Claude Cursor opencode Skill

git-guardrails-claude-code

Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.

LLM Mart · 0 points · 0 views 0 listing impressions 0 install-command copies
Virus-scanned Reviewed automatically before listing.

Full trust report

Download vodailocz-kilo-kit-mcp-skills_productivity_git-guardrails-claude-code-0448e6c.zip · 1 KB
Part of vodailocz/kilo-kit-mcp — 142 skills

Install

skills CLI npx skills add https://github.com/VoDaiLocz/kilo-kit-mcp/tree/main/skills/productivity/git-guardrails-claude-code
Claude Code claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install vodailocz-kilo-kit-mcp@llmmart
Git git clone https://github.com/VoDaiLocz/kilo-kit-mcp.git

The skills CLI installs just this skill, for any of its supported agents. Claude Code installs the whole vodailocz/kilo-kit-mcp collection as a plugin from our marketplace. Git is the plain clone.

Skill manifest

Setup Git Guardrails

Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.

What Gets Blocked

  • git push (all variants including --force)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

When blocked, Claude sees a message telling it that it does not have authority to access these commands.

Steps

1. Ask scope

Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?

2. Copy the hook script

The bundled script is at: scripts/block-dangerous-git.sh

Copy it to the target location based on scope:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

Make it executable with chmod +x.

3. Add hook to settings

Add to the appropriate settings file:

Project (.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Global (~/.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

If the settings file already exists, merge the hook into the existing hooks.PreToolUse array. Don't overwrite other settings.

4. Ask about customization

Ask if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.

5. Verify

Run a quick test:

echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

Should exit with code 2 and print a BLOCKED message to stderr.

Files (kilo-kit-mcp)
  • scripts
    • block-dangerous-git.sh 507 B
      #!/bin/bash
      
      INPUT=$(cat)
      COMMAND=$(echo "$INPUT" | jq -r '.tool_input.command')
      
      DANGEROUS_PATTERNS=(
        "git push"
        "git reset --hard"
        "git clean -fd"
        "git clean -f"
        "git branch -D"
        "git checkout \."
        "git restore \."
        "push --force"
        "reset --hard"
      )
      
      for pattern in "${DANGEROUS_PATTERNS[@]}"; do
        if echo "$COMMAND" | grep -qE "$pattern"; then
          echo "BLOCKED: '$COMMAND' matches dangerous pattern '$pattern'. The user has prevented you from doing this." >&2
          exit 2
        fi
      done
      
      exit 0
      
  • SKILL.md 2.3 KB
    ---
    name: git-guardrails-claude-code
    description: Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.
    ---
    
    # Setup Git Guardrails
    
    Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.
    
    ## What Gets Blocked
    
    - `git push` (all variants including `--force`)
    - `git reset --hard`
    - `git clean -f` / `git clean -fd`
    - `git branch -D`
    - `git checkout .` / `git restore .`
    
    When blocked, Claude sees a message telling it that it does not have authority to access these commands.
    
    ## Steps
    
    ### 1. Ask scope
    
    Ask the user: install for **this project only** (`.claude/settings.json`) or **all projects** (`~/.claude/settings.json`)?
    
    ### 2. Copy the hook script
    
    The bundled script is at: [scripts/block-dangerous-git.sh](scripts/block-dangerous-git.sh)
    
    Copy it to the target location based on scope:
    
    - **Project**: `.claude/hooks/block-dangerous-git.sh`
    - **Global**: `~/.claude/hooks/block-dangerous-git.sh`
    
    Make it executable with `chmod +x`.
    
    ### 3. Add hook to settings
    
    Add to the appropriate settings file:
    
    **Project** (`.claude/settings.json`):
    
    ```json
    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hooks": [
              {
                "type": "command",
                "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
              }
            ]
          }
        ]
      }
    }
    ```
    
    **Global** (`~/.claude/settings.json`):
    
    ```json
    {
      "hooks": {
        "PreToolUse": [
          {
            "matcher": "Bash",
            "hooks": [
              {
                "type": "command",
                "command": "~/.claude/hooks/block-dangerous-git.sh"
              }
            ]
          }
        ]
      }
    }
    ```
    
    If the settings file already exists, merge the hook into the existing `hooks.PreToolUse` array. Don't overwrite other settings.
    
    ### 4. Ask about customization
    
    Ask if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.
    
    ### 5. Verify
    
    Run a quick test:
    
    ```bash
    echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>
    ```
    
    Should exit with code 2 and print a BLOCKED message to stderr.
    

Comments (0)

Sign in to join the conversation.

No comments yet.

Reviews (0)

No reviews yet.

Related