protect-agent-config
v0.2.0by open-coder-ai · author: chock-core
protect-agent-config is an Agent Plugin published by open-coder-ai. It packages 1 skill. We fetched the plugin.json from GitHub on 2026-10-02 and checked it against the official Agent Plugins 1.0.0 schema.
Guard against an agent hand-editing its own guardrails. Agent instruction files (AGENTS.md and the per-agent wrappers), permission files (.claude/settings.json,.mcp.json), the dependency allowlist (.chock/dependency-allowlist.txt) and vendored enforcement (.chock/bin/,.chock/compiled/) define what the agent may do, so a shell command that rewrites them is the agent modifying its own authority (MITRE ATLAS AML.T0081). The guard refuses shell writes to those paths, a redirect, rm/mv/tee/sed -i, cp into the path, git checkout/restore, PowerShell Set-Content/Add-Content/Out-File; reads and copies out pass, and `chock sync` passes. Best-effort and deliberately coarse. The 'chock: approved-config-change' marker is friction plus an audit trail, not authentication. A second, tool_use-only gate refuses Edit/Write to the same paths; it never runs at commit, so a person stays free to edit them.
- Skills
- 1
- MCP servers
- 0
- Stars
- 8
- License
- Apache-2.0
- Repo created
- 2026-08-17
- Last pushed
- 2026-10-02
- Publisher type
- Organization
- Version
- 0.2.0
Links
Skills · 1
- protect-agent-config
- Guard against an agent hand-editing its own guardrails. Agent instruction files (AGENTS.md and the per-agent wrappers), permission files (.claude/settings.json,.mcp.json) and vendored enforcement (.chock/bin/,.chock/compiled/) define what the agent may do, so a shell command that rewrites them…
Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
Category
Security & Compliance. Assigned by this directory. Agent Plugins 1.0.0 has no category field, so no manifest declares one.
Keywords
chock · policy-as-code · rule · advise · asi03
Related by publisher and keywords
Give each agent its own scoped, short-lived identity so a compromise does not inherit a human's or a shared account's full permissions. Use when an agent needs credentials, a service account, a cloud role, an API token, or when reviewing delegation and impersonation between an agent and its user. Do NOT use for keeping secrets out of the repository, that is `code-safety` and `scan-secrets`.
trigger: edits without reading, unverified completion claims, weakened tests, dead code. avoid: skipping verification, deleting assertions, leaving unused code.
Best-effort guard against destructive commands, read as parsed commands (bash -c and cd chains included, echo excluded): rm -rf on absolute, home ($HOME/~) or root-adjacent paths (and PowerShell Remove-Item -Recurse); git push --force (not --force-with-lease), reset --hard, clean -f; kubectl delete; terraform destroy; aws s3 rm --recursive / rb --force; dropdb; helm uninstall/delete; docker volume rm/prune and system prune; gcloud... delete; find -delete / -exec rm; shred; truncate; wipefs -a. git branch -D asks first. Verbs are matched position-aware, so a bucket or object NAMED like a verb is allowed, and a relative path in the working tree stays allowed. sudo, doas and pkexec are transparent. A pre-push hook refuses any non-fast-forward push, force, +refspec or lease alike; a human escapes with git push --no-verify. Known bypasses: aliases, an unusual value-flag, interpreters and scripts. Friction, not a security boundary.
Best-effort guard against bypassing git hooks via git commit/push --no-verify, commit's short -n form, or any way of pointing core.hooksPath elsewhere: -c, --config-env, `git config core.hooksPath <path>` and the GIT_CONFIG_* environment. Read as a parsed command, so `cd repo && git commit --no-verify`, `bash -c '...'` and sudo/env/xargs wrappers are caught and a message that merely says --no-verify is not. On git push, -n means --dry-run and stays allowed. Known bypass classes include aliases, wrapper scripts, and non-standard clients. Also refuses an agent command that sets a person-only override (CHOCK_ALLOW*, CHOCK_AGENT_COMMIT, CHOCK_DIFF_LIMIT) by env prefix, env, export, declare, set/setx or $env:, and refuses hiding the agent markers (CLAUDECODE, AI_AGENT, CHOCK_AGENT_COMMIT) by unset, env -u/-i, export -n or Remove-Item Env:; it tells the agent to ask the person. Fix the underlying hook failure instead of skipping validation.
trigger: secrets, eval/exec, unsanitized SQL, hallucinated dependencies. avoid: committing credentials, adding unverified packages, executing dynamic code. Install scan-secrets for the enforced counterpart of the secret slice (a commit-time gate), and verify-dependency-exists for the dependency slice (opt-in: disabled by default, needs a curated allowlist); the eval/exec and unsanitized-SQL guidance stays advisory (a gate can decide only the non-literal slice: agentic-code-security's code pack).
trigger: context bloat, stale observations, resolved content inlined, noisy exploration. avoid: context rot and lost-in-the-middle failures.
[](https://agentpluginsdirectory.com/plugins/protect-agent-config)✓ Verified . We fetched the manifest from GitHub and checked it against the official Agent Plugins 1.0.0 schema at agent-plugins.org.