# CI and Review as the Final Authority — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/git-ci-authority

> Run tests, scanners and a human review in CI, outside the agent's control.

## Checks the agent cannot edit away

Local checks are advisory because an agent can change or skip them. The authoritative checks run in **CI on the server**, from configuration the agent cannot modify without review: unit tests, linters, **secret scanning**, dependency and vulnerability scanning, and a required **human approval** from a code owner. Make sure CI for pull requests from branches or forks does not receive production secrets.

## A CI job sketch

Names are illustrative. The point is that these steps run on the server and are required by branch protection.

```yaml
name: checks
on: pull_request
permissions: { contents: read }      # least privilege for the job token
jobs:
  verify:
    runs-on: ubuntu-latest
    steps:
      - uses: actions/checkout@v4
      - run: npm ci
      - run: npm run lint && npm test
      - run: npx gitleaks detect --no-banner      # secret scan
      - run: npm audit --audit-level=high         # dependency scan
```

## Do not let the agent approve itself

Require at least one human who is not the author. An agent that opens a pull request and also approves it, or merges with admin rights, defeats the purpose of review.

**Quiz:** Why are server-side CI checks more trustworthy than local checks?

- [ ] Local checks are always wrong
- [ ] CI is always faster
- [x] The agent cannot silently modify or skip them
- [ ] Local checks cost money

*Answer:* The agent cannot silently modify or skip them. Checks controlled outside the agent's environment remain valid even if the agent is compromised.
