An agent that can write outside its workspace, delete things, or send data somewhere is gated by a review step that lives in a document — a tool manifest, a plan, a runbook — and by a policy that lives in another one. Nothing checks that the two agree. The failure is quiet in both directions: an external write slips through because nobody wrote a rule naming it, or a rule exists and the plan spells the effect slightly differently so no rule ever matched.
This walkthrough uses the tool's public README and checked-in example files. Run the command from a repository checkout with Node.js 22+; inspect the source before using it on your own files.
Run the checked-in example
# A plan whose every action is cleared by the policy. Exits 0.
node bin/approval-boundary-checker.mjs \
--actions examples/allowed/actions.json \
--policy examples/policy.json \
--now 2026-09-14T09:00:00Z
# A plan with an unapproved external write, a denied credential upload, and an
# action no rule covers. Exits 1.
node bin/approval-boundary-checker.mjs \
--actions examples/blocked/actions.json \
--policy examples/policy.json \
--now 2026-09-14T09:00:00Z --jsonRead the result
Exit 2 has two shapes on purpose. A usage error means the run never had a subject, so there is nothing to report about. An unreadable input means the run had a subject and failed to obtain evidence about it — which is what incomplete exists to say, and a consumer needs that report to know which input was not read. A consumer piping stdout must handle an empty stdout on exit 2.
Where this check stops
Every limit is enforced and overridable. Exceeding one is an incomplete result naming the limit, never a silent truncation and never a pass.
Before adapting the command to your own workflow, review the accepted inputs, exit codes and safety boundaries in the README.
Compiled with AI assistance from checked-in public documentation and example scripts. Run the example and review the repository's current documentation before relying on its result.