Skip to main content
A pack is a set of policies published as a GitHub release. One command installs it: the release’s checksums are verified before anything runs, and its digest is recorded so the pack cannot change under your machine afterwards. Browse every pack, and every policy in each, on the policy hub. There are two kinds:
  • Failproof AI policy packs — ready-made packs for predefined use cases: plug one in and it works. The coding agent policy pack is available now, and packs for more use cases are coming soon.
  • Community policy packs — policies developers have written for their own use cases and published for anyone to take.

Failproof AI policy packs

Coding agent policy pack

The pack carries 39 policies and switches on the 10 its manifest marks safe to enable unattended; the rest are listed for you to choose from. Some of the most used, and whether a plain policies add switches them on: Switch on any that are off by name — failproofai policies add block-rm-rf — or take the whole pack with --all. See every policy in it, grouped by category:

Community policy packs

Developers publish packs for the use cases they have met, and the policy hub lists them. A community pack is published by its author, not audited by Failproof AI, so read what it carries before installing it:
That lists every policy it carries, grouped by category, and marks which ones its author switches on by default. It reads only the manifest — the entry artifact is never downloaded or imported, so looking at a stranger’s pack cannot run a stranger’s code. The manifest is still checked against the release’s own SHA256SUMS, so what you read is what would install. Then install it:
Any of these work — paste whichever you have: Naming no tag installs the newest release and pins it, then tells you which tag it chose. What gets recorded always names exactly one release, so a reinstall cannot drift.

Take part of a pack

By default you get the pack’s own defaults — the policies its author marked safe to switch on unattended — not everything it contains.
--category and --policy combine as a union (--only is accepted as a synonym for --policy), and each may be repeated: --policy a --policy b takes both. When the pack is already installed, the flags add to what you had, and re-adding it with no flag and no terminal — to upgrade, say — keeps your selection as it is. At a terminal with no flag, add opens the picker instead, pre-ticked with the author’s defaults, and what you tick replaces your selection.

Manage what is on

Switching a pack policy on or off applies to the whole machine: the switch is recorded with the installed pack, not in a project’s configuration, whatever --scope says. A name with no slash is a policy; anything with one is a pack source. A bare name resolves to the installed pack that declares it. When two installed packs declare the same name, name the one you mean:
Scopes, parameters, and the files these commands write are covered in local configuration.

What integrity does and does not buy

SHA256SUMS ships in the same release as the artifact, so it is not a signature and proves nothing about who published it. What it does prove is that the bytes are the ones that release published — and because the digest is recorded when you add the pack and re-verified before every import, a pack cannot change under your machine afterwards. A repository that retags or replaces an asset stops loading instead of quietly running something else. At install time the pack is also imported once and checked against its own manifest. A pack whose artifact does not parse, or that registers something other than what it declares, is refused before anything is activated — rather than installing cleanly and failing on your next tool call. So is a pack whose id claims the FailproofAI/ namespace but whose release is not in a FailproofAI repository.

When a pack will not load

A pack this machine was told to enforce and cannot run denies the events its missing policies covered, rather than allowing them silently — as pack/failproofai-pack-unavailable, which outranks the policies that did load so the deny is attributed to the missing pack rather than to whichever guard happened to fire first. The exception is UserPromptSubmit, which instructs instead: denying there would lock you out of the agent you need in order to fix it. See Failure behavior. A pack can name the oldest failproofai it works with (minCliVersion, set by its publisher). An older CLI refuses to add it and prints the upgrade command, npm i -g "failproofai@>=<minCliVersion>" && failproofai update (a range, so npm picks a release that meets it — a bare failproofai installs latest, which can be older than a prerelease minimum); one already installed that the running CLI is too old for does not load, with the result above. A minCliVersion the CLI cannot read is ignored with a warning rather than refusing the pack.

Offline and mirrors

To share your own policies this way, see Publish a policy pack.