skillZs
★ LIVE SKILL TAGS ★
>>> LIVE SKILLS INDEX <<<
* OPEN SOURCE *
NO LOGIN, NO TRACKING
※ REAL INSTALL DATA ※
← back to all skills
dedalus-erp-pas/foundation-skills121 installs

git-guardrails

Configure des hooks Claude Code pour bloquer les commandes git dangereuses (push, force-push, reset --hard, clean, branch -D, checkout/restore) avant leur exécution. Empêche les opérations git destructrices au niveau de l'agent. À utiliser quand l'utilisateur veut protéger son dépôt contre les commandes git destructrices, installer des garde-fous git, ou mentionne « git guardrails » / « bloquer force-push » / « sécuriser git ».

How do I install this agent skill?

npx skills add https://github.com/dedalus-erp-pas/foundation-skills --skill git-guardrails
view source ↗

Is this agent skill safe to install?

  • Gen Agent Trust Hubpass

    This skill is a security-focused utility designed to protect the user's Git repository by preventing the AI agent from executing destructive commands like force-pushes or hard resets. It implements a legitimate safety hook for the Claude Code platform and contains no malicious code or suspicious patterns.

  • Socketpass

    No alerts

  • Snykpass

    Risk: LOW · No issues

  • ZeroLeakspass

    Score: 93/100 · 2 sections analyzed

What does this agent skill do?

Git Guardrails

Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude Code executes them.

Prerequisites

  • jq: required for the hook script to parse tool input — install with brew install jq or apt-get install jq
    • Important: if jq is not installed, the hook will fail open (allow all commands). Always verify jq is available after setup.

When to Use This Skill

Activate when the user:

  • Wants to prevent destructive git operations from being run by the AI agent
  • Asks to add git safety hooks to Claude Code
  • Wants to block git push, git reset --hard, or other dangerous commands
  • Is setting up a new project and wants guardrails on git operations

What Gets Blocked

The following commands are intercepted and blocked before execution:

PatternDescription
git pushAll push variants (prevents unreviewed pushes)
git push --forceForce push (rewrites remote history)
git push --force-with-leaseForce push variant
git reset --hardDiscards all uncommitted changes
git clean -f / git clean -fdDeletes untracked files permanently
git branch -DForce-deletes a branch without merge check
git checkout .Discards all working tree changes
git restore .Discards all working tree changes
git rebase on main/masterPrevents rebase of protected branches

When blocked, Claude sees a message telling it that it does not have authority to run these commands. The user must run them manually if needed.

Setup Steps

Step 1: Ask Scope

Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?

Step 2: Copy the Hook Script

The bundled script is at: reference/block-dangerous-git.sh

Copy it to the target location based on scope:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

Make it executable:

chmod +x <path-to-script>

Step 3: Add Hook to Settings

Add to the appropriate settings file.

Project scope (.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Global scope (~/.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

If the settings file already exists, merge the hook into the existing hooks.PreToolUse array. Do not overwrite other settings.

Step 4: Ask About Customization

Ask if the user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.

Common additions users may want:

  • Block git stash drop (prevents accidental stash loss)
  • Block git tag -d (prevents tag deletion)
  • Allow git push but only block --force variants

Step 5: Verify Installation

Run a quick test to confirm the hook works:

echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

Expected result: exits with code 2 and prints a BLOCKED message to stderr.

Run a second test with a safe command:

echo '{"tool_input":{"command":"git status"}}' | <path-to-script>

Expected result: exits with code 0 (allowed).

How It Works

Claude Code supports PreToolUse hooks that run before any tool invocation. The hook:

  1. Receives the tool input as JSON on stdin
  2. Extracts the command field using jq
  3. Checks the command against a list of dangerous patterns
  4. If a match is found, exits with code 2 (which tells Claude the command is blocked)
  5. If no match, exits with code 0 (which allows normal execution)

Important Notes

  • The hook only blocks commands run by the AI agent. The user can still run any git command manually in their terminal.
  • The blocked patterns use regex matching, so git push also catches git push origin main --force.
  • If jq is not installed, the script will fail open (allow all commands). Ensure jq is available.
  • The hook does not modify any git configuration; it only intercepts Claude Code tool calls.

Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.

<a href="https://skillzs.dev/skills/dedalus-erp-pas/foundation-skills/git-guardrails">View git-guardrails on skillZs</a>