October DealsAmazon USOctober deal check: compare before you payAmazon US: current deals, useful picks and tech finds.Check DealsWindows FixRecommendedWindows errors stealing your time? Find the fix fastScan stability, cleanup and performance issues.Fix NowOctober DealsAmazon USDeal season is back - check today's better picksAmazon US: current deals, useful picks and tech finds.See Picks×
Skip to content
World desk5 min

Fail Closed on Path Delay: How Local-First Agents Should Handle Command-Safety Deadlines

A command-safety timeout is an unverified result, not proof that execution is safe. See when a local-first agent should request review, deny, or adjust its bounded hook deadline.
Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

If a repository command’s safety check reaches its deadline before it can decide, the agent should treat the command as unverified—not safe. Request human review only when the hook protocol can actually deliver a decision to an operator. In unattended sessions, configure unverified commands to be denied.

That is the policy documented by Destructive Command Guard (dcg), not a universal standard for every coding-agent hook. Its documentation separates an evaluation timeout from malformed input, transient I/O failures, oversized commands, and script-extraction failures; those cases do not all receive the same treatment.

As an Amazon Associate I earn from qualifying purchases.

What should an agent do when a command safety check times out?

Deny execution unless a real operator-review path is available and the policy explicitly requests review. A deadline expiry means the evaluator did not establish whether the command is safe; it does not establish that the command is dangerous, but it also does not justify allowing it.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

The dcg project documentation states: “It never treats elapsed analysis time or an oversized extracted command as proof that execution is safe.” When its absolute evaluation deadline expires, dcg returns an indeterminate result. A hook that supports operator review can request an “ask” decision; when review is unavailable, the result blocks unless configuration selects another outcome.

#1 Best Overall
Yubico - Security Key C NFC - Basic Compatibility - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key C NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key C NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key C NFC via USB-C and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

For unattended sessions, dcg recommends explicitly denying unverified outcomes:

  • Configuration: general.unverified_decision = "deny"
  • Environment variable: DCG_UNVERIFIED_DECISION=deny

The documented examples of unverified outcomes include deadline-expired evaluations and extracted commands that exceed the configured size limit. This is a dcg policy recommendation, not a claim that every hook or agent exposes the same controls.

How long is the documented deadline, and how can it be changed?

In dcg, the ordinary end-to-end hook evaluation deadline defaults to 1000 ms. The careful_company_running_windows preset defaults to 3000 ms. These are documented configuration defaults, not measurements of typical evaluation speed or a general recommendation for all systems.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Rank #2
Yubico - YubiKey 5 NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-A or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5 NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5 NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5 NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts
Setting Documented value or effect
Ordinary hook evaluation deadline 1000 ms by default
careful_company_running_windows preset 3000 ms by default
general.hook_timeout_ms Explicit setting overrides the applicable default
DCG_HOOK_TIMEOUT_MS Explicit environment setting overrides the applicable default
Explicit timeout below 10 ms Clamped to the documented 10 ms safety minimum

The dcg documentation does not establish a single correct timeout for every repository, host, or workload. It advises increasing hook_timeout_ms on heavily loaded hosts and using dcg test --enforce-budget to exercise the evaluator-side budget outside a live hook. A longer deadline gives evaluation more time, but the hook still needs a bounded wait: once its deadline expires, the result remains unverified.

Why use a wall-clock deadline?

dcg measures the deadline using monotonic wall-clock time. The project documentation explains that a CPU-time budget would stop advancing while the process is descheduled or waiting on a bounded operation, so it could not guarantee hook latency. A monotonic clock also avoids treating a change to the system’s calendar clock as elapsed evaluation time.

Because this deadline is end-to-end, it covers the time available to finish hook evaluation rather than only CPU work. The practical consequence is that a busy host or a slow bounded operation can consume the available time even if the evaluator is not continuously using the processor.

Rank #3
Yubico - YubiKey 5C NFC - Multi-Factor authentication (MFA) Security Key and passkey, Connect via USB-C or NFC, FIDO Certified - Protect Your Online Accounts
  • POWERFUL SECURITY KEY: The YubiKey 5C NFC is the most versatile physical passkey, protecting your digital life from phishing attacks. It ensures only you can access your accounts
  • WORKS WITH 1000+ ACCOUNTS: Compatible with popular accounts like Google, Microsoft, and Apple. A single YubiKey 5C NFC secures 100+ of your favorite accounts, including email, password managers, and more
  • FAST & CONVENIENT LOGIN: Plug in your YubiKey 5C NFC via USB and tap it, or tap it against your phone (NFC), to authenticate. No batteries, no internet connection, and no extra fees required
  • MOST SECURE PASSKEY: Supports FIDO2/WebAuthn, FIDO U2F, Yubico OTP, OATH-TOTP/HOTP, Smart card (PIV), and OpenPGP. That means it’s versatile, working almost anywhere you need it
  • PRIMARY & SPARE KEYS: Just like having a spare house key, we recommend buying two YubiKeys - one for daily use and one as a spare. That way you’ll never get locked out of your accounts

Which failures are different from a timeout?

Do not collapse every hook failure into one “fail closed” switch. dcg documents different handling for failures that occur before evaluation, failures while reading input, an evaluation that runs out of time, and failures extracting embedded script content.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Failure case Documented dcg handling Practical meaning
Malformed or oversized raw hook JSON Allowed with an audit warning by default; denied when general.fail_closed = true. The top-level hook envelope could not be read as valid input. This is separate from an evaluation that began but did not finish.
Transient hook stdin I/O error Fail-open. The documented general.fail_closed setting does not change this case into a denial.
Absolute evaluation deadline expires Indeterminate result; requests review where supported, otherwise blocks, subject to the configured unverified decision. The safety check began but did not establish a result in time.
Extracted command exceeds max_command_bytes Indeterminate result. An oversized extracted command is not treated as safe merely because it could not be fully evaluated.
Heredoc or inline-script extraction/parsing failure Uses a bounded fallback scanner; configuration can disable fallback on parse error or timeout to block. Embedded-code parsing has its own fallback and failure policy; it is not the raw JSON policy or the deadline-expiry policy.

These behaviors are documented in the dcg project’s Bounded Failure Policy and Absolute Evaluation Deadline documentation. Since they are implementation-specific and can change, check the project documentation for the version and configuration you deploy.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

How to choose review or denial

Interactive agent with a working review channel

Use a review outcome only if the hook protocol can surface the request to a person who can decide before execution proceeds. A setting that says “ask” is not useful protection if the session is unattended, the client cannot display the prompt, or no operator is available. In those cases, configure unverified outcomes to deny.

Rank #4
Yubico - Security Key NFC - Basic Compatibility - Multi-Factor Authentication (MFA) Key, Connect via USB-A or NFC, FIDO Certified
  • POWERFUL SECURITY KEY: The Security Key NFC is the essential physical passkey for protecting your digital life from phishing attacks. It ensures only you can access your accounts.
  • WORKS WITH 1000+ ACCOUNTS: Compatible with Google, Microsoft, and Apple. A single Security Key NFC secures 100 of your favorite accounts, including email, password managers, and more.
  • FAST & CONVENIENT LOGIN: Plug in your Security Key NFC via USB-A and tap it, or tap it against your phone (NFC) to authenticate. No batteries, no internet connection, and no extra fees required.
  • TRUSTED PASSKEY TECHNOLOGY: Uses the latest passkey standards (FIDO2/WebAuthn & FIDO U2F) but does not support One-Time Passwords. For complex needs, check out the YubiKey 5 Series.
  • BUILT TO LAST: Made from tough, waterproof, and crush-resistant materials. Manufactured in Sweden and programmed in the USA with the highest security standards.

Unattended agent or CI job

Set general.unverified_decision = "deny" or DCG_UNVERIFIED_DECISION=deny, then confirm that your hook integration actually applies that configuration to deadline-expired and oversized extracted commands. Do not infer denial from a separate setting for malformed JSON: dcg documents that malformed JSON is allowed by default, and transient stdin I/O errors remain fail-open.

Slow or heavily loaded host

First establish whether the delay comes from evaluator work or host contention. dcg recommends increasing hook_timeout_ms under heavy load and testing the evaluator-side budget with dcg test --enforce-budget. Keep the unverified-outcome policy explicit while adjusting the deadline; raising the timeout should not turn an elapsed evaluation into permission to run the command.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What a sound hook policy should make explicit

  • What happens when the end-to-end deadline expires, and whether an “ask” result can reach a human.
  • Whether unattended runs deny commands whose safety remains unverified.
  • How malformed or oversized hook input differs from transient stdin I/O failure.
  • How oversized extracted commands and embedded-script extraction or parsing failures are handled.
  • Whether the deadline is wall-clock and bounded, and which configuration values override defaults.

The cited dcg documentation provides one concrete implementation, not a comparison of competing hooks. Its timeout values and failure policies should be read as dcg-specific configuration behavior, not as industry-wide defaults.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Leave a Reply

Your email address will not be published. Required fields are marked *

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

More from the Wire

  1. World desk4 min
    How to Spot an AI Voice Scam Before Sending MoneyDon’t rely on how a caller sounds. Pause, call back through a known number, and verify the emergency with another trusted person before sending money.
  2. Mountain View desk4 min
    Google’s SynthID Detector: How to Check AI-Generated Images, Video and AudioGoogle’s SynthID Detector looks for an embedded watermark in supported images, video and audio. Here is what its results do—and do not—show.
  3. Redmond desk20 min
    How to create a link to File or Folder in Windows 11Windows 11 gives you several ways to point to a file or folder without moving or duplicating it. You can create a desktop shortcut,…
Recommended PC Tool
Recommended PC Tool
Crashes, No Sound, or Screen Glitches?Free driver scan
PC Slower Than It Used to Be?Free scan - under a minute

Two free Windows tools

One Free Minute Could Fix That PC

Before you go - each of these free tools takes about a minute and tackles what quietly slows a Windows PC down.

Special offer. View Outbyte info, uninstall instructions, EULA, and Privacy Policy.