Guardrails for coding-agent pull requests
Coding agents are fast and mostly right. The problem is the part that's wrong ships with the same confidence as the rest. Four layers keep that out of main.
1. Tell the agent the rules
Put these in CLAUDE.md, AGENTS.md or .cursor/rules:
- Never replace existing code with placeholder comments. Show full edits.
- Don't add a dependency without adding it to the manifest and saying why.
- No empty catch blocks. Handle the error or let it propagate.
- Don't leave TODOs for the requested feature. If something can't be done, say so in the PR.
- Run
npx github:kburrus64-max/slopscore-code --stagedand fix findings before committing.
2. Gate in CI
Instructions get ignored under long contexts. A required check doesn't. Add the SlopScore for Code Action and make it required in branch protection.
3. Size limits
Ask agents for PRs under about 400 changed lines. Review quality falls off sharply above that, for people and for AI reviewers. The giant-file rule flags the worst cases.
4. A human reads the logic
Once the mechanical problems are gone, a person (optionally helped by an AI reviewer) checks the approach, the edge cases and the tests. Review checklist.
For agencies: what to tell clients
Clients increasingly ask whether their code was written by AI. A better answer than "yes" or "no" is a report: every PR passed the same automated checks, with the score attached. The Agency plan (proposed) adds white-label PR reports for exactly this.