full FAQ covers setup, every AI tool, privacy and troubleshooting.
No. The questions are in plain English, "Not sure" is always a safe answer, and the download includes a step-by-step setup checklist. Tell the generator you're new to coding and the rules ask your agent to explain every change in plain English.
Claude Code gets both layers: rules and enforced locks. Cursor, GitHub Copilot, OpenAI Codex, Windsurf, Cline, Gemini CLI and Aider get an AGENTS.md rules file, plus tool-specific setup notes (checked against each tool's docs) on where to switch on their own approval settings.
The markdown tells the agent how to behave: ask first, stop looping, keep secrets out of code. The settings file makes the most dangerous actions impossible even if the agent ignores the markdown. You want both.
No. The generator is a static page: your answers are turned into files in your browser, and nothing is uploaded. There are no cookies, no analytics and no requests to other sites. If you copy the share link, your answers are in the part of the address after #, which browsers never send to a server.
Only where you want them to. In Balanced mode the agent edits code and runs your tests freely; it stops only for things like installs, pushes, migrations and deletes. Pick Sandbox for throwaway projects, or Guided if you want to approve everything.
06 Honest limits
Every safety tool has edges. Here is exactly where ours are, and what covers each gap, so you know how far to trust it.
A Bash lock matches the text the agent types. The same program started another way isn't recognised.
rm -rf distbash -c 'rm -rf dist'What helps The OS sandbox keeps every command's writes inside your project. Commit often. Works on macOS, Linux and WSL2. Not available on native Windows; use WSL2.
File locks cover the agent's own read tool. A Python or Node script that opens .env itself isn't stopped.
Read(.env)node dump-config.jsWhat helps The OS sandbox applies your .env read locks to scripts too. Works on macOS, Linux and WSL2. Not available on native Windows; use WSL2.
SQL locks look for words like DROP TABLE in a command. They miss SQL inside a file, and can block a harmless search.
psql -c "DROP TABLE users"psql -f cleanup.sqlWhat helps Backups you have tested, and reading every migration before it runs.
The markdown file is read and usually followed. Usually isn't always: the agent can still misread, forget or get things wrong.
same error twice: stop, explainusually followed, not enforcedWhat helps Read the diff before you ship. Tests that run on every change.
Cursor, Copilot, Codex, Windsurf, Cline, Gemini CLI and Aider get the rules file. What gates their commands is each tool's own approval settings.
Claude Code: rules + locksother tools: rules + their approvalsWhat helps Switch on your tool's approvals. SETUP.md shows where.
Ask locks pause and hand the decision to you. Approving on autopilot turns a checkpoint into a formality.
git push origin main"yes" without readingWhat helps Read the command, then answer. Choose Guided if you want to see everything.
Each layer covers gaps the one before it leaves open.
Not legal advice. The GDPR rules are engineering basics, not a compliance review. Lock limits are taken from Claude Code's permissions documentation.
07 Who built this
I'm a senior full-stack developer and applied-AI solutions architect in Germany. I build with AI coding agents every day, and I built this so people shipping without a senior reviewer get safe defaults from day one.
The site practises what it preaches: fully static, strict Content-Security-Policy with no inline scripts, zero third-party requests, self-hosted fonts, and every generated file covered by snapshot, property-based and end-to-end tests.