careful
Safety guardrails for destructive commands. (gstack)
- 0
- Installs
- —
- Rating
- —
- Success rate
- 3
- Files scanned
Security scan
Needs reviewSuspicious-but-common patterns. Skim the findings before installing.
- mediumRewrites or discards git history
bin/check-careful.sh:100
# compound command does (`cd X && git push --force` — whose cwd? which repo?),
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
bin/check-careful.sh:168
# Strip one layer of surrounding quotes: `git push -f origin "main"`
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
bin/check-careful.sh:181
# Bare `git push --force` (force flags only, no remote/ref): targets
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
bin/check-careful.sh:323
# git push --force / git push -f / plus-refspec force (git push origin +ref)
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
bin/check-careful.sh:330
# git reset --hard
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
SKILL.md:32
force-push, git reset --hard, kubectl delete, and similar destructive operations.
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
SKILL.md:56
| `git push --force` / `-f` | `git push -f origin main` | History rewrite |
Force-push and hard reset can destroy other people's work or uncommitted changes.
- mediumRewrites or discards git history
SKILL.md:57
| `git reset --hard` | `git reset --hard HEAD~3` | Uncommitted work loss |
Force-push and hard reset can destroy other people's work or uncommitted changes.
Content sha256 369f36cbb7c602f2… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
When to invoke this skill
Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".
/careful — Destructive Command Guardrails
Safety mode is now active. Every Bash and PowerShell command will be checked for destructive patterns before running. If a destructive command is detected, you'll be warned and can choose to proceed or cancel.
GSTACK_STATE_ROOT=$(~/.claude/skills/gstack/bin/gstack-paths --get GSTACK_STATE_ROOT); : "${GSTACK_STATE_ROOT:?gstack-paths failed; reinstall with ./setup or /gstack-upgrade}"
mkdir -p "$GSTACK_STATE_ROOT"/analytics
echo '{"skill":"careful","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}' >> "$GSTACK_STATE_ROOT"/analytics/skill-usage.jsonl 2>/dev/null || true
What's protected
| Pattern | Example | Risk |
|---|---|---|
rm -rf / rm -r / rm --recursive | rm -rf /var/data | Recursive delete |
DROP TABLE / DROP DATABASE | DROP TABLE users; | Data loss |
TRUNCATE | TRUNCATE orders; | Data loss |
git push --force / -f | git push -f origin main | History rewrite |
git reset --hard | git reset --hard HEAD~3 | Uncommitted work loss |
git checkout . / git restore . | git checkout . | Uncommitted work loss |
kubectl delete | kubectl delete pod | Production impact |
docker rm -f / docker system prune | docker system prune -a | Container/image loss |
PowerShell and cmd (Windows)
The hook also checks the PowerShell tool (Claude Code's main Windows shell)
and any pwsh/powershell/cmd launched from Bash. Matching ignores case,
covers aliases in command position, accepts parameter prefixes (-r, -fo)
and strips cmd ^ escapes. All rows above apply there too.
| Pattern | Example |
|---|---|
Remove-Item/rm/ri/del/erase/rd/rmdir + -Recurse or -Force | gci | ri -r -fo |
cmd rd /s, rmdir /s, del /s, erase /s | cmd /c rd /s /q C:\proj |
Format-Volume, Clear-Disk, Clear-Content, [IO.Directory]::Delete, [IO.File]::Delete | Clear-Disk -Number 1 |
-EncodedCommand, iex, Start-Process of a shell, & $cmd (can't be inspected) | irm $url | iex |
Best-effort on PowerShell. String matching can't see a command built at
runtime. For a hard stop, add Claude Code permission deny rules, which parse
PowerShell and its aliases: "deny": ["PowerShell(Remove-Item *)"] in
.claude/settings.json. The hook runs through bash, so Windows needs Git Bash.
Safe exceptions
These patterns are allowed without warning:
rm -rf node_modules/.next/dist/__pycache__/.cache/build/.turbo/coverage
How it works
The hook reads tool_name and the command from the tool input JSON, checks it against the
patterns above, and returns a hookSpecificOutput payload with
permissionDecision: "ask" and a warning reason if a match is found (the
decision must be nested under hookSpecificOutput — Claude Code ignores a
top-level permissionDecision). You can always override a MEDIUM warning and
proceed.
HIGH tier (hard deny)
Two catastrophic shapes are denied, not asked: rm -r/-R of exactly
/, ~, or $HOME, and force-push to the repo's default branch. SIMPLE
commands only (no ;, &&, ||, |, newline) — compound shapes fall
through to the MEDIUM ask; --force-with-lease is never HIGH. A best-effort
advisory hard-stop, not a policy boundary: the escape hatch is ending the
opt-in, session-scoped /careful session.
Project patterns (additive only)
Add warn rules — one POSIX ERE per line, # comments OK — in
~/.gstack/careful-patterns.txt (global) or
~/.gstack/projects/<slug>/careful-patterns.txt (per-project). Consulted
after the built-in families, so config can only ADD rules, never suppress a
baseline warning. Invalid regex lines are skipped.
To deactivate, end the conversation or start a new one. Hooks are session-scoped.
Files
3- SKILL.md
8e8e918b4f5.0 KB - bin/check-careful.sh
356a16840119.4 KB - bin/hook-extract.sh
790876f8bf10.2 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from garrytan/gstack8
Fixture dispatcher with a mode table and forced-read references.
Auto-review pipeline — reads the full CEO, design, eng, and DX review skills from disk and runs them sequentially with auto-decisions using 6 decision principles. (gstack)
Web performance regression detection. (gstack)
Cross-model benchmark for gstack skills. (gstack)
Clean fixture tool skill with no forced reads and no mode table.
Drive a real browser through Aside: open a page, read it, click through a flow, take screenshots, check console errors. (gstack)
Post-deploy canary monitoring. (gstack)
OpenAI Codex CLI wrapper — three modes. (gstack)
Related knowledge skillsscan passed
PostHog error tracking for Web (JavaScript)
Track and report Claude Code token usage, spending, and budgets from the local ECC cost-tracker metrics log. Use when the user asks about costs, spending, usage, tokens, budgets, or cost breakdowns by model, session, or date.