Guided first use
Try faf-cli command protection
Reviewed HOL Guard coverage for faf-cli commands that write agent context. Follow the three steps below with your own setup — nothing on this page runs on your machine or changes a policy.
Step 1 · Check fit
What this coverage governs
Reviews faf-cli commands that write agent instruction files (AGENTS.md, CLAUDE.md, .cursorrules, GEMINI.md, Copilot instructions), add an MCP server to an agent's config, install git hooks, git drivers or CI workflows, send project context off the machine, or rewrite faf's own project files (project.faf, .fafb, soul.fafm, cards). Read-only commands (score, check, dna, context, drift, log, diff, convert, search, share, wjttc, info, formats, demo) are not matched by this extension; Guard's default handling for commands no rule matches still applies to them. Covers the `faf` and `faf-cli` executables; npx, bunx, pnpx, pnpm, yarn, npm exec, yarn exec, npm x, bun x, pnpm dlx and yarn dlx launches of either bin name; and versioned launches (`pkg@tag`) of the `faf-cli` npm package.
External — off until you opt in
This coverage stays off until you explicitly enable it from your Guard workspace controls. Reading this page never changes your policy; activation happens in Guard itself.
Harness support
No harness compatibility profile is published yet. Check the Guard harness guide for what your setup uses.
Are you the publisher? Complete this section in your Studio — until then this stays unknown for readers instead of being guessed.
Catalog version 1.0.0 · source snapshot 97acff7b9a
Step 2 · Set up
Install and activate
No reviewed setup steps are published for this coverage yet. Install Guard itself, then return here after the publisher publishes a guide — or ask for one. Are you the publisher? Complete this section in your Studio.
New to Guard? Start with Install Guard. Already installed? Skip install — this coverage stays off until you enable it from your workspace controls.
Activation happens in your Guard workspace. This page links to it; it never enables the coverage for you.
Missing the setup information you need? Request setup documentation — the publisher reviews requests before anything is published here.
Step 3 · Verify the result
Run a safe test and compare
Safe fixture inputs
No published safe fixture yet. Try the coverage against a harmless command of your own — not production traffic.
Are you the publisher? Complete this section in your Studio — until then this stays unknown for readers instead of being guessed.
Expected outcome
No expected outcome published yet. Guard surfaces what it matched — the rule and its decision — in its own activity view; compare that with this coverage’s stated rules to inspect the actual decision.
Are you the publisher? Complete this section in your Studio — until then this stays unknown for readers instead of being guessed.
Outcome reporting
This coverage has no claimed publisher page yet, so outcome reports are not collected. You can still verify the result locally against the expected outcome above.