Skip to main content

Swif Destructive Command Guard (DCG) Policy for Agentic Security

Overview

The Swif Destructive Command Guard (DCG) Policy stops AI coding agents from running destructive commands on your managed devices. Examples are git reset --hard and rm -rf.

The policy works with Claude Code, Codex CLI and Cursor. When an AI agent tries to run a command, DCG checks it first:

  • Safe commands, such as git status or ls -la, run normally.

  • Destructive commands are blocked before they run. The agent shows a message such as BLOCKED by dcg, and no files or Git history are changed.

  • Commands on your allowlist run, even if DCG would normally block them. For example, you can allow rm -rf node_modules for dependency cleanup.

Note: This policy blocks commands. To monitor AI agent activity, use the Swif ADR Sensor Policy. The two policies work well together.

How DCG protects itself

AI agents can't switch off their own guardrails:

  • DCG runs through a protected wrapper that only an administrator (root) can change. It ignores user-level overrides such as DCG_BYPASS=1, dcg allow-once and personal allowlist files.

  • Standard users can't edit or delete the protected hook files. If they try, they get "Permission denied."

  • If someone removes the DCG hook with admin rights, Swif puts it back on the next sync.

  • Swif keeps any hooks your own administrators have added to these files.

Requirements

Requirement

Details

Agent

Swif Agentic Security installed and running

macOS

Apple silicon (M1 or newer) and Intel Macs

Linux

Ubuntu 22.04+, Debian 12, Rocky Linux / RHEL 9 (x86_64 and ARM64)

Windows

Windows 11 (x64)

AI agents

Claude Code, Codex CLI and/or Cursor. Open each one at least once on the device.

Connectivity

The device must be online to receive the policy. On macOS, the first install needs internet access because Swif checks DCG's Apple notarization online.

Not supported: Amazon Linux 2, Alpine Linux and Windows on ARM. On unsupported systems, Swif doesn't install anything and commands aren't blocked.

Supported AI agents

Source value

AI agent

macOS

Linux

Windows

claude

Claude Code

✅

✅

✅

codex

OpenAI Codex CLI

✅

✅

✅

cursor

Cursor

✅

✅

✅

Create the policy

  1. Go to Agentic Security > Policies.

  2. Select Swif Destructive Command Guard Policy.

  3. Turn on Enabled.

  4. Under Agents, select the AI agents to protect: Claude Code, Codex and/or Cursor.

  5. Set the Default Mode to deny.

  6. Add any allowlist entries you need (see below).

  7. Assign the policy to your devices and save.

Devices apply the policy on their next sync. This usually takes a few minutes.

Policy settings

Setting

What it does

Recommended

Enabled

Turns protection on or off

On

Agents

Which AI agents DCG protects. Pick at least one, and list each agent only once.

claude, codex, cursor

Default Mode

What happens to commands that DCG identifies as destructive

deny

Enabled Packs / Disabled Packs

Turn optional groups of rules on or off, for example containers.docker. A pack can't be in both lists.

As needed

Allowlist

Exact commands that are always allowed, each with a reason

Keep it short

Fail Closed

Blocks commands if DCG can't make a decision

On

Unverified Decision

What to do when a command can't be verified

deny

Swif rejects invalid settings when you save, for example an agent listed twice, an unsupported agent, or Enabled turned on with no agents selected.

Example: protect all three agents and allow dependency cleanup

Enabled: On
Agents: claude, codex, cursor
Default Mode: deny
Enabled Packs: containers.docker
Allowlist: "rm -rf node_modules" — Dependency cleanup
Fail Closed: On
Unverified Decision: deny

Check that the policy is working

Use a test folder so nothing real is deleted:

mkdir ~/dcg-test && cd ~/dcg-test && git init && touch a.txt && git add . && git commit -m test

Then open the folder in each AI agent and ask it to run:

Ask the agent to run

Expected result

git status

Runs normally

git reset --hard

Blocked by DCG

rm -rf node_modules (if allowlisted)

Runs

DCG_BYPASS=1 git reset --hard

Still blocked

Turn off or remove the policy

  • Disable or unassign the policy: On the next sync, Swif removes the DCG hooks and settings. Your own admin hooks stay in place. On macOS, the DCG program stays cached, so turning the policy back on works right away without downloading it again.

  • Unenroll the device: Swif removes all DCG files, hooks and settings.

After either change, AI agents can run commands without DCG checks.


Troubleshooting

Destructive commands aren't blocked

  • Check that the policy is enabled, assigned to the device, and has synced.

  • Check that the AI agent is selected under Agents.

  • Check that the user has opened the AI agent at least once on the device.

  • Check that the device runs a supported operating system.

Only Codex isn't blocked

  • Update Codex CLI to the latest version. Older versions may not load machine-wide hooks.

Cursor isn't blocked on a Mac

  • Install Xcode Command Line Tools on the Mac. DCG needs them for Cursor. Without them, DCG protects the other agents and reports a partial status.

DCG didn't install on a Mac

  • Make sure the Mac was online during the first install. DCG needs internet access to verify Apple notarization.

Advanced (macOS): You can check DCG's status on the device:

cat /usr/local/agentsecurity/dcg/status.json

overallState: "enforced" means DCG is fully active. If you contact Swif Support, include this file.

Summary

The Swif Destructive Command Guard Policy blocks destructive commands from Claude Code, Codex CLI and Cursor on macOS, Linux and Windows. It also stops AI agents from switching off their own protection. Start with a small pilot group, keep your allowlist short, and test with a throwaway folder before you roll it out widely.

Did this answer your question?