{"id":20358,"plugin_id":"plugins_6aa30aa10cf88191bb67ad3007e43fdc","kind":"skill","collection_source":null,"comparison_source":null,"observed_at":"2026-09-30T23:16:12.861Z","digest":"01e62b3aedc48c301556be9a906072acd619d288ea151c8050c5c1ec071509d4","against":null,"payload":{"name":"git-guardrails-claude-code","description":"Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.","included_files":[{"relative_path":"agents/openai.yaml","size_in_bytes":112},{"relative_path":"scripts/block-dangerous-git.sh","size_in_bytes":507}],"skill_md_contents":"---\nname: git-guardrails-claude-code\ndescription: Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.\ndisable-model-invocation: true\n---\n\n# Setup Git Guardrails\n\nSets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.\n\n## What Gets Blocked\n\n- `git push` (all variants including `--force`)\n- `git reset --hard`\n- `git clean -f` / `git clean -fd`\n- `git branch -D`\n- `git checkout .` / `git restore .`\n\nWhen blocked, Claude sees a message telling it that it does not have authority to access these commands.\n\n## Steps\n\n### 1. Ask scope\n\nAsk the user: install for **this project only** (`.claude/settings.json`) or **all projects** (`~/.claude/settings.json`)?\n\n### 2. Copy the hook script\n\nThe bundled script is at: [scripts/block-dangerous-git.sh](scripts/block-dangerous-git.sh)\n\nCopy it to the target location based on scope:\n\n- **Project**: `.claude/hooks/block-dangerous-git.sh`\n- **Global**: `~/.claude/hooks/block-dangerous-git.sh`\n\nMake it executable with `chmod +x`.\n\n### 3. Add hook to settings\n\nAdd to the appropriate settings file:\n\n**Project** (`.claude/settings.json`):\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Bash\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"\\\"$CLAUDE_PROJECT_DIR\\\"/.claude/hooks/block-dangerous-git.sh\"\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n**Global** (`~/.claude/settings.json`):\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Bash\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"~/.claude/hooks/block-dangerous-git.sh\"\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\nIf the settings file already exists, merge the hook into the existing `hooks.PreToolUse` array. Don't overwrite other settings.\n\n### 4. Ask about customization\n\nAsk if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.\n\n### 5. Verify\n\nRun a quick test:\n\n```bash\necho '{\"tool_input\":{\"command\":\"git push origin main\"}}' | <path-to-script>\n```\n\nShould exit with code 2 and print a BLOCKED message to stderr.\n"},"changes":[],"summary":"First saved snapshot. No earlier version is available for comparison.","summary_kind":"deterministic","summary_metadata":{}}