Require query-before-modify, full-command display, explicit confirmation, and rollback preparation before any cloud CLI invocation that mutates infrastructure. Covers Azure (az), AWS (aws), GCP (gcloud, gsutil), Kubernetes (kubectl, helm), and Terraform/IaC (terraform). Born from a real production incident where a…
Require preview-before-modify, row-count disclosure, transactional execution, and rollback preparation before any SQL or ORM operation that mutates data or schema. Block destructive statements without a WHERE clause, schema drops without confirmation, prod migrations without dry-run, and raw string interpolation into…
Block container runtime escape paths, root-by-default images, build-time secrets baked into layers, and supply-chain risks from floating base tags before they reach a registry or a host. Require non-root USER, digest-pinned base images, BuildKit secret mounts (never ENV/ARG for secrets), --no-install-recommends +…
Block irreversible filesystem operations, history-destroying git commands on shared branches, network exposure to non-loopback interfaces, world-readable credential paths, and credential exfiltration patterns before they run on a developer or CI machine. Covers rm/find -delete/dd/chmod -R, git push --force/reset…
Block real customer data from appearing in test fixtures, code comments, documentation, debug output, or shared transcripts. Require synthetic generators (faker, @faker-js/faker, provider test cards), reserved test ranges (555 phone numbers, @example.com emails, RFC 5737 IPs), and redaction of PII/PHI/PCI from logs…
Detects and blocks hardcoded secrets — API keys, tokens, private keys, and database connection strings — before they are written to disk, committed to git, or echoed to logs. Covers 40+ patterns across Stripe, AWS, GitHub, GitLab, OpenAI, Anthropic, Slack, Google, SendGrid, Mailgun, Square, Twilio, and generic…
Govern how secrets are stored, scoped, distributed, rotated, and surfaced to running code — never committed .env files, never echoed in CI logs, never embedded in URLs or error messages, never shared across environments. Complements secret-blocking (which detects hardcoded patterns at write time) by enforcing the…
Block typosquats, unpinned dependencies, floating GitHub Actions tags, curl | bash installs, unverified agent skills/MCP servers, and post-install scripts from unknown publishers before they reach a developer machine, a CI runner, or a production image. Require lockfile-based installs, SHA-pinned third-party actions…