skills/ mattpocock/skills

git-guardrails-claude-code

Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.

0
Installs
—
Rating
—
Success rate
3
Files scanned
Needs reviewmethodology
Source on GitHub

Security scan

Needs review

Suspicious-but-common patterns. Skim the findings before installing.

3 files scannedscanner v1.2.0Oct 11, 20265 medium
  • mediumRewrites or discards git history

    scripts/block-dangerous-git.sh:8

    "git reset --hard"

    Force-push and hard reset can destroy other people's work or uncommitted changes.

  • mediumRewrites or discards git history

    scripts/block-dangerous-git.sh:9

    "git clean -fd"

    Force-push and hard reset can destroy other people's work or uncommitted changes.

  • mediumRewrites or discards git history

    SKILL.md:12

    - `git push` (all variants including `--force`)

    Force-push and hard reset can destroy other people's work or uncommitted changes.

  • mediumRewrites or discards git history

    SKILL.md:13

    - `git reset --hard`

    Force-push and hard reset can destroy other people's work or uncommitted changes.

  • mediumRewrites or discards git history

    SKILL.md:14

    - `git clean -f` / `git clean -fd`

    Force-push and hard reset can destroy other people's work or uncommitted changes.

Content sha256 aca7bba953f95596… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

SKILL.md

exact scanned copy

Setup Git Guardrails

Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.

What Gets Blocked

  • git push (all variants including --force)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

When blocked, Claude sees a message telling it that it does not have authority to access these commands.

Steps

1. Ask scope

Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?

2. Copy the hook script

The bundled script is at: scripts/block-dangerous-git.sh

Copy it to the target location based on scope:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

Make it executable with chmod +x.

3. Add hook to settings

Add to the appropriate settings file:

Project (.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Global (~/.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

If the settings file already exists, merge the hook into the existing hooks.PreToolUse array. Don't overwrite other settings.

4. Ask about customization

Ask if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.

5. Verify

Run a quick test:

echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

Should exit with code 2 and print a BLOCKED message to stderr.

Files

3
2.9 KB

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from mattpocock/skills8

Related methodology skillsscan passed