{"id":17535,"plugin_id":"plugins_6a78e83987748191afc0c56e12172fce","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:14:15.163Z","digest":"bd99e9f79263c274b6b046a000ba9cf45d7f3d0aa246f0479953d6e42c17fc92","against":null,"payload":{"description":"Safeguard repositories against destructive, irreversible, or history-rewriting Git operations. Use when running force pushes, hard resets, branch deletions, cleans, destructive restores, or history re-writes — even if the user says \"clean up git history\". Do NOT use for routine safe git status, fetch, diff, or branch queries.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":109},{"relative_path":"scripts/block-dangerous-git.sh","size_in_bytes":507},{"relative_path":"scripts/classify_git_command.py","size_in_bytes":1004}],"name":"git-safety-guardrails","skill_md_contents":"---\nname: git-safety-guardrails\ndescription: \"Safeguard repositories against destructive, irreversible, or history-rewriting Git operations. Use when running force pushes, hard resets, branch deletions, cleans, destructive restores, or history re-writes — even if the user says \\\"clean up git history\\\". Do NOT use for routine safe git status, fetch, diff, or branch queries.\"\n---\n\n# Git Safety Guardrails\n\nInstall and maintain deterministic pre-execution guardrails that intercept and block dangerous, destructive, or history-rewriting Git commands before autonomous agents can execute them.\n\n---\n\n## Core Invariants\n\n1. **Deterministic Interception**: Automatically block destructive Git commands (`git push --force`, `git reset --hard`, `git clean -f/-fd`, `git branch -D`, `git checkout .`, `git restore .`) before execution.\n2. **Explicit Authority Gate**: Intercepted commands return an explicit non-zero exit code notifying the agent that it lacks authority to execute destructive operations.\n3. **Scope Clarification**: Always ask the user whether to apply guardrails locally to the project (`.claude/settings.json`) or globally (`~/.claude/settings.json`).\n4. **Settings Merge Safety**: Seamlessly merge guardrail hooks into existing `PreToolUse` configurations without overwriting other tools or settings.\n5. **Mandatory Interception Test**: Verify that the safety hook triggers correctly on simulated forbidden commands before concluding setup.\n\n---\n\n## Architecture & Map of Content (MOC)\n\n```\n[ Agent Tool Call (Bash/Git) ] ──► [ PreToolUse Hook: `block-dangerous-git.sh` ]\n                                                  │\n                        ┌─────────────────────────┴─────────────────────────┐\n                        ▼                                                   ▼\n            [ Safe Git Operation ]                              [ Destructive Command ]\n            - `git status`, `git diff`                          - `git push --force`, `reset --hard`\n            - ALLOWED to execute                                - BLOCKED (Exit Code 2)\n```\n\n| Component | Responsibility | Location |\n|---|---|---|\n| **Classifier Hook Script** | Inspect and block forbidden git patterns | `scripts/block-dangerous-git.sh` |\n| **Python Command Parser** | Parse complex shell command chains | `scripts/classify_git_command.py` |\n| **Settings Integration** | Hook registration in agent environment | `.claude/settings.json` or `~/.claude/settings.json` |\n\n---\n\n## Step-by-Step Procedure (TWI)\n\n### Step 1: Confirm Guardrail Scope\n- **Action**: Ask the user whether to configure guardrails for this project only or globally.\n- **Key Point**: Default to project-level `.claude/settings.json` unless the user specifies global.\n- **Why**: Scoped installation avoids unexpected side-effects across external personal repositories.\n\n### Step 2: Copy Hook Script & Make Executable\n- **Action**: Copy `scripts/block-dangerous-git.sh` to `.claude/hooks/block-dangerous-git.sh` and run `chmod +x`.\n- **Key Point**: Ensure parent directories exist before copying.\n- **Inline Checklist**:\n  - [ ] Target directory created\n  - [ ] Script copied and executable permissions set (`chmod +x`)\n  - [ ] Python classifier script colocated if needed\n\n### Step 3: Register Hook in Settings Configuration\n- **Action**: Add the PreToolUse hook entry to `.claude/settings.json`, merging into existing arrays if present.\n- **Key Point**: Use `\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh` path expansion.\n- **Why**: Relative path expansions ensure the hook functions across different working directory contexts.\n\n### Step 4: Verify Guardrail Interception (Test Gate)\n- **Action**: Test the hook with a simulated blocked command:\n  ```bash\n  echo '{\"tool_input\":{\"command\":\"git push origin main --force\"}}' | .claude/hooks/block-dangerous-git.sh\n  ```\n- **Key Point**: Verify that the command exits with code 2 and outputs a descriptive blocked message.\n- **Why**: Proving the hook intercepts dangerous commands guarantees that unverified agents cannot accidentally wipe Git history.\n\n---\n\n## Anti-Rationalization Guardrails\n\n| Tempting Rationalization | Binding Rule | Engineering Rationale |\n|---|---|---|\n| *\"Allow `git reset --hard` if the working tree has uncommitted bugs.\"* | **Block all hard resets; require explicit stashes or reverts.** | Hard resets permanently delete uncommitted code and worktree context. |\n| *\"Allow force pushes on feature branches.\"* | **Block all force pushes by default.** | Force pushing can overwrite teammate commits and destroy branch history. |\n| *\"Skip verifying the hook script with simulated input.\"* | **Mandatory simulated test pass.** | Syntax errors in hook scripts cause them to fail open, leaving the repo unprotected. |\n\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}