Guided first use

Try faf-cli command protection

Reviewed HOL Guard coverage for faf-cli commands that write agent context. Follow the three steps below with your own setup — nothing on this page runs on your machine or changes a policy.

Step 1 · Check fit

What this coverage governs

Reviews faf-cli commands that write agent instruction files (AGENTS.md, CLAUDE.md, .cursorrules, GEMINI.md, Copilot instructions), add an MCP server to an agent's config, install git hooks, git drivers or CI workflows, send project context off the machine, or rewrite faf's own project files (project.faf, .fafb, soul.fafm, cards). Read-only commands (score, check, dna, context, drift, log, diff, convert, search, share, wjttc, info, formats, demo) are not matched by this extension; Guard's default handling for commands no rule matches still applies to them. Covers the `faf` and `faf-cli` executables; npx, bunx, pnpx, pnpm, yarn, npm exec, yarn exec, npm x, bun x, pnpm dlx and yarn dlx launches of either bin name; and versioned launches (`pkg@tag`) of the `faf-cli` npm package.

External — off until you opt in

This coverage stays off until you explicitly enable it from your Guard workspace controls. Reading this page never changes your policy; activation happens in Guard itself.

Harness support

No harness compatibility profile is published yet. Check the Guard harness guide for what your setup uses.

Are you the publisher? Complete this section in your Studio — until then this stays unknown for readers instead of being guessed.

Catalog version 1.0.0 · source snapshot 97acff7b9a

Step 2 · Set up

Install and activate

No reviewed setup steps are published for this coverage yet. Install Guard itself, then return here after the publisher publishes a guide — or ask for one. Are you the publisher? Complete this section in your Studio.

New to Guard? Start with Install Guard. Already installed? Skip install — this coverage stays off until you enable it from your workspace controls.

Activation happens in your Guard workspace. This page links to it; it never enables the coverage for you.

Missing the setup information you need? Request setup documentation — the publisher reviews requests before anything is published here.

Back to fit

Step 3 · Verify the result

Run a safe test and compare

Safe fixture inputs

No published safe fixture yet. Try the coverage against a harmless command of your own — not production traffic.

Are you the publisher? Complete this section in your Studio — until then this stays unknown for readers instead of being guessed.

Expected outcome

No expected outcome published yet. Guard surfaces what it matched — the rule and its decision — in its own activity view; compare that with this coverage’s stated rules to inspect the actual decision.

Are you the publisher? Complete this section in your Studio — until then this stays unknown for readers instead of being guessed.

Outcome reporting

This coverage has no claimed publisher page yet, so outcome reports are not collected. You can still verify the result locally against the expected outcome above.