Hermes Atlas
Security & sandboxing · works with Hermes Agent

Destructive Command Guard (dcg)

Dicklesworthstone/destructive_command_guard

Hook that blocks dangerous git and shell commands before AI coding agents run them

In short

Destructive Command Guard (dcg) is a Rust hook that intercepts destructive git, filesystem and infrastructure commands before an AI coding agent executes them. Its installer configures Hermes Agent among many supported agents.

What Destructive Command Guard (dcg) does

dcg sits in an agent's pre-execution hook and blocks commands such as git reset --hard, rm -rf ./src or DROP TABLE users, replying with an explanation and a safer alternative. It ships more than 50 security packs covering databases, Kubernetes, Docker, AWS, GCP, Azure and Terraform, and it scans heredocs and inline scripts such as python -c "os.remove(...)".

It separates data from execution, so grep "rm -rf" passes while rm -rf / is denied. Machine-readable hook output stays on stdout while the human-readable denial panel goes to stderr, and a scan mode can check pre-commit hooks and CI. The installer detects supported agents and configures their hooks. Hermes Agent is on that list next to Claude Code, Codex CLI, Gemini CLI, GitHub Copilot CLI and Cursor.

Key features

  • Blocks destructive git and shell commands before they execute
  • 50+ security packs for databases, Kubernetes, Docker, cloud providers and Terraform
  • Scans heredocs and inline scripts for embedded destructive calls
  • Distinguishes quoted data from executed commands
  • Scan mode for pre-commit hooks and CI
  • Sub-millisecond filtering, according to the README

When to use it

  • Protect uncommitted work while Hermes Agent runs shell and git commands
  • Stop an agent from running a database-destroying statement such as DROP TABLE
  • Apply one safety layer across several coding agents on the same machine
  • Catch dangerous commands during code review with CI scan mode

Who it is for: Developers who let AI agents run shell and git commands and want a guardrail against accidental data loss.

How it fits with Hermes Agent

Hermes Agent is one of many agents supported by dcg. The installer configures its hook alongside Claude Code, Codex CLI and others, so the project is not Hermes-specific.

How to install Destructive Command Guard (dcg)

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.sh?$(date +%s)" | bash -s -- --easy-mode
& ([scriptblock]::Create((irm "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.ps1"))) -EasyMode -Verify

Requirements: Linux, macOS, or Windows (via WSL for the shell installer, or the native PowerShell installer)

FAQ

What is Destructive Command Guard (dcg)?

Destructive Command Guard, or dcg, is a hook for AI coding agents that blocks destructive commands before they run. It explains each denial and suggests safer alternatives.

Does Destructive Command Guard work with Hermes Agent?

Yes. The README lists Hermes Agent as a supported agent, and the installer configures detected agent hooks, including Hermes Agent, automatically.

How do I install Destructive Command Guard?

On Linux, macOS or WSL, run the curl installer from the README with the --easy-mode flag. On native Windows, use the PowerShell installer with -EasyMode -Verify.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely