The Destructive Command Guard blocks dangerous git and shell commands before agents execute them—keeping autonomy useful without handing over an unguarded terminal.