Overview
The Swif Destructive Command Guard (DCG) Policy stops AI coding agents from running destructive commands on your managed devices. Examples are git reset --hard and rm -rf.
The policy works with Claude Code, Codex CLI and Cursor. When an AI agent tries to run a command, DCG checks it first:
Safe commands, such as
git statusorls -la, run normally.Destructive commands are blocked before they run. The agent shows a message such as
BLOCKED by dcg, and no files or Git history are changed.Commands on your allowlist run, even if DCG would normally block them. For example, you can allow
rm -rf node_modulesfor dependency cleanup.
Note: This policy blocks commands. To monitor AI agent activity, use the Swif ADR Sensor Policy. The two policies work well together.
How DCG protects itself
AI agents can't switch off their own guardrails:
DCG runs through a protected wrapper that only an administrator (root) can change. It ignores user-level overrides such as
DCG_BYPASS=1,dcg allow-onceand personal allowlist files.Standard users can't edit or delete the protected hook files. If they try, they get "Permission denied."
If someone removes the DCG hook with admin rights, Swif puts it back on the next sync.
Swif keeps any hooks your own administrators have added to these files.
Requirements
Requirement | Details |
Agent | Swif Agentic Security installed and running |
macOS | Apple silicon (M1 or newer) and Intel Macs |
Linux | Ubuntu 22.04+, Debian 12, Rocky Linux / RHEL 9 (x86_64 and ARM64) |
Windows | Windows 11 (x64) |
AI agents | Claude Code, Codex CLI and/or Cursor. Open each one at least once on the device. |
Connectivity | The device must be online to receive the policy. On macOS, the first install needs internet access because Swif checks DCG's Apple notarization online. |
Not supported: Amazon Linux 2, Alpine Linux and Windows on ARM. On unsupported systems, Swif doesn't install anything and commands aren't blocked.
Supported AI agents
Source value | AI agent | macOS | Linux | Windows |
| Claude Code | ✅ | ✅ | ✅ |
| OpenAI Codex CLI | ✅ | ✅ | ✅ |
| Cursor | ✅ | ✅ | ✅ |
Create the policy
Go to Agentic Security > Policies.
Select Swif Destructive Command Guard Policy.
Turn on Enabled.
Under Agents, select the AI agents to protect: Claude Code, Codex and/or Cursor.
Set the Default Mode to deny.
Add any allowlist entries you need (see below).
Assign the policy to your devices and save.
Devices apply the policy on their next sync. This usually takes a few minutes.
Policy settings
Setting | What it does | Recommended |
Enabled | Turns protection on or off | On |
Agents | Which AI agents DCG protects. Pick at least one, and list each agent only once. |
|
Default Mode | What happens to commands that DCG identifies as destructive |
|
Enabled Packs / Disabled Packs | Turn optional groups of rules on or off, for example | As needed |
Allowlist | Exact commands that are always allowed, each with a reason | Keep it short |
Fail Closed | Blocks commands if DCG can't make a decision | On |
Unverified Decision | What to do when a command can't be verified |
|
Swif rejects invalid settings when you save, for example an agent listed twice, an unsupported agent, or Enabled turned on with no agents selected.
Example: protect all three agents and allow dependency cleanup
Enabled: On
Agents: claude, codex, cursor
Default Mode: deny
Enabled Packs: containers.docker
Allowlist: "rm -rf node_modules" — Dependency cleanup
Fail Closed: On
Unverified Decision: deny
Check that the policy is working
Use a test folder so nothing real is deleted:
mkdir ~/dcg-test && cd ~/dcg-test && git init && touch a.txt && git add . && git commit -m test
Then open the folder in each AI agent and ask it to run:
Ask the agent to run | Expected result |
| Runs normally |
| Blocked by DCG |
| Runs |
| Still blocked |
Turn off or remove the policy
Disable or unassign the policy: On the next sync, Swif removes the DCG hooks and settings. Your own admin hooks stay in place. On macOS, the DCG program stays cached, so turning the policy back on works right away without downloading it again.
Unenroll the device: Swif removes all DCG files, hooks and settings.
After either change, AI agents can run commands without DCG checks.
Troubleshooting
Destructive commands aren't blocked
Check that the policy is enabled, assigned to the device, and has synced.
Check that the AI agent is selected under Agents.
Check that the user has opened the AI agent at least once on the device.
Check that the device runs a supported operating system.
Only Codex isn't blocked
Update Codex CLI to the latest version. Older versions may not load machine-wide hooks.
Cursor isn't blocked on a Mac
Install Xcode Command Line Tools on the Mac. DCG needs them for Cursor. Without them, DCG protects the other agents and reports a partial status.
DCG didn't install on a Mac
Make sure the Mac was online during the first install. DCG needs internet access to verify Apple notarization.
Advanced (macOS): You can check DCG's status on the device:
cat /usr/local/agentsecurity/dcg/status.json
overallState: "enforced" means DCG is fully active. If you contact Swif Support, include this file.
Summary
The Swif Destructive Command Guard Policy blocks destructive commands from Claude Code, Codex CLI and Cursor on macOS, Linux and Windows. It also stops AI agents from switching off their own protection. Start with a small pilot group, keep your allowlist short, and test with a throwaway folder before you roll it out widely.