How are you actually catching unsafe stuff before an agent runs it, not after?

Reddit r/AI_Agents News

Summary

The author discusses the lack of robust safety enforcement in AI coding agents like Claude Code and Cursor, relying on prompt instructions and manual review, and seeks input on actual pre-execution policy enforcement methods.

Been building on Claude Code / Cursor for client work and realized my only real protection right now is prompt instructions telling the agent what not to touch. That's not enforcement, it's a suggestion. Had a moment last week where I noticed a project had zero RLS on the DB, agent built it, tests passed, nothing flagged it. Would've shipped exactly like that if I hadn't happened to check. Curious what people are actually running: is there real policy enforcement before a command executes, or is everyone still relying on system-prompt rules and manual review before anything touches prod?
Original Article

Similar Articles

@akshay_pachaar: https://x.com/akshay_pachaar/status/2067646389291725258

X AI KOLs Following

AI coding agents like Claude Code can be dangerous because they generate code without considering authorization and operational safety, potentially leading to unauthorized writes like deleting production databases. The real risk is not the code quality but the lack of runtime access controls.