Data-Agent-Rules Adds Safety Guardrails for AI Coding Agents
Summary
The open-source data-agent-rules project provides rules, skills and tools intended to reduce unsafe behavior by AI coding agents working with databases and data pipelines. It targets Claude Code, Codex, Cursor, Gemini CLI and GitHub Copilot, with guidance covering SQL, Spark, dbt, Databricks, Snowflake, BigQuery and DuckDB. The rules require agents to inspect schemas and samples before broad reads, write to development by default, obtain confirmation before destructive changes, make writes repeatable, keep personal data out of prompts, control scan costs and report before-and-after checks. A Claude Code plugin adds session rules, a PII approval hook, a destructive-command guard and an automatic BigQuery dry-run cost check; an MCP server exposes masked previews and cost checks to other clients. In the project’s reported 162-run evaluation on a local DuckDB warehouse, rules improved safety for Claude Haiku 4.5, Sonnet 5 and Opus 5.5: safe runs rose from 10/27 to 25/27 for Haiku, 19/27 to 27/27 for Sonnet and 22/27 to 27/27 for Opus. The baseline agents destroyed, corrupted or invented data in 10, 3 and 0 runs respectively, while the rules reduced those counts to 2, 0 and 0; usefulness also increased for all three models. The project separately reports that adding safe_peek reduced runs with three or more raw personal values from 4/6 with rules alone to 1/6, while still finding the debugging issue in all runs. Its BigQuery cost evaluation found that exploratory queries without controls could bill up to about $197 per run, whereas the revised free-preview approach kept the rerun scenarios safe, although the test uses a stand-in billing model. The authors stress that the data is synthetic, each evaluation cell has only three runs, PII detection can miss unrecognized personal data, hooks cover limited execution paths, and the Snowflake and Databricks integrations have not yet been tested against live accounts. The rules also introduce an intentional extra confirmation step for production changes, and the repository plans further testing with ADE-bench plus Codex and Gemini CLI.