windsurf-policy-guardrails

Solid

Implement team-wide Windsurf usage policies, code quality gates, and Cascade guardrails. Use when setting up code review policies for AI-generated code, configuring Turbo mode safety controls, or implementing CI gates for Cascade output. Trigger with phrases like "windsurf policy", "windsurf guardrails", "cascade safety rules", "windsurf team rules", "AI code policy".

AI & Automation 2,266 stars 315 forks Updated today MIT

Install

View on GitHub

Quality Score: 99/100

Stars 20%
100
Recency 20%
100
Frontmatter 20%
70
Documentation 15%
100
Issue Health 10%
50
License 10%
100
Description 5%
100

Skill Content

# Windsurf Policy Guardrails ## Overview Policy guardrails for team Windsurf usage: controlling what Cascade can do, enforcing code review for AI output, configuring terminal safety controls, and preventing common AI coding mistakes. ## Prerequisites - Windsurf configured for team use - Git workflow established - CI/CD pipeline in place - Team agreement on AI usage standards ## Instructions ### Step 1: Terminal Command Safety (Turbo Mode Controls) Configure what Cascade can and cannot auto-execute: ```json // settings.json — Team-wide terminal safety { "windsurf.cascadeCommandsAllowList": [ "npm test", "npm run", "npx vitest", "npx tsc", "git status", "git diff", "git log", "git add", "eslint", "prettier", "biome", "ls", "cat", "head", "tail", "wc", "grep" ], "windsurf.cascadeCommandsDenyList": [ "rm -rf", "rm -r /", "sudo", "git push --force", "git reset --hard", "DROP TABLE", "DELETE FROM", "TRUNCATE", "curl | bash", "wget | sh", "chmod 777", "kill -9", "shutdown", "reboot", "halt", "mkfs", "dd if=", "npm publish", "npx publish" ] } ``` ### Step 2: Workspace Isolation Rules Prevent Cascade from accessing sensitive directories: ```gitignore # .codeiumignore — security boundary # AI cannot see or modify files matching these patterns # Credentials .env .env.* credentials/ secrets/ *.pem *.key # Infrastructure terraform.tfstate* *.tfvars ansible/vault* # Customer data data/production/ exports/ ``` ```m...

Details

Author
jeremylongshore
Repository
jeremylongshore/claude-code-plugins-plus-skills
Created
7 months ago
Last Updated
today
Language
Python
License
MIT

Integrates with

Similar Skills

Semantically similar based on skill content — not just same category

AI & Automation Solid

windsurf-ci-integration

Integrate Windsurf Cascade workflows into CI/CD pipelines and team automation. Use when automating Cascade tasks in GitHub Actions, enforcing AI code quality gates, or setting up Windsurf config validation in CI. Trigger with phrases like "windsurf CI", "windsurf GitHub Actions", "windsurf automation", "cascade CI", "windsurf pipeline".

2,266 Updated today
jeremylongshore
AI & Automation Solid

windsurf-multi-env-setup

Configure Windsurf IDE and Cascade AI across team members and project environments. Use when onboarding teams to Windsurf, setting up per-project Cascade configuration, or managing Windsurf settings across development, staging, and production contexts. Trigger with phrases like "windsurf team setup", "windsurf environments", "windsurf multi-project", "windsurf team config", "cascade rules per env".

2,266 Updated today
jeremylongshore
AI & Automation Solid

windsurf-reliability-patterns

Implement reliable Cascade workflows with checkpoints, rollback, and incremental editing. Use when building fault-tolerant AI coding workflows, preventing Cascade from breaking builds, or establishing safe practices for multi-file AI edits. Trigger with phrases like "windsurf reliability", "cascade safety", "windsurf rollback", "cascade checkpoint", "safe cascade workflow".

2,266 Updated today
jeremylongshore
AI & Automation Solid

windsurf-data-handling

Control what code and data Windsurf AI can access and process in your workspace. Use when handling sensitive data, implementing data exclusion patterns, or ensuring compliance with privacy regulations in Windsurf environments. Trigger with phrases like "windsurf data privacy", "windsurf PII", "windsurf GDPR", "windsurf compliance", "codeium data", "windsurf telemetry".

2,266 Updated today
jeremylongshore
AI & Automation Solid

windsurf-security-basics

Apply Windsurf security best practices for workspace isolation, data privacy, and secret protection. Use when securing sensitive code from AI indexing, configuring telemetry, or auditing Windsurf security posture. Trigger with phrases like "windsurf security", "windsurf secrets", "windsurf privacy", "windsurf data protection", "codeiumignore".

2,266 Updated today
jeremylongshore