Overview
The Swif AI Agent Command Protection Policy stops AI coding agents from running destructive commands on your managed devices, such as rm -rf or git reset --hard. It works with Claude Code, Codex CLI, and Cursor on macOS, Linux, and Windows.
It's powered by the open-source Destructive Command Guard (DCG), which is why messages such as BLOCKED by dcg, overrides such as DCG_BYPASS, and the install folders on devices still use the name "dcg":
OS | Install folder |
macOS |
|
Linux |
|
Windows |
|
When an AI agent tries to run a shell command, the policy checks it first:
Safe commands, such as
git statusorls -la, run normally.Destructive commands are blocked before they run. The agent shows a message such as
BLOCKED by dcg, and no files or Git history are changed.Commands on your allowlist run, even if they'd normally be blocked. For example, you can allow
rm -rf node_modulesfor dependency cleanup.
Important: This policy blocks commands. It doesn't record AI agent activity. To monitor what agents do, also assign the Swif Agentic Security Logging Policy or the Swif AI Agent Activity Monitoring Policy. The policies work well together.
How the policy protects itself
AI agents can't switch off their own guardrails:
The policy runs through a protected wrapper that only an administrator (root) can change. It ignores user-level overrides such as
DCG_BYPASS=1,dcg allow-once, and personal allowlist files.Standard users can't edit or delete the protected hook files. If they try, they get "Permission denied."
If someone removes the hook with admin rights, Swif puts it back on the next sync.
Swif keeps any hooks your own administrators have added to these files.
Requirements
Requirement | Details |
Agent | Swif Agentic Security installed and running. Deploy it with the Apple, Windows, or Linux Agentic Security Policy. |
macOS | Apple silicon (M1 or newer) and Intel Macs |
Linux | Ubuntu 22.04+, Debian 12, Rocky Linux / RHEL 9 (x86_64 and ARM64) |
Windows | Windows 11 (x64) |
AI agents | Claude Code, Codex CLI, and/or Cursor. Open each one at least once on the device. |
Connectivity | The device must be online to receive the policy. On macOS, the first install needs internet access, because Swif checks the program's Apple notarization online. |
Device ownership | Company-owned and BYOD devices |
Not supported: Amazon Linux 2, Alpine Linux, and Windows on ARM. On unsupported systems, Swif doesn't install anything, and commands aren't checked.
Supported AI agents
Value | AI agent | macOS | Linux | Windows |
| Claude Code | ✅ | ✅ | ✅ |
| OpenAI Codex CLI | ✅ | ✅ | ✅ |
| Cursor | ✅ | ✅ | ✅ |
Settings reference
Basic settings
Setting | What it does | Default |
Enabled | Turns command protection on or off. | Off |
Protected Agents | The AI agents whose shell commands are checked before they run: |
|
Default Mode | What happens when a command matches a rule. See the modes below. |
|
Modes
Default Mode applies to every matched rule. Rule Modes can override it for specific rules.
Mode | What happens |
| The command is blocked. The agent shows a message such as |
| The command runs. A |
| The command runs silently. The match isn't recorded anywhere, and Swif doesn't report it. |
In practice, warn and log turn a rule off. Both let matching commands run, and neither reports the match to Swif. Use deny for every rule you want enforced. Use warn or log only to stop a specific rule from blocking, and prefer an Allowlist entry when you can.
Critical rules may still block commands in warn or log mode. The most dangerous commands stay blocked, whatever mode you choose.
Rule packs
Rules are grouped into packs. Each rule has an ID in the format pack:rule, for example core.git:reset-hard.
Pack | Default state |
| Always on. Can't be disabled. |
| Always on. Can't be disabled. |
| On by default. Can be disabled. |
| On by default on Windows. Can be disabled. |
| On by default on Windows. Can be disabled. |
All other packs | Off until you add them under Enabled Packs |
Setting | What it does |
Enabled Packs | Optional packs to turn on, for example |
Disabled Packs | Packs to turn off. The two core packs can't be disabled. |
Choose packs from the list in Swif. A pack can't be in both lists.
Rule Modes
Override the mode for individual rules. Each entry has:
Field | What to enter |
Rule ID | The rule to override, in the format |
Mode |
|
For example, keep Default Mode set to deny, but set one rule to warn so it stops blocking. Remember that warn and log matches aren't reported to Swif.
Allowlist
Exceptions that are always allowed. Each entry has:
Field | What to enter |
Rule | A rule to allow everywhere, in the format |
Exact Command | One exact shell command to allow, such as |
Reason | Why the exception is needed. Required. |
Each entry needs a Rule, an Exact Command, or both, plus a Reason. Swif rejects an entry with only a reason ("requires rule or exactCommand").
Use Exact Command for one specific command. Use Rule only when you trust every command that rule matches. Keep the allowlist short.
Safety settings
Setting | What it does | Default |
Fail Closed | Blocks commands that can't be parsed or checked. | On |
Unverified Decision | What happens when a command can't be evaluated: |
|
ask applies only to Unverified Decision, not to rules. What it does depends on the AI agent:
AI agent | With |
Claude Code | Shows its normal approval prompt, and the user decides whether to run the command. |
Codex CLI | Doesn't support |
Cursor | Treats |
Keep Fail Closed on and Unverified Decision set to deny for the strongest protection.
Swif rejects invalid settings when you save. For example, an agent listed twice, an unsupported agent, or Enabled turned on with no agents selected.
Before you start
Deploy the Agentic Security agent to the devices.
Make sure users have opened each AI agent at least once on their devices.
List any commands your team needs to allow, such as dependency cleanup, with a reason for each.
Choose a pilot group of devices for testing.
Create the policy
In Swif, go to Agentic Security > Policies.
Select Swif AI Agent Command Protection Policy.
Turn on Enabled.
Under Protected Agents, select the AI agents to protect.
Set Default Mode to
deny.Add optional packs, rule modes, and allowlist entries if you need them.
Leave Fail Closed on and Unverified Decision set to
deny.Assign the policy to your devices and save.
Devices apply the policy on their next sync. This usually takes a few minutes.
Example configurations
Example 1: Protect all three agents and allow dependency cleanup
Setting | Value |
Enabled | On |
Protected Agents |
|
Default Mode |
|
Enabled Packs |
|
Allowlist | Exact Command: |
Fail Closed | On |
Unverified Decision |
|
Example 2: Add Docker protection and stop one rule from blocking
Setting | Value |
Enabled | On |
Protected Agents |
|
Default Mode |
|
Enabled Packs |
|
Rule Modes | One Docker rule your team needs, set to |
The Docker pack adds protection against destructive container commands, and all its other rules still block. The one rule in warn mode no longer blocks, and its matches aren't reported. If only one specific command is needed, add it to the Allowlist instead.
Example 3: Let Claude Code users confirm uncertain commands
Setting | Value |
Enabled | On |
Protected Agents |
|
Default Mode |
|
Fail Closed | On |
Unverified Decision |
|
Destructive commands are still blocked. When a command can't be evaluated, Claude Code asks the developer whether to run it. Codex CLI and Cursor still deny the command, because they don't support ask.
Check that the policy is working
Use a test folder, so nothing real is deleted:
mkdir ~/dcg-test && cd ~/dcg-test && git init && touch a.txt && git add . && git commit -m test
Then open the folder in each AI agent and ask it to run:
Ask the agent to run | Expected result |
| Runs normally |
| Blocked |
| Runs |
| Still blocked |
Turn off or remove the policy
Disable or unassign the policy: on the next sync, Swif removes the protection hooks and settings. Your own admin hooks stay in place. On macOS, the program stays cached, so turning the policy back on works right away without downloading it again.
Unenroll the device: Swif removes all program files, hooks, and settings.
After either change, AI agents can run commands without checks.
Troubleshooting
Destructive commands aren't blocked
Check that the policy is enabled, assigned to the device, and has synced.
Check that the AI agent is selected under Protected Agents.
Check that the user has opened the AI agent at least once on the device.
Check that the device runs a supported operating system.
Check Default Mode and Rule Modes. In
warnorlogmode, matched commands run.Check that the command isn't covered by an allowlist Rule.
A legitimate command is blocked
Add it to the Allowlist as an Exact Command, with a reason. If a rule blocks too much in general, set it to warn or log in Rule Modes. Its matches then run without being reported.
A command is still blocked in warn or log mode
Critical rules may still block commands in warn or log mode. Add the exact command to the allowlist if it's genuinely needed.
I can't see warn or log matches in Swif
This is expected. Swif reports only blocked commands. warn messages appear only in Claude Code's and Codex's verbose or debug hook output, and log matches aren't recorded.
Claude Code asks for approval, but Codex and Cursor block
Unverified Decision is set to ask. Only Claude Code supports it. Codex denies the command, and Cursor denies it when Fail Closed is on.
Only Codex isn't blocked
Update Codex CLI to the latest version. Older versions may not load machine-wide hooks.
Cursor isn't blocked on a Mac
Install Xcode Command Line Tools on the Mac. The policy needs them for Cursor. Without them, it protects the other agents and reports a partial status.
The protection didn't install on a Mac
Make sure the Mac was online during the first install. The program needs internet access to verify its Apple notarization.
Advanced (macOS): you can check the protection's status on the device:
cat /usr/local/agentsecurity/dcg/status.json
overallState: "enforced" means protection is fully active. If you contact Swif Support, include this file.