━━ failproof ai · policy hub

policy-hub

every policy your agent can be held to, published as a github release and installed with one command. take a whole pack, one category, or a single policy — you pick, not us.

64 policies 3 packs 86 installs free & local
[ publish a pack → ]

packs are published by their authors, not audited by failproof ai. read the source before you install.[ read more ↓ ]

64 policies

  1. block-aws-cliinfra commandsPreToolUse

    Block aws CLI commands

    failproofai/policies
    72 installs
  2. block-az-cliinfra commandsPreToolUse

    Block az (Azure) CLI commands

    failproofai/policies
    72 installs
  3. block-curl-pipe-shdangerous commandsPreToolUsedefault

    Block piping downloads to shell

    failproofai/policies
    72 installs
  4. block-env-filesenvironmentPreToolUsedefault

    Block reading/writing .env files

    failproofai/policies
    72 installs
  5. block-force-pushgitPreToolUse

    Prevent force-pushing to any branch

    failproofai/policies
    72 installs
  6. block-gcloudinfra commandsPreToolUse

    Block gcloud (Google Cloud) CLI commands

    failproofai/policies
    72 installs
  7. block-gh-pipelineinfra commandsPreToolUse

    Block gh CLI pipeline-trigger subcommands (workflow run, run rerun/cancel, pr merge, release create/delete, cache delete, secret set/delete)

    failproofai/policies
    72 installs
  8. block-helminfra commandsPreToolUse

    Block helm commands

    failproofai/policies
    72 installs
  9. block-kubectlinfra commandsPreToolUse

    Block kubectl commands (Kubernetes cluster mutations)

    failproofai/policies
    72 installs
  10. block-push-mastergitPreToolUsedefault

    Block pushing to main/master

    failproofai/policies
    72 installs
  11. block-read-outside-cwdenvironmentPreToolUse

    Block file reads outside the session working directory

    failproofai/policies
    72 installs
  12. block-rm-rfdangerous commandsPreToolUse

    Prevent catastrophic deletions

    failproofai/policies
    72 installs
  13. block-secrets-writedangerous commandsPreToolUse

    Block writing secret key files

    failproofai/policies
    72 installs
  14. block-sudodangerous commandsPreToolUsePermissionRequestdefault

    Block sudo commands

    failproofai/policies
    72 installs
  15. block-terraforminfra commandsPreToolUse

    Block terraform and tofu (OpenTofu) commands

    failproofai/policies
    72 installs
  16. block-work-on-maingitPreToolUse

    Block git commits and merges on main/master branch

    failproofai/policies
    72 installs
  17. prefer-package-managerpackages & systemPreToolUse

    Blocks non-preferred package managers and tells Claude to use an allowed one (e.g., uv instead of pip)

    failproofai/policies
    72 installs
  18. protect-env-varsenvironmentPreToolUsedefault

    Prevent commands that read environment variables

    failproofai/policies
    72 installs
  19. Require CI checks to pass on the current HEAD commit before Claude stops (ignores stale runs on prior commits)

    failproofai/policies
    72 installs
  20. Require all changes to be committed before Claude stops

    failproofai/policies
    72 installs
  21. Require the current branch to merge cleanly with the base branch before Claude stops

    failproofai/policies
    72 installs
  22. Require a pull request to exist for the current branch before Claude stops

    failproofai/policies
    72 installs
  23. Require all commits to be pushed to remote before Claude stops

    failproofai/policies
    72 installs
  24. sanitize-api-keyssanitizePostToolUsedefault

    Stop Claude from reading API keys (OpenAI, Anthropic, GitHub, AWS, Stripe, Google) in tool responses

    failproofai/policies
    72 installs
  25. sanitize-bearer-tokenssanitizePostToolUsedefault

    Stop Claude from reading Authorization Bearer tokens in tool responses

    failproofai/policies
    72 installs
  26. sanitize-connection-stringssanitizePostToolUsedefault

    Stop Claude from reading database connection strings with embedded credentials in tool responses

    failproofai/policies
    72 installs
  27. sanitize-jwtsanitizePostToolUsedefault

    Stop Claude from reading JWTs in tool responses

    failproofai/policies
    72 installs
  28. sanitize-private-key-contentsanitizePostToolUsedefault

    Stop Claude from reading PEM private key content in tool responses

    failproofai/policies
    72 installs
  29. Warns before staging all working tree files with git add -A / . / --all

    failproofai/policies
    72 installs
  30. warn-background-processpackages & systemPreToolUse

    Warns before starting detached or background processes

    failproofai/policies
    72 installs
  31. warn-destructive-sqldatabasePreToolUse

    Warn before executing destructive SQL (DROP/TRUNCATE/DELETE without WHERE) via database clients

    failproofai/policies
    72 installs
  32. warn-git-amendgitPreToolUse

    Warns before amending git commits, which rewrites history

    failproofai/policies
    72 installs
  33. warn-git-stash-dropgitPreToolUse

    Warns before permanently deleting stashed changes

    failproofai/policies
    72 installs
  34. warn-global-package-installpackages & systemPreToolUse

    Warns before installing packages globally (npm -g, cargo install, etc.)

    failproofai/policies
    72 installs
  35. warn-large-file-writepackages & systemPreToolUse

    Warn before writing files larger than 1MB (configurable via thresholdKb param)

    failproofai/policies
    72 installs
  36. warn-package-publishpackages & systemPreToolUse

    Warn before publishing packages to public registries (npm, PyPI, crates.io, RubyGems, etc.)

    failproofai/policies
    72 installs
  37. warn-repeated-tool-callsai behaviorPreToolUse

    Warn when the same tool is called 3+ times with identical parameters

    failproofai/policies
    72 installs
  38. warn-schema-alterationdatabasePreToolUse

    Warns before SQL schema changes (ALTER TABLE with column or rename operations)

    failproofai/policies
    72 installs
  39. block-ci-config-editrepo hygienePreToolUse

    Block edits to CI workflow files — the thing that checks the work should not be edited by it

    chhhee10/deploy-guard
    13 installs
  40. block-lockfile-deleterepo hygienePreToolUsedefault

    Block deleting a lockfile — regenerating one silently moves every transitive dependency

    chhhee10/deploy-guard
    13 installs
  41. block-mutable-image-pushdeploysPreToolUsedefault

    Block docker push of a mutable tag (:latest, :prod, :stable) — push an immutable tag instead

    chhhee10/deploy-guard
    13 installs
  42. block-prod-deploydeploysPreToolUsedefault

    Block one-command deploys to production (vercel, fly, netlify, wrangler, serverless, eb)

    chhhee10/deploy-guard
    13 installs
  43. block-remote-db-shelldataPreToolUsedefault

    Block database shells pointed at a non-local host

    chhhee10/deploy-guard
    13 installs
  44. block-unscoped-sql-writedataPreToolUsedefault

    Block DROP / TRUNCATE and any DELETE or UPDATE with no WHERE clause

    chhhee10/deploy-guard
    13 installs
  45. require-conventional-commitrepo hygienePreToolUsedefault

    Require a Conventional Commits prefix on every commit message

    chhhee10/deploy-guard
    13 installs
  46. warn-bulk-exportdataPreToolUse

    Flag a query that writes rows out to a file

    chhhee10/deploy-guard
    13 installs
  47. warn-migration-deploydeploysPreToolUse

    Ask for a rollback plan before running a database migration

    chhhee10/deploy-guard
    13 installs
  48. Refuse a bucket-to-bucket copy whose two ends are in different regions

    chhhee10/cost-guard
    1 installs
  49. block-gpu-instance-launchcomputePreToolUsedefault

    Block launching 4+ GPU or A100/H100-class instances

    chhhee10/cost-guard
    1 installs
  50. block-large-scale-upcomputePreToolUsedefault

    Block scaling nodes or replicas to a large absolute count

    chhhee10/cost-guard
    1 installs
  51. Block creating an EKS/GKE/AKS/EMR cluster that bills while idle

    chhhee10/cost-guard
    1 installs
  52. Block launching 24xlarge-and-up or bare-metal instances

    chhhee10/cost-guard
    1 installs
  53. block-terraform-apply-without-plancomputePreToolUsedefault

    Block non-interactive terraform apply with no saved plan file

    chhhee10/cost-guard
    1 installs
  54. Refuse unlimited parallelism when each worker costs money

    chhhee10/cost-guard
    1 installs
  55. block-unbounded-retry-looprunawayPreToolUsedefault

    Refuse an unbounded loop that re-issues a billed call

    chhhee10/cost-guard
    1 installs
  56. Refuse multi-year log retention and replication rules; flag versioning with no expiry rule

    chhhee10/cost-guard
    1 installs
  57. block-unreaped-background-spendrunawayPreToolUsedefault

    Refuse to detach a billable job with nothing to reap it

    chhhee10/cost-guard
    1 installs
  58. Refuse a recursive copy or sync whose source is a whole bucket

    chhhee10/cost-guard
    1 installs
  59. Refuse a full dump of a managed database, or a snapshot restore into a new instance

    chhhee10/cost-guard
    1 installs
  60. bound-inference-job-concurrencyinferencePreToolUsedefault

    Refuse unbounded fan-out on a job that makes one model call per item

    chhhee10/cost-guard
    1 installs
  61. cap-frontier-eval-row-countinferencePreToolUsedefault

    Ask for a row cap before an eval loop runs a frontier model over a full dataset

    chhhee10/cost-guard
    1 installs
  62. Nudge for a deadline on a metered command that can hang

    chhhee10/cost-guard
    1 installs
  63. Ask for an output-token cap when a loop calls a hosted model per item

    chhhee10/cost-guard
    1 installs
  64. Ask for a sampled run before a fine-tune or an embedding pass over a full corpus

    chhhee10/cost-guard
    1 installs

━━ packs

━━ review before you install

packs are published by their authors. failproof ai does not review, audit, or certify them, and listing here is not an endorsement. the hub checksums every pack against the SHA256SUMS in its own release — that proves the file is the one that release published, and nothing else. it is not a signature: whoever controls the release controls both files, so it says nothing about who wrote the code, and nothing about whether the code is safe.

read the source before you install. a policy runs inside your agent's hook path on every call it matches, and sees the tool input your agent is about to act on. treat a third-party pack exactly as you would any other dependency you are about to give that access to.

━━ publish your own

no submission form, no approval queue. publish a release, tag your repo failproofai-policies, and it is indexed here within the hour.

how to publish →