Rules Directory

Rule packs for AI coding agents.

Each pack is a set of Monitor and Block settings over Scopebond's built-in rules. In your workspace, open Rules, choose Browse community packs, and you see exactly what would change before anything does. Applying a pack follows your workspace's approval setting.

Open your workspace

Observe first

Every rule a workspace can change set to Monitor: see what your agents do for a week before anything is stopped.

For: Teams adopting Scopebond who want a baseline before they block. · By

RuleSettingDetails
Force-push to a protected branchMonitor—
Push to a protected branchMonitor—
Destructive shell commandMonitor—
Reading a secret fileMonitor—
Changing CI configurationMonitor—
Network accessMonitor—

Protect main

No agent pushes or force-pushes to main or master; everything else is recorded.

For: Any repository where main is the release line. · By

RuleSettingDetails
Force-push to a protected branchBlockprotected branches: main, master
Push to a protected branchBlockprotected branches: main, master

Release branches

Protects main, release/* and hotfix/* from agent pushes and force-pushes.

For: Teams that cut release and hotfix branches. · By

RuleSettingDetails
Force-push to a protected branchBlockprotected branches: main, release/*, hotfix/*
Push to a protected branchBlockprotected branches: main, release/*, hotfix/*

No destructive shell

Blocks the computer's destructive commands plus disk tools that wipe or format storage.

For: Agents that run in a developer's own machine. · By

RuleSettingDetails
Destructive shell commandBlockalso blocks: dd, mkfs, shred, wipefs, diskpart

Secrets locked

Agents cannot read secret files and cannot change CI configuration, where secrets are used.

For: Repositories with deploy credentials in CI. · By

RuleSettingDetails
Reading a secret fileBlock—
Changing CI configurationBlock—

CI guard

Agent edits to CI configuration are stopped; pushes to main are stopped; the rest is recorded.

For: Teams whose pipeline deploys to production. · By

RuleSettingDetails
Changing CI configurationBlock—
Push to a protected branchBlockprotected branches: main

Node.js network allowlist

Agents reach only the npm registry and GitHub; other sites are blocked.

For: JavaScript and TypeScript repositories. · By

RuleSettingDetails
Network accessBlockallowed sites: registry.npmjs.org, github.com, api.github.com, codeload.github.com, objects.githubusercontent.com, raw.githubusercontent.com

Python network allowlist

Agents reach only PyPI and GitHub; other sites are blocked.

For: Python repositories. · By

RuleSettingDetails
Network accessBlockallowed sites: pypi.org, files.pythonhosted.org, github.com, api.github.com, codeload.github.com, objects.githubusercontent.com

Docs-site friendly

Protects main and CI configuration, except the one workflow file that publishes documentation, which agents may edit. The exception needs hook 0.11.0 or later.

For: Repositories whose docs deploy from their own workflow. · By

RuleSettingDetails
Push to a protected branchBlockprotected branches: main
Changing CI configurationBlockskips paths: .github/workflows/docs.yml

Regulated repository

Every changeable rule blocks: protected branches, destructive shell, secret reads, CI edits, and network beyond GitHub.

For: Repositories under change control (SOC 2, ISO 27001, PCI). · By

RuleSettingDetails
Force-push to a protected branchBlockprotected branches: main, release/*
Push to a protected branchBlockprotected branches: main, release/*
Destructive shell commandBlock—
Reading a secret fileBlock—
Changing CI configurationBlock—
Network accessBlockallowed sites: github.com, api.github.com

Contribute a pack

Send a pack you run in a real repository to rules@scopebond.com: its settings, who it is for, and how you want to be credited. Every pack is checked against the same rules a workspace change is, and is listed with your name. An accepted pack earns its author Scopebond Team free for twelve months.

Implementers who publish packs can join the partner program: a partner author's pack carries a disclosed link to work with them, and partners earn commission on the workspaces they refer. Using a pack never attributes your workspace to anyone.