All skills
mattpocock avatar

/git-guardrails-claude-code

@3216582 official
by Matt Pocockmattpocock/skills274k stars
22,991

Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.

Use this Skill: https://skilld.dev/gh/mattpocock/skills/git-guardrails-claude-code

This session only. Nothing lands on disk.

SKILL.md

≈68 tokens always: the name and description. ≈504 when used: this file. ≈28 more on demand in 1 file.

Setup Git Guardrails

Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.

What Gets Blocked

  • git push (all variants including --force)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

When blocked, Claude sees a message telling it that it does not have authority to access these commands.

Steps

1. Ask scope

Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?

2. Copy the hook script

The bundled script is at: scripts/block-dangerous-git.sh

Copy it to the target location based on scope:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

Make it executable with chmod +x.

3. Add hook to settings

Add to the appropriate settings file:

Project (.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Global (~/.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

If the settings file already exists, merge the hook into the existing hooks.PreToolUse array. Don't overwrite other settings.

4. Ask about customization

Ask if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.

5. Verify

Run a quick test:

echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

Should exit with code 2 and print a BLOCKED message to stderr.

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    This skill provides a security enhancement for AI agents by implementing guardrails against destructive Git commands. It sets up a local hook to monitor and block potentially dangerous operations like force pushing or hard resets.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer7mo

    2/2 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 3216582. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated last month
  • Git/VCS
  • claude-code
  • hooks
  • safety
  • bash
  • destructive-operations
  • pre-tool-use

README badge

README badge for mattpocock/skills/git-guardrails-claude-code

Installs a PreToolUse hook in Claude Code that blocks destructive git commands (push, reset --hard, clean, branch -D, checkout .) before Claude executes them. Configurable per-project or globally, with an optional step to customize the blocked command list.

Generated from the current SKILL.md.

What git commands does this skill block?
It blocks git push (including --force), git reset --hard, git clean -f/-fd, git branch -D, and git checkout ./ git restore . Before Claude executes them, it sees a message that it lacks authority to access these commands.
Can I customize which git commands are blocked?
Yes. After copying the hook script, you can edit it to add or remove blocked patterns from the list.
Does this work globally or per-project?
Both. During setup you choose whether to install the hook in .claude/settings.json (project-only) or ~/.claude/settings.json (all projects).
How does Claude know a command is blocked?
The skill sets up a PreToolUse hook that intercepts Bash commands before they run. When a dangerous command matches, the hook exits with code 2 and Claude receives a message indicating it does not have authority for that operation.

Generated from the current SKILL.md. These answers refresh after source changes.