When an AI coding agent does something it shouldn't
When an agent takes a harmful action — a bad push, a deleted file, a leaked secret — respond in five steps: contain it (stop the agent, revoke credentials), find out exactly what happened from the signed record, assess the impact, remediate, and add a rule so it can't happen again. The step that makes the rest possible is having a tamper-evident record before the incident; you cannot investigate what was never recorded.
The checklist
- Contain. Stop the agent and revoke its credentials or keys. Scopebond's gateway has a kill switch; for a hook setup, disable the agent and rotate exposed secrets.
- Find out what happened. Read the signed record —
scopebond-hook logandscopebond-hook verify— to see the exact actions, decisions and timing. - Assess impact. Which systems, which data, which branches. The record's action detail scopes the blast radius.
- Remediate. Revert the change, rotate leaked secrets, restore from backup as needed.
- Prevent recurrence. Add or tighten a rule so the action is blocked before it runs next time, and confirm it with
scopebond-hook test.
What this does not do
Scopebond helps you contain (kill switch), investigate (a verifiable record) and prevent (a rule); it does not undo an action that already happened or replace your backup and secret-rotation procedures. A signed record attests decisions, not real-world remediation.
Alternatives
- Reconstructing from ad-hoc logs — editable logs are a claim; a signed record is evidence you can verify.
- Manual review after the fact — catches nothing in real time; a fail-closed rule blocks the action before it runs.
FAQ
Can Scopebond undo what the agent did?
No. It contains (kill switch), records what happened for investigation, and lets you add a rule to prevent recurrence; reverting and restoring are your normal procedures.
What if we had no record?
Then investigation is guesswork. Put a checkpoint in place now so the next incident has a verifiable record to work from.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/shell.test.mjs).