How do you keep AI coding agents from doing something you'll regret?

Modern coding agents like Claude Code, Cursor and Codex can run shell commands, read files, install packages and connect to MCP servers on their own. For a solo founder that is the whole point, and also the risk. The practical answer in 2026 is three layers: keep the agent's built-in approvals on, add a local firewall such as the free, open-source HOL Guard, and make sure that if something does go wrong, the damage is small.

Verified · updated for 2026
LAYER 1 · FREE

Built-in approvals

Every serious coding agent can ask before it runs commands or edits files. Keep that on, especially for anything that touches the internet or your secrets.

Read more
LAYER 2 · FREE, OPEN SOURCE

HOL Guard

A local firewall that pauses risky shell commands, secret reads, MCP changes and package installs for review before they run.

Read the verdict
LAYER 3 · HABITS

Small blast radius

Secrets outside the project folder, capped API keys, and a separate environment for anything you're unsure about.

Read more

A year ago an AI coding assistant mostly suggested the next line. Today the agent opens a terminal, installs what it thinks it needs, reads your config files to understand the project and connects to tools through MCP. That is what makes it useful for a founder without a development team. It also means one confused or manipulated step can delete data, leak an API key or pull in a malicious package.

Layer 1: keep the built-in approvals on

Claude Code, Cursor, Codex and the other agents all let you require approval before commands run or files change, and most let you allow safe commands permanently while still asking about the rest. Use that. The real weakness is not the feature, it is fatigue: after a long session it is easy to approve everything without reading. That is where a second, more specific check helps.

Layer 2: HOL Guard, a local firewall for coding agents

HOL Guard sits on your own machine between the agent and the system. It can pause shell commands, reads of secrets and sensitive files, changes to MCP servers and package installs, and ask you before they happen. It keeps a record of what it decided and why, so security decisions don't disappear into terminal history. It supports Claude Code, Cursor, Codex, Gemini and several other agent harnesses.

It is open source under the Apache-2.0 licence, so the rules can be inspected, and the local version is free. Setup is two commands: pipx install hol-guard and hol-guard init. Teams that want shared policies and an overview across machines can add Guard Cloud, while enforcement still happens locally on each machine.

Its makers are refreshingly direct about the limits: a scan is not a safety guarantee, and it is not a web application firewall, an endpoint security product or a cloud MCP gateway. That is the right way to think about it: one strong layer, not the whole wall.

Layer 3: make the worst case small

Assume something will eventually slip through, and make sure it costs little when it does. Keep real secrets out of the folder your agent works in, or in a file it is told never to open. Give every API key the lowest limits and a spending cap. Use a separate test account for anything that can send email or move money. And for experiments you don't trust, run the agent in a container or a throwaway environment instead of your main machine.

How we'd actually decide

  • If you only use an agent for small edits and read every prompt: built-in approvals plus the habits in layer 3 are enough.
  • If your agent runs commands, installs packages or touches API keys on your own machine: add HOL Guard. It's free and takes minutes.
  • If several people or machines run agents against the same systems: look at Guard Cloud for shared policy and visibility.

Product details checked against the makers' own descriptions and public listings in October 2026. StackIndex has no affiliate relationship with HOL.

Frequently asked questions

Do I need a security tool if my coding agent already asks for permission?

The built-in approval prompts are your first line of defence, and you should keep them on. The problem is fatigue: after the hundredth prompt most people click yes without reading. A local firewall like HOL Guard adds a second check that looks specifically for risky patterns, such as reading a secrets file or installing an unknown package, so the dangerous ones stand out.

What is HOL Guard?

HOL Guard is an open-source (Apache-2.0), local-first firewall for AI coding agents. It runs on your own machine and can pause shell commands, secret and file reads, MCP server changes and package installs for review before they happen. It works with Claude Code, Cursor, Codex, Gemini and other agent harnesses. The local version is free; Guard Cloud is an optional paid layer for teams.

Is HOL Guard a guarantee that nothing bad will happen?

No, and its makers say so themselves: a scan is not a safety guarantee, and it is not a WAF, an EDR or a cloud MCP gateway. Treat it as one layer alongside keeping secrets out of your project folder, using limited API keys, and reviewing what your agent installs.

What is the single most important thing a solo founder can do?

Keep real secrets out of the folder the agent works in, and give every API key the lowest limits you can live with. If an agent ever reads or leaks a key, a capped key with a spending limit turns a disaster into an annoyance.