How do you keep AI coding agents from doing something you'll regret?
Modern coding agents like Claude Code, Cursor and Codex can run shell commands, read files, install packages and connect to MCP servers on their own. For a solo founder that is the whole point, and also the risk. The practical answer in 2026 is three layers: keep the agent's built-in approvals on, add a local firewall such as the free, open-source HOL Guard, and make sure that if something does go wrong, the damage is small.
Verified · updated for 2026Built-in approvals
Every serious coding agent can ask before it runs commands or edits files. Keep that on, especially for anything that touches the internet or your secrets.
Read moreHOL Guard
A local firewall that pauses risky shell commands, secret reads, MCP changes and package installs for review before they run.
Read the verdictSmall blast radius
Secrets outside the project folder, capped API keys, and a separate environment for anything you're unsure about.
Read moreA year ago an AI coding assistant mostly suggested the next line. Today the agent opens a terminal, installs what it thinks it needs, reads your config files to understand the project and connects to tools through MCP. That is what makes it useful for a founder without a development team. It also means one confused or manipulated step can delete data, leak an API key or pull in a malicious package.
Layer 1: keep the built-in approvals on
Claude Code, Cursor, Codex and the other agents all let you require approval before commands run or files change, and most let you allow safe commands permanently while still asking about the rest. Use that. The real weakness is not the feature, it is fatigue: after a long session it is easy to approve everything without reading. That is where a second, more specific check helps.
Layer 2: HOL Guard, a local firewall for coding agents
HOL Guard sits on your own machine between the agent and the system. It can pause shell commands, reads of secrets and sensitive files, changes to MCP servers and package installs, and ask you before they happen. It keeps a record of what it decided and why, so security decisions don't disappear into terminal history. It supports Claude Code, Cursor, Codex, Gemini and several other agent harnesses.
It is open source under the Apache-2.0 licence, so the rules can be inspected, and the local version is free. Setup is two commands: pipx install hol-guard and hol-guard init. Teams that want shared policies and an overview across machines can add Guard Cloud, while enforcement still happens locally on each machine.
Its makers are refreshingly direct about the limits: a scan is not a safety guarantee, and it is not a web application firewall, an endpoint security product or a cloud MCP gateway. That is the right way to think about it: one strong layer, not the whole wall.
Layer 3: make the worst case small
Assume something will eventually slip through, and make sure it costs little when it does. Keep real secrets out of the folder your agent works in, or in a file it is told never to open. Give every API key the lowest limits and a spending cap. Use a separate test account for anything that can send email or move money. And for experiments you don't trust, run the agent in a container or a throwaway environment instead of your main machine.
How we'd actually decide
- If you only use an agent for small edits and read every prompt: built-in approvals plus the habits in layer 3 are enough.
- If your agent runs commands, installs packages or touches API keys on your own machine: add HOL Guard. It's free and takes minutes.
- If several people or machines run agents against the same systems: look at Guard Cloud for shared policy and visibility.
Product details checked against the makers' own descriptions and public listings in October 2026. StackIndex has no affiliate relationship with HOL.