All skills
garrytan avatar

/guard

@01593aa official
by Garry Tangarrytan/gstack135k stars
20,051

Full safety mode: destructive command warnings + directory-scoped edits. (gstack)

Use this Skill: https://skilld.dev/gh/garrytan/gstack/guard

This session only. Nothing lands on disk.

SKILL.md

≈22 tokens always: the name and description. ≈638 when used: this file.

<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly --> <!-- Regenerate: bun run gen:skill-docs -->

When to invoke this skill

Combines /careful (warns before rm -rf, DROP TABLE, force-push, etc.) with /freeze (blocks edits outside a specified directory). Use for maximum safety when touching prod or debugging live systems. Use when asked to "guard mode", "full safety", "lock it down", or "maximum safety".

/guard — Full Safety Mode

Activates both destructive command warnings and directory-scoped edit restrictions. This is the combination of /careful + /freeze in a single command.

Dependency note: This skill references hook scripts from the sibling /careful and /freeze skill directories. Both must be installed (they are installed together by the gstack setup script).

mkdir -p ~/.gstack/analytics
echo '{"skill":"guard","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}'  >> ~/.gstack/analytics/skill-usage.jsonl 2>/dev/null || true

Setup

Ask the user which directory to restrict edits to. Use AskUserQuestion:

  • Question: "Guard mode: which directory should edits be restricted to? Destructive command warnings are always on. Files outside the chosen path will be blocked from editing."
  • Text input (not multiple choice) — the user types a path.

Once the user provides a directory path:

Set the user-selected boundary with the shared writer, which resolves a physical absolute path and serializes replacement with investigation cleanup:

bash "$HOME/.claude/skills/gstack/freeze/bin/freeze-state.sh" set "<user-provided-path>"

On helper failure, do not claim the boundary is active. Preserve the state and report recovery; never bypass the shared writer with a direct write or deletion.

Tell the user:

  • "Guard mode active. Two protections are now running:"
  • "1. Destructive command guard — rm -rf, DROP TABLE, force-push, etc. warn before executing (overridable); catastrophic shapes (recursive delete of / or ~, force-push to the default branch) are hard-denied"
  • "2. Edit boundary — file edits restricted to <path>/. Edits outside this directory are blocked."
  • "To remove the persistent edit boundary, run /unfreeze. Ending the session stops its hooks but does not delete that boundary."

What's protected

See /careful for the full list of destructive command patterns and safe exceptions. See /freeze for how edit boundary enforcement works.

Source: SKILL.md on GitHub

No alertstoday3 checks · Risk SAFE
  • Gen Agent Trust Hubtoday

    The skill provides safety features by monitoring commands and restricting file edits. It carries a low risk of command injection if user-provided paths are not correctly handled by the underlying scripts or the agent's execution environment. It also performs local logging of skill usage, including repository names.

  • Sockettoday

    No alerts

  • Snyktoday

    Risk: LOW · No issues

Signed by skilld at 01593aa. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 15 hours ago.

Activeupdated 5 days ago
What it can do
Runs commands Reads files
version
0.1.0
triggers
[
  "full safety mode",
  "guard against mistakes",
  "maximum safety"
]
All 3 allowed tools
BashReadAskUserQuestion
Other metadata
hooks
{
  "PreToolUse": [
    {
      "matcher": "Bash",
      "hooks": [
        {
          "type": "command",
          "command": "bash $HOME/.claude/skills/gstack/careful/bin/check-careful.sh",
          "statusMessage": "Checking for destructive commands..."
        }
      ]
    },
    {
      "matcher": "Edit",
      "hooks": [
        {
          "type": "command",
          "command": "bash $HOME/.claude/skills/gstack/freeze/bin/check-freeze.sh",
          "statusMessage": "Checking freeze boundary..."
        }
      ]
    },
    {
      "matcher": "Write",
      "hooks": [
        {
          "type": "command",
          "command": "bash $HOME/.claude/skills/gstack/freeze/bin/check-freeze.sh",
          "statusMessage": "Checking freeze boundary..."
        }
      ]
    }
  ]
}
  • safety
  • guards
  • destructive-commands
  • edit-boundary
  • bash
  • production
  • workflows

README badge

README badge for garrytan/gstack/guard

Activates destructive command warnings (rm -rf, DROP TABLE, force-push) and restricts file edits to a specified directory. Use when working on production systems or live environments where safety is critical.

Generated from the current SKILL.md.

What commands does guard warn about?
Guard warns before destructive commands like rm -rf, DROP TABLE, and force-push. See the /careful skill for the full list of patterns and safe exceptions.
Can I override the destructive command warnings?
Yes. The warnings are advisory; you can proceed after seeing the warning.
Does guard require both /careful and /freeze to be installed?
Yes. Guard combines both skills and will not work if either sibling skill directory is missing.
How do I remove the edit boundary after enabling guard?
Run /unfreeze to remove the directory restriction. Destructive command warnings remain active until you end the session.

Generated from the current SKILL.md. These answers refresh after source changes.