# Revision: Cheat Sheet and Self-Check — AI Coding-Agent Guardrails

Source: https://www.geekswithgeeks.com/en/coding-agent-guardrails/wrap-revision

> Review the layers, controls and habits from the whole course.

## Cheat sheet

**Threat model**: destructive actions, secret exposure, injection, supply chain, scope creep, runaway cost; outside content is data. **Policy**: allow/ask/deny, unknown means ask, parse commands (do not prefix-match), allowed commands can still run code. **Sandbox**: resolve paths, container with only the project, protected paths. **Secrets and network**: clean environment, redaction as a net, exact-host egress allowlist, no metadata endpoint. **Git/CI**: branch only, server-side protection, size gate, CI scans, human approval. **Hooks/budgets**: pre-tool hooks fail closed, policy as code, session limits. **Operations**: audit log, red-team tests, incident checklist, kill switch.

## Questions interviewers ask

Be ready to explain: why prompts are not security controls, why a prefix allowlist is bypassable, why an allowlist is not a sandbox, how symlinks defeat naive path checks, how you would stop data exfiltration after a prompt injection, and what you do in the first ten minutes of an agent incident.

**Quiz:** A hook script crashes while checking a command. What should happen to that command?

- [ ] It is allowed to keep things moving
- [ ] It runs twice
- [x] It is blocked (fail closed)
- [ ] It is ignored forever

*Answer:* It is blocked (fail closed). A broken check must not silently allow risky actions.

**Quiz:** An injected instruction tells the agent to upload `.env` to a website. Which two controls most directly stop it?

- [x] Denying reads of .env and an egress allowlist
- [ ] A longer system prompt and a bigger font
- [ ] More commit messages
- [ ] Dark mode

*Answer:* Denying reads of .env and an egress allowlist. One control keeps the secret out of reach; the other blocks the destination, so the attack needs two failures.

**Quiz:** Which statement about prefix allowlists is correct?

- [ ] They are safe because commands are short
- [ ] They are required by Linux
- [ ] They replace sandboxes
- [x] They can be bypassed by chaining operators and substitution

*Answer:* They can be bypassed by chaining operators and substitution. `git status; rm -rf x` starts with an allowed prefix yet runs a second command.
