FAQ Questions and answers

Questions, straight answers.

How the rules and locks work, what they block, how to set them up in your AI tool, and where their limits are. Can't find your question? Email me.

01 Getting started

Do I need to be a developer to use this?

No. The questions are in plain English, "Not sure" is always a safe answer, and a template can fill in a typical stack for you in one click. The download includes a step-by-step setup checklist (SETUP.md).

Tell the generator you're new to coding, and the rules ask your agent to explain every change in plain English.

What exactly do I get?

It depends on your AI tool:

  • Claude Code: CLAUDE.md with the main rules, short topic files in .claude/rules/ (only the topics your answers need, such as database.md or security.md), .claude/settings.json with the locks, and SETUP.md.
  • Other tools: one AGENTS.md with all the rules, plus SETUP.md. Cursor also gets .cursorignore, Gemini CLI gets .gemini/settings.json and .geminiignore, and Aider gets .aider.conf.yml and .aiderignore. The ignore files keep your secret files away from the AI; the config files make Gemini CLI and Aider load AGENTS.md.

You can read every file on the page before you download, copy them one at a time, or download them all as a ZIP.

Where do the files go?

In the root of your project: the folder with your main code and config files (for a JavaScript project, the one with package.json). Unzip there, then open SETUP.md. It shows every file with its path and walks you through the remaining steps in order.

Then commit the files, so every session and every teammate gets them.

I already have a CLAUDE.md, AGENTS.md or settings.json. What do I do?

Don't overwrite them. Copy our sections into your CLAUDE.md or AGENTS.md, and add our deny, ask and allow lines to the lists in your settings.json. SETUP.md lists anything else worth copying across.

One catch with Claude Code: it reads AGENTS.md only when there is no CLAUDE.md. To use both, put @AGENTS.md on its own line at the top of CLAUDE.md, or set Project instructions to claude-md-and-agents-md in /config.

What if I don't know an answer?

Pick "Not sure". It counts as yes, so you get the safer rules: "Not sure" about personal data, for example, adds the rules for handling personal data.

For your stack, pick what you know. You can go back and change any answer, and the protection summary next to the questions updates as you go.

My framework or host isn't in the list. Is this still useful?

Yes. Most of the main file doesn't depend on your stack: how the agent should work, what it asks first, what it must never do, keeping secrets out of code, git, tests, and what to do when something keeps failing.

Pick the closest match, or "None" for a row that doesn't apply. Stack answers add framework-specific rules and the locks for that host's command-line tool.

Is it free? Do I need an account?

It's free, and there's no sign-up, no account and no email address to give. The page is static, and the generator runs entirely in your browser.

02 Rules and locks

What's the difference between a rule and a lock?

A rule is a line in a markdown file (CLAUDE.md or AGENTS.md), such as "ask before installing packages". The agent reads it at the start of a session and is asked to follow it. It usually does, but it can misread or forget it.

A lock is an entry in Claude Code's .claude/settings.json. When the agent tries a matching action, Claude Code steps in: a deny lock blocks it, and an ask lock makes it wait for your approval. The agent's own judgment doesn't come into it.

Why do I need both?

The markdown tells the agent how to behave: ask first, stop looping, keep secrets out of code. The settings file makes the most dangerous actions impossible even if the agent ignores the markdown.

Rules also cover what no lock can express, like how to handle personal data, how to write tests, or when to stop and explain. You want both.

What is blocked no matter what I choose?

At every control level and for every stack:

  • Deleting data: rm -rf, dropping tables, database resets
  • Rewriting git history: force push, git reset --hard, git clean
  • Reading secrets: .env files (except .env.example), private keys, cloud credential folders
  • Deploying to production with your host's command-line tool
  • Changing IAM, roles or billing in your cloud account
  • Publishing packages, such as npm publish
  • Editing its own locks
  • Changing the computer itself: sudo, disk tools, system services and scheduled jobs, your shell profile and ~/.ssh

For Claude Code these are deny locks. For other tools they are "Never" rules, and SETUP.md shows where to switch on your tool's own approvals.

What do Guided, Balanced and Sandbox change?
  • Guided: the agent asks before every file change and every command. Best while you're learning.
  • Balanced (recommended): the agent edits code and runs your lint, test and build scripts freely. It asks before installs, git push, deletes, downloads, database commands, migrations and changes to CI files.
  • Sandbox: for throwaway projects. The agent installs packages without asking, but still asks before pushes and migrations.

The "always blocked" list is the same at every level. For Claude Code, Guided and Balanced also switch off bypass-permissions mode, so nobody can put the agent into a mode that skips every prompt.

Will the locks slow my agent down?

Only where you want them to. In Balanced mode the agent edits code and runs your tests freely; it stops only for things like installs, pushes, migrations and deletes. Pick Sandbox for throwaway projects, or Guided if you want to approve everything.

Do the locks still work in auto mode?

Yes. According to Claude Code's docs on permission modes, deny rules block in every mode, even bypass-permissions mode, and ask rules that match a command, like Bash(git push *), still bring up a prompt in auto mode.

That matters, because since version 2.1.283 auto mode is Claude Code's built-in starting mode in the terminal and in VS Code.

One detail: a starting mode set in a settings file comes first. The Guided and Balanced files set it to Manual and Accept edits, so sessions in your project start there. The Sandbox level leaves it to Claude Code. Whichever mode you switch to, the locks keep working.

What changes when I say my app is already live?

Pushing a database schema to production, with commands like supabase db push or prisma migrate deploy, moves from "asks first" to blocked. The agent writes the migration file, and you apply it.

The rules also ask the agent to check with you before anything that emails or messages real people, changes scheduled jobs, or changes URLs, API responses or data that other code or users rely on.

Why does it ask where my code is stored?

It decides which command-line tool gets locked. On GitHub (gh), GitLab (glab) and Azure DevOps (az repos), the agent can't delete, archive or transfer the repo, change its visibility, or merge past branch protection. Merges, releases, CI secrets and workflow runs ask first. Bitbucket has no official command-line tool, so there you get rules only.

A public repo adds a rule that anything committed can be seen by anyone, even after it's deleted. A repo other people work in adds pull-request rules, and the agent never merges or approves.

Why can't the agent change its own locks?

If it could, one bad decision could remove every lock at once. So editing .claude/settings.json, .claude/settings.local.json and .mcp.json is blocked, and changing CLAUDE.md or the files in .claude/rules/ asks you first.

When a lock needs to change, the agent suggests the change and you make it.

What is the OS sandbox option?

Claude Code can run shell commands inside an operating-system sandbox that limits which files and websites a command can reach, even commands no rule recognises. It also applies your read locks to every command, so even a script can't read your .env files.

Works on macOS, Linux and WSL2. Not available on native Windows; use WSL2. On Linux and WSL2 it needs extra packages: run /sandbox to check. Some commands, such as docker, can't run inside it; the setup guide explains what to do.

03 Your AI tool

Which AI tools does it work with?

Claude Code gets both layers: rules and enforced locks. Cursor, GitHub Copilot, OpenAI Codex, Windsurf (now Devin Desktop), Cline, Gemini CLI and Aider get an AGENTS.md rules file, plus setup notes checked against each tool's docs on where to switch on its own approval settings.

Using something else? Pick "Something else": many AI coding tools read AGENTS.md from the project root.

Why does only Claude Code get locks?

Claude Code is the only tool here that enforces a deny and ask list from a file in your project. The others keep approvals in their own settings, and in some a "deny" entry means "always ask", not "block": Windsurf's Deny list and Copilot's false auto-approve rules work that way.

So other tools get the rules, a config file where the tool supports one, and a setup guide that shows where to switch on their approvals. The generator doesn't make settings files for formats it hasn't checked.

I don't use Claude Code. What should I switch on in my tool?
  • Cursor: Run Mode set to Auto-review or Allowlist, plus File-Deletion Protection and External-File Protection. Avoid "Run Everything".
  • GitHub Copilot in VS Code: set risky commands to false in chat.tools.terminal.autoApprove. Avoid chat.tools.global.autoApprove and /yolo.
  • OpenAI Codex: an approval policy such as on-request and the workspace-write sandbox. Avoid danger-full-access and --yolo.
  • Windsurf / Devin Desktop: put the "Never" commands on Cascade's Deny list. Avoid Turbo mode.
  • Cline: leave "Execute all commands" off in Auto Approve. Avoid YOLO mode.
  • Gemini CLI: the generated .gemini/settings.json sets the approval mode for your level and blocks YOLO mode.
  • Aider: keep its confirmation prompts. Avoid --yes-always.

Your SETUP.md has these steps for your tool, with a link to its docs.

I use Claude Code in VS Code. Is anything different?

The locks work the same. One difference: the VS Code extension never reads the starting mode from .claude/settings.json. New conversations start in the mode you last picked, or in Auto.

To start in the mode your control level picked, set claudeCode.initialPermissionMode in your VS Code user settings: default for Guided, acceptEdits for Balanced. SETUP.md tells you the same.

I use more than one AI tool. What do I do?

Run the generator once per tool. Unzip the second download into a separate folder first, then copy its AGENTS.md and any tool files into your project, so the two SETUP.md files don't overwrite each other.

While a CLAUDE.md exists, Claude Code doesn't read AGENTS.md, so the rules don't double up there. When you change a rule, change it in both files.

04 Privacy

Do you see my answers or my code?

No. The generator is a static page: your answers are turned into files in your browser, and nothing is uploaded. It never sees your project either; it only knows what you tell it.

Does the site use cookies, analytics or tracking?

No cookies, no analytics, no ads and no requests to other sites. Fonts and code are served from this domain.

The only thing the site stores is your light or dark theme choice, in your own browser, and only after you click the theme switch. Like any website, the page is delivered by a hosting provider, which processes connection data to do so. The privacy policy has the details.

05 Editing and troubleshooting

Can I edit the generated files?

Please do. They're starter files: short, readable, and meant to grow with your project. Delete rules that don't apply to you. If two rules contradict each other, the agent may follow either one, so keep just one.

To remove a single lock, delete that one line from settings.json, not the whole file.

A lock blocks something I really need. What now?

Delete that one line from .claude/settings.json. Adding an allow rule won't help: in Claude Code, a deny rule always wins over an allow rule.

The "Ask me first" and "Never" lists in CLAUDE.md say in plain English what each lock protects, so you can judge what's safe to drop. For a one-off, you can also run the command yourself in your own terminal.

How do I check the locks are working?
  1. Restart Claude Code in your project folder.
  2. Run /permissions to see every lock, and /memory to see which rule files loaded.
  3. Ask Claude: "show me what is in my .env file" (create an empty .env first if you don't have one). It should be refused.

Before you download anything, the "Test the locks" tab in the generator lets you type any command and see whether it would be blocked, asked or allowed. It simulates Claude Code's documented matching rules; Claude Code makes the real decision.

With the sandbox on, my dev server or build can't find its environment variables.

That's the sandbox doing its job: it applies the read locks to every command, including your dev server, builds and scripts, so they can't read .env either.

Run those commands yourself in your own terminal, or list them under sandbox.excludedCommands in .claude/settings.local.json (keep that file out of git). The same fix works for docker and cloud command-line tools that fail inside the sandbox.

The agent ignored one of my rules. Why?

Rules are instructions, not guarantees, and the agent weighs them against everything else in the conversation. Things to check:

  • Did the file load? In Claude Code, run /memory.
  • Does another rule say something different? Keep one of them.
  • Has the file grown long? Long instruction files are followed less reliably.

If the rule is about a command, a lock is the stronger tool: in Claude Code, add it to the deny or ask list. For a block that doesn't depend on the agent at all, Claude Code offers PreToolUse hooks.

Why are the files so short?

Long instruction files are followed less reliably. Claude Code's docs recommend keeping each CLAUDE.md under 200 lines. So the files contain only what your answers call for, and tests keep them within fixed limits: 150 lines for the main file, 60 per topic file, and no Claude Code file over 200 lines.

How do I change my answers or update the files later?

Use "Copy link" on the results page. Your answers live in that link, so you can open it later, change an answer and generate again. Every file starts with the generator version and date, so you can tell which version you have.

Unzip the new files into a separate folder and compare them with yours, or unzip over them and review the changes with git diff before you commit, so you keep your own edits.

How do I share the setup with my team?

Commit the files, so every teammate and every session gets the same rules and locks. Keep personal additions out of git: notes in CLAUDE.local.md and your own permission tweaks in .claude/settings.local.json.

Answer "Yes" to "Do other people work in it?" in the generator: that adds pull-request rules, and the agent never merges or approves.

06 Limits and legal

Does this make my agent safe?

No. It reduces risk; it isn't a guarantee.

  • Locks match the command text. The same program run another way, like /bin/rm or inside bash -c, isn't matched.
  • A Python or Node script that opens files itself isn't stopped by the file locks, unless the OS sandbox is on.
  • Rules are instructions, and the agent can still get things wrong.

Review what the agent changes before you ship, and keep backups. More under Honest limits.

Is the GDPR file legal advice?

No. gdpr.md covers engineering basics: collect only what a feature needs, keep personal data in an EU region and out of logs, and make every user's data exportable and deletable. It doesn't cover legal bases, contracts with processors or your privacy policy.

It's added when you have users in the EU (or aren't sure). For compliance questions, ask a lawyer or your data protection officer.

How current are the facts about each tool?

Every Claude Code fact in the files (permission syntax, how files load, modes, the sandbox) was checked against the official Claude Code docs in September 2026, and every other tool's setup notes against that vendor's docs.

These tools change often. Each file's header carries the generator version and date, and SETUP.md links to the docs for your tool. If something has changed, please tell me.

Can I get the rule files in another language?

The rule files are always in English. It's the standard for these files, and they work that way in every tool and every team. The setup guide (SETUP.md) follows the site's language, English or German. You can translate or reword the rules any time.

I found a wrong or missing rule. How do I tell you?

Email sai@saimaddi.dev. Say which tool you use, what the file says and what you expected. If you're happy to, include your share link, so I can see the same answers.

Ready to lock things down?

About two minutes. Nothing leaves your browser.

Generate my rules