Never force-push to a protected branch, never rewrite shared history — the agent has to open a PR instead.
For: Teams running Cursor agents against a shared repository
Blocks `git push --force` and `--force-with-lease` onto a protected branch.
Blocks a rebase or reset that would rewrite already-pushed commits.
Escalates a direct push to the default branch so it routes through review.
# Cursor Protected-Branch Guard
# Fork: set protected_branches to your own list.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: cursor-protected-branch-guard
surface: cursor
standards: [SOC2-CC8.1, ISO27001-A.8.32]
defaults:
mode: shadow
emit_dossier: true
fail_closed: true
protected_branches: [main, master, release/*, production]
rules:
- name: force_push_block
when: "tool == 'Bash' AND command matches '^git\s+push'"
decision: |
BLOCK IF command matches '(--force|-f\b|--force-with-lease)' AND target_branch in protected_branches
ALLOW OTHERWISE
reason_code: force_push_to_protected_branch
- name: history_rewrite_guard
when: "tool == 'Bash'"
decision: |
BLOCK IF command matches '^git\s+(rebase|reset --hard|filter-branch)' AND branch.is_pushed == true
ALLOW OTHERWISE
reason_code: shared_history_rewrite
- name: direct_to_default_push
when: "tool == 'Bash' AND command matches '^git\s+push'"
decision: |
ESCALATE IF target_branch == repo.default_branch
ALLOW OTHERWISE
reason_code: bypasses_pull_request_review
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.
This recipe is one step in a path. The same five steps apply to every recipe in the exchange.
Run the policy against a realistic action in the browser. Push it past what the rules allow and watch the verdict come back. No account.
See exactly what was decided and why: the rule that fired, the evidence it read, the policy version in force, and an Ed25519 signature you can verify yourself.
Measure what the policy would have caught on your own traffic without touching the live path. Every recipe defaults to shadow, so the first deployment carries no execution risk.
Point the same policy at the system where the action actually originates — a checkout, an ERP posting, a Zap, an agent's tool call.
Publish the proof: a public verification link, an embeddable badge, a PR comment, or an anonymized shadow-mode finding. This is how the next person discovers Decionis.