Agent Skillsgarrytan/gstack › careful

careful

GitHub

提供破坏性命令的安全护栏,在执行 rm -rf、DROP TABLE、force-push 等高危操作前进行拦截和警告,防止误删数据或覆盖代码,支持用户确认后继续执行。

careful/SKILL.md garrytan/gstack

Trigger Scenarios

执行 rm -rf、DROP TABLE、git push --force 等破坏性命令时 用户明确要求进入 'careful mode'、'safety mode' 或 'prod mode' 时

Install

npx skills add garrytan/gstack --skill careful -g -y
More Options

Non-standard path

npx skills add https://github.com/garrytan/gstack/tree/main/careful -g -y

Use without installing

npx skills use garrytan/gstack@careful

指定 Agent (Claude Code)

npx skills add garrytan/gstack --skill careful -a claude-code -g -y

安装 repo 全部 skill

npx skills add garrytan/gstack --all -g -y

预览 repo 内 skill

npx skills add garrytan/gstack --list

SKILL.md

Frontmatter
{
    "name": "careful",
    "hooks": {
        "PreToolUse": [
            {
                "hooks": [
                    {
                        "type": "command",
                        "command": "bash $HOME\/.claude\/skills\/gstack\/careful\/bin\/check-careful.sh",
                        "statusMessage": "Checking for destructive commands..."
                    }
                ],
                "matcher": "Bash"
            }
        ]
    },
    "version": "0.1.0",
    "triggers": [
        "be careful",
        "warn before destructive",
        "safety mode"
    ],
    "description": "Safety guardrails for destructive commands. (gstack)",
    "allowed-tools": [
        "Bash",
        "Read"
    ]
}

When to invoke this skill

Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".

/careful — Destructive Command Guardrails

Safety mode is now active. Every bash command will be checked for destructive patterns before running. If a destructive command is detected, you'll be warned and can choose to proceed or cancel.

mkdir -p ~/.gstack/analytics
echo '{"skill":"careful","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}'  >> ~/.gstack/analytics/skill-usage.jsonl 2>/dev/null || true

What's protected

Pattern Example Risk
rm -rf / rm -r / rm --recursive rm -rf /var/data Recursive delete
DROP TABLE / DROP DATABASE DROP TABLE users; Data loss
TRUNCATE TRUNCATE orders; Data loss
git push --force / -f git push -f origin main History rewrite
git reset --hard git reset --hard HEAD~3 Uncommitted work loss
git checkout . / git restore . git checkout . Uncommitted work loss
kubectl delete kubectl delete pod Production impact
docker rm -f / docker system prune docker system prune -a Container/image loss

Safe exceptions

These patterns are allowed without warning:

  • rm -rf node_modules / .next / dist / __pycache__ / .cache / build / .turbo / coverage

How it works

The hook reads the command from the tool input JSON, checks it against the patterns above, and returns a hookSpecificOutput payload with permissionDecision: "ask" and a warning reason if a match is found (the decision must be nested under hookSpecificOutput — Claude Code ignores a top-level permissionDecision). You can always override a MEDIUM warning and proceed.

HIGH tier (hard deny)

Two catastrophic shapes are denied, not asked: rm -r/-R of exactly /, ~, or $HOME, and force-push to the repo's default branch. SIMPLE commands only (no ;, &&, ||, |, newline) — compound shapes fall through to the MEDIUM ask; --force-with-lease is never HIGH. A best-effort advisory hard-stop, not a policy boundary: the escape hatch is ending the opt-in, session-scoped /careful session.

Project patterns (additive only)

Add warn rules — one POSIX ERE per line, # comments OK — in ~/.gstack/careful-patterns.txt (global) or ~/.gstack/projects/<slug>/careful-patterns.txt (per-project). Consulted after the built-in families, so config can only ADD rules, never suppress a baseline warning. Invalid regex lines are skipped.

To deactivate, end the conversation or start a new one. Hooks are session-scoped.

Version History

  • 28d59ad Current 2026-08-20 05:27

    新增 HIGH 级别硬拒绝机制(禁止删除根目录/主分支强制推送),修复 JSON 提取器缺陷,增加项目级自定义规则支持。

  • a325940 2026-07-25 11:04

Same Skill Collection

autoplan/SKILL.md
benchmark/SKILL.md
browse/SKILL.md
browser-skills/hackernews-frontpage/SKILL.md
context-restore/SKILL.md
design-consultation/SKILL.md
design-html/SKILL.md
design-review/SKILL.md
design-shotgun/SKILL.md
diagram/SKILL.md
freeze/SKILL.md
guard/SKILL.md
investigate/SKILL.md
ios-clean/SKILL.md
ios-design-review/SKILL.md
ios-sync/SKILL.md
landing-report/SKILL.md
make-pdf/SKILL.md
open-gstack-browser/SKILL.md
openclaw/skills/gstack-openclaw-ceo-review/SKILL.md
openclaw/skills/gstack-openclaw-investigate/SKILL.md
openclaw/skills/gstack-openclaw-office-hours/SKILL.md
openclaw/skills/gstack-openclaw-retro/SKILL.md
pair-agent/SKILL.md
plan-design-review/SKILL.md
plan-devex-review/SKILL.md
plan-tune/SKILL.md
qa/SKILL.md
setup-browser-cookies/SKILL.md
setup-deploy/SKILL.md
setup-gbrain/SKILL.md
ship/SKILL.md
skillify/SKILL.md
spec/SKILL.md
sync-gbrain/SKILL.md
test/fixtures/context-bill/tree-a/alpha/SKILL.md
test/fixtures/golden/claude-ship-SKILL.md
test/fixtures/golden/codex-ship-SKILL.md
test/fixtures/golden/factory-ship-SKILL.md
unfreeze/SKILL.md
benchmark-models/SKILL.md
canary/SKILL.md
codex/SKILL.md
context-save/SKILL.md
cso/SKILL.md
devex-review/SKILL.md
document-release/SKILL.md
gstack-upgrade/SKILL.md
health/SKILL.md

Metadata

Files
0
Version
28d59ad
Hash
51c82132
Indexed
2026-07-25 11:04

Главная - Вики-сайт
Copyright © 2011-2026 iteam. Current version is 2.155.2. UTC+08:00, 2026-08-20 10:26
浙ICP备14020137号-1 $Гость$