Catch the oops before it runs.
OopsAI sits between your coding agent and its tools. Every file edit, command and network call is checked against the task before it executes. And “done” only counts when the tests agree.
Task: fix session expiry
scope src/auth/ + tests/auth/
- agentTokens expire early. Checking the session handler.
read_filesrc/auth/session.tsAllowededit_filesrc/auth/session.ts +12 −3Allowed- agentWhile I’m here, the schema could use a cleanup.
edit_filedb/schema.sql[!] OopsOutside the task. Never ran.- agentIt’s safe, I promise. The fix needs it.
edit_filedb/schema.sql[!] OopsA good argument isn’t a permission.runnpm test tests/authAllowed14 passedfinish“Session expiry fixed.”Checking…CheckedTests pass. Nothing outside scope.
Three checks between an idea and the damage.
-
Give the task a boundary.
The files, tools and network access this job actually needs. Nothing more.
- Can edit
- src/auth/, tests/auth/
- Can run
- npm test
- Can’t
- touch the schema, upload files, push to main
-
Check every action before it runs.
Each tool call gets an answer before execution: allowed, stopped, or held for a person. A stopped action never starts, so there’s nothing to roll back.
-
Make “done” prove it.
The run finishes when the tests pass and the diff stays in scope. Every request and decision lands in a trace you can read when something looks off.
Permission is a policy, not a persuasive paragraph.
Agents explain themselves well. Sometimes too well. OopsAI decides from the task’s boundary, not from the agent’s reasoning, so a confident rationale or an injected instruction can’t talk its way into your database.
See the harness at work
Two drawings: where the harness sits between the agent and your systems, and the four answers a request can get.
How the harness worksLess oops.
Let’s talk.
OopsAI is available on request. Tell us which agent you run and what it touches, and we’ll reply to talk through access and integration.