Profiles
Profile catalog
Guardrails block what an agent must never do. Quality and stack profiles hold generated code to your conventions. Set a profile by its id.
ccpp cpo profile set <id>Security
Secrets, credentials and code from the internet stay out of the agent's reach.
Secrets baseline
5 policiesSecrets stay out of the model's context and out of files, whatever the tool. Code from the internet is never piped into a shell.
secrets-baseline
Base security
39 policiesA Bash and Python workstation: you confirm what destroys, leaves the project, reaches the network or needs privileges.
base-security
Governance
History rewrites and infrastructure changes need a human.
Git safety
3 policiesNo force-push to protected branches and no skipped hooks.
git-safety
Infrastructure changes
2 policiesYou confirm every Terraform, Pulumi, Kubernetes, Helm or CloudFormation change. State files are never edited by hand.
infra-changes
Enterprise baseline
bundleOrganisation-wide guardrails for every repository, built from the security and governance profiles.
enterprise-baseline
Cost control
GPU jobs and cloud machines start once you confirm.
Compute spend
2 policiesYou confirm training runs, cluster jobs and new cloud machines before they start billing.
compute-spend
Code quality
Type safety and file size, so generated code stays maintainable.
TypeScript strict
6 policiesNo new any, loose types, unsafe assertions or suppressions.
typescript-strict
Python strict
2 policiesType checker and linter findings are fixed, not silenced, and modules stay small.
python-strict
Dart strict
3 policiesAnalyzer findings are fixed and analysis_options.yaml is never weakened.
dart-strict
Frontend
Web interfaces: markup, styles, copy and build.
Next.js 16
123 policiesNext.js 16.4 apps without pre-16 APIs, with explicit server, client and cache boundaries.
nextjs-16
Tailwind CSS v4
39 policiesUtility-first Tailwind v4. Blocks the v3 patterns agents still write.
tailwind-v4
Anti-AI writing
13 policiesInterface copy without stock phrases, filler transitions or templated rhetoric.
anti-ai-writing
Backend
Services, APIs and the databases behind them.
Backend TypeScript
48 policiesTypeScript services with trustworthy contracts, bounded work and inspectable failures.
backend-typescript
Fastify 5
110 policiesFastify 5 services without Fastify 3/4 APIs, with explicit encapsulation and trusted schemas.
fastify-5
TypeScript backend
3 policiesNode.js, Bun or Deno services in strict TypeScript with a SQL database and migrations.
typescript-backend
Backend Python
63 policiesPython services with checked types, explicit failures and owned async work.
backend-python
Backend Go
63 policiesGo services with checked errors, owned goroutines and bounded work.
backend-go
Backend Rust
63 policiesRust services (Tokio, axum, SQLx) with explicit failures and bounded resources.
backend-rust
Backend Java
65 policiesJava services (Spring, JPA, JDBC) with declared boundaries and consistent transactions.
backend-java
Backend Kotlin
78 policiesKotlin services (Ktor, Spring) with owned coroutine lifetimes and preserved cancellation.
backend-kotlin
Backend C#
80 policiesASP.NET Core and EF Core services with explicit DI lifetimes and safe queries.
backend-csharp
Backend PHP
78 policiesSymfony, Laravel and Doctrine services with safe input, SQL and shell calls.
backend-php
Mobile
Native and cross-platform mobile applications.
Flutter app
5 policiesFlutter and Dart apps for iOS and Android, with code generation and store signing.
flutter-app
Data & ML
Data pipelines, model training and notebooks.
Python ML
6 policiesPyTorch, Hugging Face and scikit-learn projects with raw data, notebooks and checkpoints.
python-ml