Developers struggle to enforce AI coding-agent boundaries
Mac developers and coding-agent users want agents confined to approved files and commands, with a chance to intervene when they go beyond those limits. Existing Claude Code hook workarounds often inspect raw shell strings, which developers report can be bypassed, while agents may still choose shell commands instead of built-in tools. A useful product could combine agent-level policies with OS or container isolation, but the evidence does not establish that one lightweight hook can enforce every boundary.
For developers using AI coding agents. Mentioned from Feb 2026 to Sep 2026 on GitHub and Hacker News.
5 different people described this problem in 3 separate discussions.
- Indie fit
- 5.0/10
- Pain
- 6.0/10
- Frequency
- 6.5/10
- Willingness to pay
- 0.0/10
- Momentum
- 4.7/10
- Who pays
- Professionals
- Competition
- High
- Build difficulty
- High
What people said
Quoted word for word. Follow a link to read the whole discussion.
I wish there was something like Lulu for file system access for an app/tool installed on a mac where I could set “/path” and that tool could access only that folder or its children and nothing else, if it tried I would get a popup
My env-guard/interpreter-guard hooks pattern-match raw Bash strings, with known bypasses we document ourselves (obfuscated payloads, git -c/-C prefixes)
Build brief
See what to build and who will buy it
- 2 product ideas with the smallest useful version and pricing
- 3 places to find your first customers
- 3 more quotes from people who have this problem
- Current workarounds, existing solutions and risks