Safety Guard

affaan-m/ECC/skills/safety-guard

作者 affaan-mef648e01899ba3e8dc6371642deaaf64b4477775无许可证275K 个星标收录于 2026年10月9日更新于 2026年10月9日仓库4天前更新

Guard against destructive operations with three modes: Careful intercepts dangerous commands (rm -rf, git push --force, DROP TABLE) for confirmation, Freeze locks writes to one directory, and Guard combines both via PreToolUse hooks. Use when working on production systems, running agents autonomously, restricting edits to a directory, or during migrations, deploys, and data changes.

仅含说明Security
AI 生成的概览

通过三种保护模式防范破坏性命令,并将文件写入限制在指定目录内。

功能
Safety Guard 提供三种保护模式:Careful 会拦截 rm -rf、git push --force、DROP TABLE 等破坏性命令并要求确认;Freeze 将文件编辑锁定在指定目录树内;Guard 同时启用两者。它通过 PreToolUse 钩子拦截 Bash、Write、Edit 和 MultiEdit 工具调用,并在执行前按当前规则检查。被阻止的操作会记录到日志文件。
适用场景
适用于在生产系统上工作、代理自主运行的场景,以及需要将编辑限制在特定目录时。也适合迁移、部署和数据变更等敏感操作。
运行要求
不包含脚本,仅为说明性指令。依赖 PreToolUse 钩子拦截 Bash、Write、Edit 和 MultiEdit 工具调用,并在用户主目录下写入日志文件。

Safety Guard — Prevent Destructive Operations

When to Use

  • When working on production systems
  • When agents are running autonomously (full-auto mode)
  • When you want to restrict edits to a specific directory
  • During sensitive operations (migrations, deploys, data changes)

How It Works

Three modes of protection:

Mode 1: Careful Mode

Intercepts destructive commands before execution and warns:

Watched patterns:- rm -rf (especially /, ~, or project root)- git push --force- git reset --hard- git checkout . (discard all changes)- DROP TABLE / DROP DATABASE- docker system prune- kubectl delete- chmod 777- sudo rm- npm publish (accidental publishes)- Any command with --no-verify

When detected: shows what the command does, asks for confirmation, suggests safer alternative.

Mode 2: Freeze Mode

Locks file edits to a specific directory tree:

/safety-guard freeze src/components/

Any Write/Edit outside src/components/ is blocked with an explanation. Useful when you want an agent to focus on one area without touching unrelated code.

Mode 3: Guard Mode (Careful + Freeze combined)

Both protections active. Maximum safety for autonomous agents.

/safety-guard guard --dir src/api/ --allow-read-all

Agents can read anything but only write to src/api/. Destructive commands are blocked everywhere.

Unlock

/safety-guard off

Implementation

Uses PreToolUse hooks to intercept Bash, Write, Edit, and MultiEdit tool calls. Checks the command/path against the active rules before allowing execution.

Integration

  • Enable by default for codex -a never sessions
  • Pair with observability risk scoring in ECC 2.0
  • Logs all blocked actions to ~/.claude/safety-guard.log

来源与署名

来源:affaan-m/ECC位于skills/safety-guard提交ef648e0

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架