Three things that stop AI coding tools from touching half your codebase for a one-line fix.
bash install.sh /path/to/your-repoThen commit the new files so your whole team gets them:
git add AGENTS.md scripts/ .windsurf/ .devin/
git commit -m "add ai-guardrails"Each developer runs install.sh once after cloning — the git hook is local only.
AGENTS.md — loaded automatically by every AI tool at session start. Before writing anything, the AI must:
- Trace the code and state what it found
- List what it doesn't know
- Offer 2–3 approaches ranked by risk
- Ask one question if something is genuinely unclear
- Announce which files it will change — then make only those changes
Pre-commit hook — fires on every git commit. If the change is > 3 files or > 150 lines, it warns you and asks yes/no. Bypasses are logged to ~/.ai-guardrails-audit.log.
IDE hook — same check, fires inside Windsurf or Devin right after the AI writes.
Defaults: 3 files, 150 lines. Either one triggers the warning.
# Override for a single commit
AI_GUARD_MAX_FILES=5 git commit -m "..."Nothing is hard-blocked. git commit --no-verify skips the check entirely.