Destructive Command Guard (dcg)
Dicklesworthstone/destructive_command_guard
Hook that blocks dangerous git and shell commands before AI coding agents run them
Destructive Command Guard (dcg) is a Rust hook that intercepts destructive git, filesystem and infrastructure commands before an AI coding agent executes them. Its installer configures Hermes Agent among many supported agents.
What Destructive Command Guard (dcg) does
dcg sits in an agent's pre-execution hook and blocks commands such as git reset --hard, rm -rf ./src or DROP TABLE users, replying with an explanation and a safer alternative. It ships more than 50 security packs covering databases, Kubernetes, Docker, AWS, GCP, Azure and Terraform, and it scans heredocs and inline scripts such as python -c "os.remove(...)".
It separates data from execution, so grep "rm -rf" passes while rm -rf / is denied. Machine-readable hook output stays on stdout while the human-readable denial panel goes to stderr, and a scan mode can check pre-commit hooks and CI. The installer detects supported agents and configures their hooks. Hermes Agent is on that list next to Claude Code, Codex CLI, Gemini CLI, GitHub Copilot CLI and Cursor.
Key features
- Blocks destructive git and shell commands before they execute
- 50+ security packs for databases, Kubernetes, Docker, cloud providers and Terraform
- Scans heredocs and inline scripts for embedded destructive calls
- Distinguishes quoted data from executed commands
- Scan mode for pre-commit hooks and CI
- Sub-millisecond filtering, according to the README
When to use it
- Protect uncommitted work while Hermes Agent runs shell and git commands
- Stop an agent from running a database-destroying statement such as DROP TABLE
- Apply one safety layer across several coding agents on the same machine
- Catch dangerous commands during code review with CI scan mode
Who it is for: Developers who let AI agents run shell and git commands and want a guardrail against accidental data loss.
How it fits with Hermes Agent
Hermes Agent is one of many agents supported by dcg. The installer configures its hook alongside Claude Code, Codex CLI and others, so the project is not Hermes-specific.
How to install Destructive Command Guard (dcg)
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.sh?$(date +%s)" | bash -s -- --easy-mode
& ([scriptblock]::Create((irm "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.ps1"))) -EasyMode -VerifyRequirements: Linux, macOS, or Windows (via WSL for the shell installer, or the native PowerShell installer)
FAQ
What is Destructive Command Guard (dcg)?
Destructive Command Guard, or dcg, is a hook for AI coding agents that blocks destructive commands before they run. It explains each denial and suggests safer alternatives.
Does Destructive Command Guard work with Hermes Agent?
Yes. The README lists Hermes Agent as a supported agent, and the installer configures detected agent hooks, including Hermes Agent, automatically.
How do I install Destructive Command Guard?
On Linux, macOS or WSL, run the curl installer from the README with the --easy-mode flag. On native Windows, use the PowerShell installer with -EasyMode -Verify.
Similar security for Hermes Agent
All securityReference stack for running Hermes, OpenClaw and LangChain Deep Agents inside NVIDIA OpenShell sandboxes
lennney Stop That ShitHook and skill guard that stops AI coding agents from unrequested checksums and scope creep
LoRexxar KunLun-MOpen-source static code security scanner with a built-in skill for AI agents including Hermes
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
kenryu42 CC Safety NetGuard that blocks destructive Git and file commands and secret access before a coding agent runs them
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
Related guides: How to run Hermes Agent securely