# ArtifactGuard for Codex CLI

Use ArtifactGuard when a Codex CLI task may create, download, extract, copy, or generate temporary artifacts.

## Agent Instruction

Before artifact-producing work, run:

```bash
artifact-guard start
```

Before the final response, run:

```bash
artifact-guard finish --report
```

If automatic safe cleanup is appropriate, run:

```bash
artifact-guard finish --delete-safe --report
```

If cleanup should be reviewed interactively, run:

```bash
artifact-guard finish --interactive --report
```

## Recommended Usage Policy

Use ArtifactGuard for tasks involving:

- web downloads
- generated logs or scratch files
- archive/document extraction
- temporary scripts
- private documents
- candidate/customer/patient data
- one-off reports

Skip ArtifactGuard for simple source-only edits that do not create temporary artifacts.

## Cleanup Boundary

ArtifactGuard only deletes files classified as both:

- `temporary`
- `created`

It does not delete source, Git-tracked, sensitive, deliverable, unknown, modified, or deleted-file records.

## Final Response Template

```text
Cleanup: ArtifactGuard <deleted safe temporary artifacts | found no temporary artifacts | kept files for manual review>; report: .artifact-guard/report.md
```
