If a repository command’s safety check reaches its deadline before it can decide, the agent should treat the command as unverified—not safe. Request human review only when the hook protocol can actually deliver a decision to an operator. In unattended sessions, configure unverified commands to be denied.
That is the policy documented by Destructive Command Guard (dcg), not a universal standard for every coding-agent hook. Its documentation separates an evaluation timeout from malformed input, transient I/O failures, oversized commands, and script-extraction failures; those cases do not all receive the same treatment.
As an Amazon Associate I earn from qualifying purchases.
What should an agent do when a command safety check times out?
Deny execution unless a real operator-review path is available and the policy explicitly requests review. A deadline expiry means the evaluator did not establish whether the command is safe; it does not establish that the command is dangerous, but it also does not justify allowing it.
The dcg project documentation states: “It never treats elapsed analysis time or an oversized extracted command as proof that execution is safe.” When its absolute evaluation deadline expires, dcg returns an indeterminate result. A hook that supports operator review can request an “ask” decision; when review is unavailable, the result blocks unless configuration selects another outcome.
#1 Best Overall
- POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
For unattended sessions, dcg recommends explicitly denying unverified outcomes:
- Configuration:
general.unverified_decision = "deny" - Environment variable:
DCG_UNVERIFIED_DECISION=deny
The documented examples of unverified outcomes include deadline-expired evaluations and extracted commands that exceed the configured size limit. This is a dcg policy recommendation, not a claim that every hook or agent exposes the same controls.
How long is the documented deadline, and how can it be changed?
In dcg, the ordinary end-to-end hook evaluation deadline defaults to 1000 ms. The careful_company_running_windows preset defaults to 3000 ms. These are documented configuration defaults, not measurements of typical evaluation speed or a general recommendation for all systems.
What’s actually slowing this PC down?
Pick the symptom - the matching free tool is one click away.
Rank #2
- POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
| Setting | Documented value or effect |
|---|---|
| Ordinary hook evaluation deadline | 1000 ms by default |
careful_company_running_windows preset |
3000 ms by default |
general.hook_timeout_ms |
Explicit setting overrides the applicable default |
DCG_HOOK_TIMEOUT_MS |
Explicit environment setting overrides the applicable default |
| Explicit timeout below 10 ms | Clamped to the documented 10 ms safety minimum |
The dcg documentation does not establish a single correct timeout for every repository, host, or workload. It advises increasing hook_timeout_ms on heavily loaded hosts and using dcg test --enforce-budget to exercise the evaluator-side budget outside a live hook. A longer deadline gives evaluation more time, but the hook still needs a bounded wait: once its deadline expires, the result remains unverified.
Why use a wall-clock deadline?
dcg measures the deadline using monotonic wall-clock time. The project documentation explains that a CPU-time budget would stop advancing while the process is descheduled or waiting on a bounded operation, so it could not guarantee hook latency. A monotonic clock also avoids treating a change to the system’s calendar clock as elapsed evaluation time.
Because this deadline is end-to-end, it covers the time available to finish hook evaluation rather than only CPU work. The practical consequence is that a busy host or a slow bounded operation can consume the available time even if the evaluator is not continuously using the processor.
Rank #3
- POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
- WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
- FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
- MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
- PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Which failures are different from a timeout?
Do not collapse every hook failure into one “fail closed” switch. dcg documents different handling for failures that occur before evaluation, failures while reading input, an evaluation that runs out of time, and failures extracting embedded script content.
Quick wins for a faster PC:
Clear out junk files and repair common Windows errorsFree Scan →Scan for outdated or missing drivers - takes under a minuteDriver Scan →| Failure case | Documented dcg handling | Practical meaning |
|---|---|---|
| Malformed or oversized raw hook JSON | Allowed with an audit warning by default; denied when general.fail_closed = true. |
The top-level hook envelope could not be read as valid input. This is separate from an evaluation that began but did not finish. |
| Transient hook stdin I/O error | Fail-open. | The documented general.fail_closed setting does not change this case into a denial. |
| Absolute evaluation deadline expires | Indeterminate result; requests review where supported, otherwise blocks, subject to the configured unverified decision. | The safety check began but did not establish a result in time. |
Extracted command exceeds max_command_bytes |
Indeterminate result. | An oversized extracted command is not treated as safe merely because it could not be fully evaluated. |
| Heredoc or inline-script extraction/parsing failure | Uses a bounded fallback scanner; configuration can disable fallback on parse error or timeout to block. | Embedded-code parsing has its own fallback and failure policy; it is not the raw JSON policy or the deadline-expiry policy. |
These behaviors are documented in the dcg project’s Bounded Failure Policy and Absolute Evaluation Deadline documentation. Since they are implementation-specific and can change, check the project documentation for the version and configuration you deploy.
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.How to choose review or denial
Interactive agent with a working review channel
Use a review outcome only if the hook protocol can surface the request to a person who can decide before execution proceeds. A setting that says “ask” is not useful protection if the session is unattended, the client cannot display the prompt, or no operator is available. In those cases, configure unverified outcomes to deny.
Rank #4
- POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
- WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
- FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
- TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
- BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.
Unattended agent or CI job
Set general.unverified_decision = "deny" or DCG_UNVERIFIED_DECISION=deny, then confirm that your hook integration actually applies that configuration to deadline-expired and oversized extracted commands. Do not infer denial from a separate setting for malformed JSON: dcg documents that malformed JSON is allowed by default, and transient stdin I/O errors remain fail-open.
Slow or heavily loaded host
First establish whether the delay comes from evaluator work or host contention. dcg recommends increasing hook_timeout_ms under heavy load and testing the evaluator-side budget with dcg test --enforce-budget. Keep the unverified-outcome policy explicit while adjusting the deadline; raising the timeout should not turn an elapsed evaluation into permission to run the command.
What a sound hook policy should make explicit
- What happens when the end-to-end deadline expires, and whether an “ask” result can reach a human.
- Whether unattended runs deny commands whose safety remains unverified.
- How malformed or oversized hook input differs from transient stdin I/O failure.
- How oversized extracted commands and embedded-script extraction or parsing failures are handled.
- Whether the deadline is wall-clock and bounded, and which configuration values override defaults.
The cited dcg documentation provides one concrete implementation, not a comparison of competing hooks. Its timeout values and failure policies should be read as dcg-specific configuration behavior, not as industry-wide defaults.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.




