Skip to main content

Swif AI Agent Command Protection Policy

Overview

The Swif AI Agent Command Protection Policy stops AI coding agents from running destructive commands on your managed devices, such as rm -rf or git reset --hard. It works with Claude Code, Codex CLI, and Cursor on macOS, Linux, and Windows.

It's powered by the open-source Destructive Command Guard (DCG), which is why messages such as BLOCKED by dcg, overrides such as DCG_BYPASS, and the install folders on devices still use the name "dcg":

OS

Install folder

macOS

/usr/local/agentsecurity/dcg/

Linux

/var/lib/agentsecurity/dcg/

Windows

C:\ProgramData\AgentSecurity\dcg\

When an AI agent tries to run a shell command, the policy checks it first:

  • Safe commands, such as git status or ls -la, run normally.

  • Destructive commands are blocked before they run. The agent shows a message such as BLOCKED by dcg, and no files or Git history are changed.

  • Commands on your allowlist run, even if they'd normally be blocked. For example, you can allow rm -rf node_modules for dependency cleanup.

Important: This policy blocks commands. It doesn't record AI agent activity. To monitor what agents do, also assign the Swif Agentic Security Logging Policy or the Swif AI Agent Activity Monitoring Policy. The policies work well together.


How the policy protects itself

AI agents can't switch off their own guardrails:

  • The policy runs through a protected wrapper that only an administrator (root) can change. It ignores user-level overrides such as DCG_BYPASS=1, dcg allow-once, and personal allowlist files.

  • Standard users can't edit or delete the protected hook files. If they try, they get "Permission denied."

  • If someone removes the hook with admin rights, Swif puts it back on the next sync.

  • Swif keeps any hooks your own administrators have added to these files.


Requirements

Requirement

Details

Agent

Swif Agentic Security installed and running. Deploy it with the Apple, Windows, or Linux Agentic Security Policy.

macOS

Apple silicon (M1 or newer) and Intel Macs

Linux

Ubuntu 22.04+, Debian 12, Rocky Linux / RHEL 9 (x86_64 and ARM64)

Windows

Windows 11 (x64)

AI agents

Claude Code, Codex CLI, and/or Cursor. Open each one at least once on the device.

Connectivity

The device must be online to receive the policy. On macOS, the first install needs internet access, because Swif checks the program's Apple notarization online.

Device ownership

Company-owned and BYOD devices

Not supported: Amazon Linux 2, Alpine Linux, and Windows on ARM. On unsupported systems, Swif doesn't install anything, and commands aren't checked.

Supported AI agents

Value

AI agent

macOS

Linux

Windows

claude

Claude Code

✅

✅

✅

codex

OpenAI Codex CLI

✅

✅

✅

cursor

Cursor

✅

✅

✅


Settings reference

Basic settings

Setting

What it does

Default

Enabled

Turns command protection on or off.

Off

Protected Agents

The AI agents whose shell commands are checked before they run: claude, codex, cursor. Pick at least one, and list each agent only once.

claude, codex, cursor

Default Mode

What happens when a command matches a rule. See the modes below.

deny

Modes

Default Mode applies to every matched rule. Rule Modes can override it for specific rules.

Mode

What happens

deny

The command is blocked. The agent shows a message such as BLOCKED by dcg, and Swif reports the blocked command.

warn

The command runs. A dcg WARNING message is written only to the AI agent's verbose or debug hook output, in Claude Code and Codex. Cursor shows nothing. The AI model never sees the warning, and Swif doesn't report it.

log

The command runs silently. The match isn't recorded anywhere, and Swif doesn't report it.

In practice, warn and log turn a rule off. Both let matching commands run, and neither reports the match to Swif. Use deny for every rule you want enforced. Use warn or log only to stop a specific rule from blocking, and prefer an Allowlist entry when you can.

Critical rules may still block commands in warn or log mode. The most dangerous commands stay blocked, whatever mode you choose.

Rule packs

Rules are grouped into packs. Each rule has an ID in the format pack:rule, for example core.git:reset-hard.

Pack

Default state

core.filesystem

Always on. Can't be disabled.

core.git

Always on. Can't be disabled.

system.disk

On by default. Can be disabled.

windows.filesystem

On by default on Windows. Can be disabled.

windows.system

On by default on Windows. Can be disabled.

All other packs

Off until you add them under Enabled Packs

Setting

What it does

Enabled Packs

Optional packs to turn on, for example containers.docker.

Disabled Packs

Packs to turn off. The two core packs can't be disabled.

Choose packs from the list in Swif. A pack can't be in both lists.

Rule Modes

Override the mode for individual rules. Each entry has:

Field

What to enter

Rule ID

The rule to override, in the format pack:rule.

Mode

deny, warn, or log.

For example, keep Default Mode set to deny, but set one rule to warn so it stops blocking. Remember that warn and log matches aren't reported to Swif.

Allowlist

Exceptions that are always allowed. Each entry has:

Field

What to enter

Rule

A rule to allow everywhere, in the format pack:rule. Optional.

Exact Command

One exact shell command to allow, such as rm -rf node_modules. Optional.

Reason

Why the exception is needed. Required.

Each entry needs a Rule, an Exact Command, or both, plus a Reason. Swif rejects an entry with only a reason ("requires rule or exactCommand").

Use Exact Command for one specific command. Use Rule only when you trust every command that rule matches. Keep the allowlist short.

Safety settings

Setting

What it does

Default

Fail Closed

Blocks commands that can't be parsed or checked.

On

Unverified Decision

What happens when a command can't be evaluated: deny or ask. See below.

deny

ask applies only to Unverified Decision, not to rules. What it does depends on the AI agent:

AI agent

With ask

Claude Code

Shows its normal approval prompt, and the user decides whether to run the command.

Codex CLI

Doesn't support ask, so the command is denied.

Cursor

Treats ask as an error. The command is denied when Fail Closed is on (the default), and allowed when it's off.

Keep Fail Closed on and Unverified Decision set to deny for the strongest protection.

Swif rejects invalid settings when you save. For example, an agent listed twice, an unsupported agent, or Enabled turned on with no agents selected.


Before you start

  1. Deploy the Agentic Security agent to the devices.

  2. Make sure users have opened each AI agent at least once on their devices.

  3. List any commands your team needs to allow, such as dependency cleanup, with a reason for each.

  4. Choose a pilot group of devices for testing.


Create the policy

  1. In Swif, go to Agentic Security > Policies.

  2. Select Swif AI Agent Command Protection Policy.

  3. Turn on Enabled.

  4. Under Protected Agents, select the AI agents to protect.

  5. Set Default Mode to deny.

  6. Add optional packs, rule modes, and allowlist entries if you need them.

  7. Leave Fail Closed on and Unverified Decision set to deny.

  8. Assign the policy to your devices and save.

Devices apply the policy on their next sync. This usually takes a few minutes.


Example configurations

Example 1: Protect all three agents and allow dependency cleanup

Setting

Value

Enabled

On

Protected Agents

claude, codex, cursor

Default Mode

deny

Enabled Packs

containers.docker

Allowlist

Exact Command: rm -rf node_modules; Reason: Dependency cleanup

Fail Closed

On

Unverified Decision

deny

Example 2: Add Docker protection and stop one rule from blocking

Setting

Value

Enabled

On

Protected Agents

claude, codex, cursor

Default Mode

deny

Enabled Packs

containers.docker

Rule Modes

One Docker rule your team needs, set to warn

The Docker pack adds protection against destructive container commands, and all its other rules still block. The one rule in warn mode no longer blocks, and its matches aren't reported. If only one specific command is needed, add it to the Allowlist instead.

Example 3: Let Claude Code users confirm uncertain commands

Setting

Value

Enabled

On

Protected Agents

claude, codex, cursor

Default Mode

deny

Fail Closed

On

Unverified Decision

ask

Destructive commands are still blocked. When a command can't be evaluated, Claude Code asks the developer whether to run it. Codex CLI and Cursor still deny the command, because they don't support ask.


Check that the policy is working

Use a test folder, so nothing real is deleted:

mkdir ~/dcg-test && cd ~/dcg-test && git init && touch a.txt && git add . && git commit -m test

Then open the folder in each AI agent and ask it to run:

Ask the agent to run

Expected result

git status

Runs normally

git reset --hard

Blocked

rm -rf node_modules (if allowlisted)

Runs

DCG_BYPASS=1 git reset --hard

Still blocked


Turn off or remove the policy

  • Disable or unassign the policy: on the next sync, Swif removes the protection hooks and settings. Your own admin hooks stay in place. On macOS, the program stays cached, so turning the policy back on works right away without downloading it again.

  • Unenroll the device: Swif removes all program files, hooks, and settings.

After either change, AI agents can run commands without checks.


Troubleshooting

Destructive commands aren't blocked

  • Check that the policy is enabled, assigned to the device, and has synced.

  • Check that the AI agent is selected under Protected Agents.

  • Check that the user has opened the AI agent at least once on the device.

  • Check that the device runs a supported operating system.

  • Check Default Mode and Rule Modes. In warn or log mode, matched commands run.

  • Check that the command isn't covered by an allowlist Rule.

A legitimate command is blocked

Add it to the Allowlist as an Exact Command, with a reason. If a rule blocks too much in general, set it to warn or log in Rule Modes. Its matches then run without being reported.

A command is still blocked in warn or log mode

Critical rules may still block commands in warn or log mode. Add the exact command to the allowlist if it's genuinely needed.

I can't see warn or log matches in Swif

This is expected. Swif reports only blocked commands. warn messages appear only in Claude Code's and Codex's verbose or debug hook output, and log matches aren't recorded.

Claude Code asks for approval, but Codex and Cursor block

Unverified Decision is set to ask. Only Claude Code supports it. Codex denies the command, and Cursor denies it when Fail Closed is on.

Only Codex isn't blocked

Update Codex CLI to the latest version. Older versions may not load machine-wide hooks.

Cursor isn't blocked on a Mac

Install Xcode Command Line Tools on the Mac. The policy needs them for Cursor. Without them, it protects the other agents and reports a partial status.

The protection didn't install on a Mac

Make sure the Mac was online during the first install. The program needs internet access to verify its Apple notarization.

Advanced (macOS): you can check the protection's status on the device:

cat /usr/local/agentsecurity/dcg/status.json

overallState: "enforced" means protection is fully active. If you contact Swif Support, include this file.


Related resources

Did this answer your question?