All playbooksRepository Safety Policy
Review GitHub Repository Guard before enforcement
Install a repository workflow, inspect report-only findings, then choose whether to require the check before merge.
Protect my GitHub repoSetup path
GitHub Repository Guard setup
npx @aporthq/aport-agent-guardrails github- Run the installer from the repository root and review the generated workflow diff.
- Open a test pull request and inspect the APort job summary in evidence-only mode.
- For a hosted enforcement test, suspend a test passport and confirm the deny reason before configuring branch protection.
Check a denied action
Request pr.merge using a suspended test passport.
Expected hosted authorization result: deny. Evidence-only mode reports findings and exits successfully; it does not block a merge. Configure the required check only after reviewing the report.
Expected policy result, illustrative
{
"policy_id": "code.repository.merge.v1",
"allow": false,
"reason": "oap.passport_suspended"
}Setup path
Prepare GitHub Guard setup
Install a repository workflow, inspect report-only findings, then choose whether to require the check before merge.
Recommended
Let my agent prepare GitHub Guard.
Best for teams already using Claude, Codex, or Cursor to open pull requests.
agent instruction
set up APort GitHub Repository Guard for this repo — https://aport.io/skillCopy this into the agent that already has access to your repo or runtime environment. Require a diff before enforcement or secrets are enabled.