F

faf-cli command protection

Reviewed HOL Guard coverage for faf-cli commands that write agent context.

Reviews faf-cli commands that write agent instruction files (AGENTS.md, CLAUDE.md, .cursorrules, GEMINI.md, Copilot instructions), add an MCP server to an agent's config, install git hooks, git drivers or CI workflows, send project context off the machine, or rewrite faf's own project files (project.faf, .fafb, soul.fafm, cards). Read-only commands (score, check, dna, context, drift, log, diff, convert, search, share, wjttc, info, formats, demo) are not matched by this extension; Guard's default handling for commands no rule matches still applies to them. Covers the `faf` and `faf-cli` executables; npx, bunx, pnpx, pnpm, yarn, npm exec, yarn exec, npm x, bun x, pnpm dlx and yarn dlx launches of either bin name; and versioned launches (`pkg@tag`) of the `faf-cli` npm package.

command.faf-cli · v1.0.0 · Specialized tools

By Community contributorExternal · opt-inCommand coverage
Protection rules
5
Permission checks
5
Mapped commands
5

Overview

What this coverage does

Reviews faf-cli commands that write agent instruction files (AGENTS.md, CLAUDE.md, .cursorrules, GEMINI.md, Copilot instructions), add an MCP server to an agent's config, install git hooks, git drivers or CI workflows, send project context off the machine, or rewrite faf's own project files (project.faf, .fafb, soul.fafm, cards). Read-only commands (score, check, dna, context, drift, log, diff, convert, search, share, wjttc, info, formats, demo) are not matched by this extension; Guard's default handling for commands no rule matches still applies to them. Covers the `faf` and `faf-cli` executables; npx, bunx, pnpx, pnpm, yarn, npm exec, yarn exec, npm x, bun x, pnpm dlx and yarn dlx launches of either bin name; and versioned launches (`pkg@tag`) of the `faf-cli` npm package.

Key facts

Catalog ID
command.faf-cli
Version
v1.0.0
Kind
Command coverage
Category
Specialized tools
Protection rules
5
Permission checks
5
Mapped commands
5
Maintainer
Community contributor(community, provenance recorded)
Source commit
bc11643
Protection model
External · opt-in
External · opt-in

External coverage. It must be enabled through Guard controls; this page does not activate it.

Stated limits

  • Coverage is limited to the reviewed operations and the surrounding Guard policy.
  • A maintainer profile is not a security certification or an official upstream endorsement.
fafcliagents-mdmcp

Command mapping

Every command this extension recognizes, with the catalog default floor Guard applies before workspace policy. Search the table, then open an operation for safe variants and the permission ID.

5 operations · 5 reviewed by default These are catalog defaults, not your workspace policy.

5 operations5 reviewed
Default floor

Showing 5 of 5 operations

  • Reviewed Guard intercepts the command for review before it runs.High
    • faf export --grok
    faf-cli agent MCP configuration write
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `faf export --grok` and its hidden alias `faf grok`, which add an MCP server entry to `.grok/config.toml` so a later Grok agent session starts that server automatically. A bare `faf export` or `faf export --all` never writes this file; only the explicit --grok flag or alias does.
    Documented safe variants
    faf-cli agent MCP configuration write help (--help)faf-cli agent MCP configuration write help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.faf-cli.permission.agent-tool-config
  • Reviewed Guard intercepts the command for review before it runs.High
    • faf hooks --install
    faf-cli git hook, git driver, or CI workflow change
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `faf hooks --install`/`--uninstall` (adds or removes a faf block in `.git/hooks/pre-commit`, which runs on every later commit), `faf diff --install-driver`/`--uninstall-driver` (sets or removes a git diff driver in the repository's git config and `.gitattributes`), and `faf taf ... --write` (`taf setup --write` creates `.github/workflows/taf.yml`, which runs in CI). `--write` is matche…
    Documented safe variants
    faf-cli git hook, git driver, or CI workflow change help (--hel…faf-cli git hook, git driver, or CI workflow change help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.faf-cli.permission.git-ci-persistence
  • Reviewed Guard intercepts the command for review before it runs.Medium
    • faf export --agents
    faf-cli agent instruction file write
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies commands that write files other coding agents load as instructions: `faf export` (AGENTS.md, .cursorrules, GEMINI.md, .github/copilot-instructions.md, llms.txt, project.html and a Server Card; a bare `faf export` writes several of these at once), `faf sync` / `bi-sync` (adds or refreshes a faf-managed block in CLAUDE.md; `--direction pull` writes into project.faf instead; with FAF_PRO=…
    Documented safe variants
    faf-cli agent instruction file write help (--help)faf-cli agent instruction file write help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.faf-cli.permission.agent-instructions-write
  • Reviewed Guard intercepts the command for review before it runs.Medium
    • faf ai analyze
    faf-cli project context sent off the machine
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies `faf ai analyze`, which sends the project's `project.faf` to the Anthropic API using ANTHROPIC_API_KEY, and `faf bench ... --submit`, which posts a benchmark receipt to the public bench ledger (default https://mcpaas.live/bench/submit, overridable with --endpoint). `faf share` is not matched: it encodes the file into a URL locally and sends nothing.
    Documented safe variants
    faf-cli project context sent off the machine help (--help)faf-cli project context sent off the machine help (-h)skip this operation when they are the documented preview or help form.
    Permission ID
    command.faf-cli.permission.data-egress
  • Reviewed Guard intercepts the command for review before it runs.Low
    • faf auto
    faf-cli project context file write
    Default floor
    Reviewed by default. Guard intercepts the command for review before it runs.
    Detector mode
    review
    What it matches
    Identifies commands that create or rewrite faf's own project files: project.faf and .faf-dna (`init`, `yolo`, `auto`, `loop`, `go`, `edit`, `migrate`, `recover`, `refresh`, `conductor import`, and `git <url>`, which also clones the public repository into a temporary directory), the .fafb binary (`compile`, `refresh`), soul.fafm (`memory etch`, `memory convert`), agent cards (`cards`, `server-card…
    Documented safe variants
    faf-cli project context file write help (--help)faf-cli project context file write help (-h)faf-cli migrate preview (--dry-run)faf-cli cards preview (--check)faf-cli server-card preview (--check)faf-cli git print-only (--stdout)skip this operation when they are the documented preview or help form.
    Permission ID
    command.faf-cli.permission.project-context-write

Tool state mapping

No per-tool overrides are declared. Command defaults above resolve through the workspace Guard policy unless a later policy layer changes them.

Runtime identity

Catalog ID
command.faf-cli
Guard enforcement ID
command.faf-cli
Source path
contributions/extensions/command.faf-cli.json
Contribution digest
sha256…90f0f3

Action classes

faf-cli agent tool configuration commandfaf-cli git and CI persistence commandfaf-cli data egress commandfaf-cli agent instruction write commandfaf-cli project context write command

Technical profile

No independent profile published

This extension has no current independent technical profile. Catalog facts and any legacy launch remain separate and are not presented as profile evidence.

FAQ

Frequently asked questions

Reviews faf-cli commands that write agent instruction files (AGENTS.md, CLAUDE.md, .cursorrules, GEMINI.md, Copilot instructions), add an MCP server to an agent's config, install git hooks, git drivers or CI workflows, send project context off the machine, or rewrite faf's own project files (project.faf, .fafb, soul.fafm, cards). Read-only commands (score, check, dna, context, drift, log, diff, convert, search, share, wjttc, info, formats, demo) are not matched by this extension; Guard's default handling for commands no rule matches still applies to them. Covers the `faf` and `faf-cli` executables; npx, bunx, pnpx, pnpm, yarn, npm exec, yarn exec, npm x, bun x, pnpm dlx and yarn dlx launches of either bin name; and versioned launches (`pkg@tag`) of the `faf-cli` npm package. The listing declares 5 rules and 5 permission checks. 5 operations · 5 reviewed by default. Coverage is limited to these reviewed operations and the surrounding Guard policy.

External · opt-in: External coverage. It must be enabled through Guard controls; this page does not activate it. Enabling state is always controlled through Guard policy, never from this directory.

This listing entered the catalog as a community contribution through a public pull request with recorded provenance, with public credit to @Wolfe-Jam, and 1 GitHub maintainer is recorded on the listing. Credit is attribution only. A verified publisher profile and the claim flow verify authority separately; neither is an upstream endorsement or a HOL safety certification.

No. Every listing documents source, activation model, maintainer identity, and stated limitations so you can evaluate coverage before enabling it. Review the stated limitations and the exact source tree before relying on any single control.

5 operations · 5 reviewed by default. Examples: faf export --grok (reviewed by default); faf hooks --install (reviewed by default); faf export --agents (reviewed by default); faf ai analyze (reviewed by default); faf auto (reviewed by default). These are catalog defaults, not your workspace policy.

External coverage. It must be enabled through Guard controls; this page does not activate it. Enablement is managed through your workspace's Guard policy and controls — never from this directory. Open the install guidance for the setup flow, then adjust the command coverage for command.faf-cli in Guard's policy surface.

The matching action is stopped at Guard's pre-action boundary before it executes, and the decision is recorded with evidence your workspace can review. Exact behavior follows your Guard policy combined with this entry's 5 rules and 5 permission checks.

No. Guard is local-first: interception, decisions, and evidence stay on your machine unless your workspace explicitly configures cloud features. This page is documentation only — it never executes a command or changes protection state.

Guard runs locally alongside the major AI coding agents and MCP-capable harnesses, so this coverage applies wherever Guard intercepts actions. See the supported harness guides at https://hol.org/guard/harnesses for per-tool approval behavior and limitations.

Guard has a free local tier that includes command interception, evidence, and the policy controls this listing documents. Team plans add shared policy, review queues, and audit surfaces. Current plans: https://hol.org/guard/pricing

Open an issue or pull request against the hol-guard repository, where the canonical catalog lives: https://github.com/hashgraph-online/hol-guard Listings are corrected through the same public review process that adds them.

Yes. Community extensions are merged through public pull requests with recorded provenance, and you can claim the publisher page for a contribution you maintain through the Publisher Studio.

The command mapping table is the audit trail for covered commands and catalog default floors. Pair it with the reviewed rule and permission counts, the per-tool state mapping, and the exact source tree linked from View exact source at the reviewed commit. Guard records enforcement decisions with evidence locally, so what ships matches what you reviewed.