01 Guardrails for AI coding agents

Your AI agent has more access than it needs.

Claude Code, Cursor and Copilot can delete files, push over your work and read your secrets. Answer a few plain-English questions and get rules your agent reads and locks it can't break, so it asks before anything risky and stops instead of looping.

Auto mode is now Claude Code's default. Your deny rules still hold in it. How?

  • Free
  • No sign-up
  • No tracking
  • Runs in your browser

02 Sound familiar?

AI agents are fast. Mistakes are too.

These happen when an agent has more access than the job needs and nobody told it where the edges are.

Data gone in a second

The agent "cleans up" and deletes a folder, resets the database or drops a table.

✕ rm -rf · DROP TABLE · db reset

Keys on the internet

A secret ends up in frontend code, a commit, or the agent's chat log.

✕ Read(.env) · keys stay server-side

History rewritten

A force push or hard reset wipes out your work, or your teammate's.

✕ push --force · reset --hard

Surprise production deploy

Half-finished code goes live because deploying was one command away.

✕ vercel --prod · firebase deploy

Tests "fixed" by deleting them

The build goes green because the failing test was skipped, weakened or removed.

rule · never weaken a test

Stuck in a loop

Same error, same fix, twenty times, burning your time and your tokens.

rule · stop after 2 tries, then explain

03 How it works

Two layers. One is a lock.

A markdown file is a suggestion: the agent reads it and usually follows it. A deny rule is a lock: Claude Code refuses the action, whatever the agent decides.

  1. Answer a few questions

    Your AI tool, your stack, what your app stores, and how much freedom the agent gets. Plain English, about two minutes.

  2. Get rules and locks

    Short, specific files built only from what you picked. Nothing generic, nothing you don't need.

  3. Drop them in your repo

    Download a ZIP, unzip it into your project, and follow the checklist. Test any lock right here first.

Layer 1 · Rules

What the agent should do

CLAUDE.md or AGENTS.md, plus short topic files. Kept short on purpose, because long instruction files get ignored.

## Ask me first
- Installing or upgrading packages
- Creating or applying database migrations

## When something fails
- Same error after 2 attempts: stop and explain
Layer 2 · Locks

What it simply can't do

For Claude Code: a .claude/settings.json with deny and ask rules. They apply in every permission mode, including auto mode.

{
  "permissions": {
    "deny": ["Read(.env)", "Bash(git push --force*)"],
    "ask":  ["Bash(git push *)", "Bash(npm install *)"]
  }
}

04 The generator

Build your agent's house rules.

Watch the protection summary update as you answer. Nothing leaves your browser.

05 Questions

Good questions, straight answers.

The short list. The full FAQ covers setup, every AI tool, privacy and troubleshooting.

Do I need to be a developer to use this?

No. The questions are in plain English, "Not sure" is always a safe answer, and the download includes a step-by-step setup checklist. Tell the generator you're new to coding and the rules ask your agent to explain every change in plain English.

Which AI tools does it work with?

Claude Code gets both layers: rules and enforced locks. Cursor, GitHub Copilot, OpenAI Codex, Windsurf, Cline, Gemini CLI and Aider get an AGENTS.md rules file, plus tool-specific setup notes (checked against each tool's docs) on where to switch on their own approval settings.

Why both a markdown file and a settings file?

The markdown tells the agent how to behave: ask first, stop looping, keep secrets out of code. The settings file makes the most dangerous actions impossible even if the agent ignores the markdown. You want both.

Do you see my answers or my code?

No. The generator is a static page: your answers are turned into files in your browser, and nothing is uploaded. There are no cookies, no analytics and no requests to other sites. If you copy the share link, your answers are in the part of the address after #, which browsers never send to a server.

Will the locks slow my agent down?

Only where you want them to. In Balanced mode the agent edits code and runs your tests freely; it stops only for things like installs, pushes, migrations and deletes. Pick Sandbox for throwaway projects, or Guided if you want to approve everything.

See all questions

06 Honest limits

Reduces risk. Not a guarantee.

Every safety tool has edges. Here is exactly where ours are, and what covers each gap, so you know how far to trust it.

Locks read the command, not the intent

A Bash lock matches the text the agent types. The same program started another way isn't recognised.

  • Stopped:rm -rf dist
  • Slips past:bash -c 'rm -rf dist'

What helps The OS sandbox keeps every command's writes inside your project. Commit often. Works on macOS, Linux and WSL2. Not available on native Windows; use WSL2.

Scripts can open files themselves

File locks cover the agent's own read tool. A Python or Node script that opens .env itself isn't stopped.

  • Stopped:Read(.env)
  • Slips past:node dump-config.js

What helps The OS sandbox applies your .env read locks to scripts too. Works on macOS, Linux and WSL2. Not available on native Windows; use WSL2.

Keyword locks are blunt

SQL locks look for words like DROP TABLE in a command. They miss SQL inside a file, and can block a harmless search.

  • Stopped:psql -c "DROP TABLE users"
  • Slips past:psql -f cleanup.sql

What helps Backups you have tested, and reading every migration before it runs.

Rules are requests

The markdown file is read and usually followed. Usually isn't always: the agent can still misread, forget or get things wrong.

  • Rule:same error twice: stop, explain
  • Slips past:usually followed, not enforced

What helps Read the diff before you ship. Tests that run on every change.

Only Claude Code enforces locks

Cursor, Copilot, Codex, Windsurf, Cline, Gemini CLI and Aider get the rules file. What gates their commands is each tool's own approval settings.

  • Claude Code: rules + locks
  • other tools: rules + their approvals

What helps Switch on your tool's approvals. SETUP.md shows where.

An ask is only as good as your answer

Ask locks pause and hand the decision to you. Approving on autopilot turns a checkpoint into a formality.

  • Asks you:git push origin main
  • Risk:"yes" without reading

What helps Read the command, then answer. Choose Guided if you want to see everything.

No single layer is enough. Stacked, they catch a lot.

Each layer covers gaps the one before it leaves open.

  1. Rulesguide what the agent does
  2. Locksblock the worst, ask for the risky
  3. OS sandboxlimits which files and sites commands reach
  4. Your reviewbefore anything ships
  5. Backupsfor everything else

Not legal advice. The GDPR rules are engineering basics, not a compliance review. Lock limits are taken from Claude Code's permissions documentation.

07 Who built this

Made by SAI MADDI.

I'm a senior full-stack developer and applied-AI solutions architect in Germany. I build with AI coding agents every day, and I built this so people shipping without a senior reviewer get safe defaults from day one.

The site practises what it preaches: fully static, strict Content-Security-Policy with no inline scripts, zero third-party requests, self-hosted fonts, and every generated file covered by snapshot, property-based and end-to-end tests.

  • TypeScript strict
  • React 19
  • Vite
  • zod validation
  • fflate in-browser ZIP
  • Vitest + fast-check
  • Playwright e2e
  • CSP script-src 'self'
  • 0 third-party requests
  • 0 cookies
  • Firebase Hosting