Code: 02_ai-engineering-code/agent-gate/agent_gate/cli.py + README.md
Problem. Autonomous coding agents leak secrets, delete files, rewrite git history, and claim "done" without proof.
What I built. A portable, stdlib-only Python guardrail (no dependencies, drop into any repo), with 79 passing tests:
before-action — classifies a command/file-change into safe vs. dangerous lanes.verify — runs a built-in secret scanner (staged-diff regex for .env, *.pem, id_rsa, oversized files) plus configurable repo adapters.done-check — blocks completion claims unless required proofs are on record; in-progress wording isn't blocked.subagent open|close — scoped leases pinning a sub-agent to a goal + allowed paths + forbidden actions, refusing to close without returned evidence.hook PreToolUse — bridges into Claude Code to block red-lane commands (exit 2).Design stance. Off by default; fail-closed; never pretends an unprovable proof is satisfied. Hardened from a real incident where a prior agent leaked secrets via git add -A and silently killed a background job.
Why it matters. Direct evidence I understand agent failure modes and build proof-based, deterministic safety around them — squarely an AI-native infrastructure concern.
GG · Applied AI Engineering portfolio · synced to youdontneedmy.help design