Git Guardrails Claude Code

作者 mattpocockc55ee46073ed无许可证收录于 2026年10月8日更新于 2026年10月8日

Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.

AI 生成的概览

设置 Claude Code 钩子,在执行前拦截 push、reset --hard、clean 等危险 git 命令。

功能
该技能在 Claude Code 中安装 PreToolUse 钩子,拦截 Bash 工具调用并阻止破坏性 git 命令,包括 git push、git reset --hard、git clean -f/-fd、git branch -D 以及 git checkout ./git restore .。它会把自带的 shell 脚本复制到项目级或全局钩子目录、赋予可执行权限,并将钩子条目合并进相应设置文件,且不覆盖已有设置。它还会询问是否自定义拦截模式列表,并给出测试命令以验证钩子以退出码 2 结束并输出 BLOCKED 信息。
适用场景
当你希望防止 Claude Code 执行破坏性 git 操作、添加 git 安全钩子,或在代理会话中阻止 git push 与 reset 命令时使用。适合需要在单个项目范围或所有项目中设置防护的用户。
运行要求
需要支持钩子的 Claude Code 以及可写的设置文件(.claude/settings.json 或 ~/.claude/settings.json)。它附带可执行 shell 脚本(scripts/block-dangerous-git.sh),需要 POSIX shell 环境和 chmod;无需凭据或网络访问。

Setup Git Guardrails

Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.

What Gets Blocked

  • git push (all variants including --force)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

When blocked, Claude sees a message telling it that it does not have authority to access these commands.

Steps

1. Ask scope

Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?

2. Copy the hook script

The bundled script is at: scripts/block-dangerous-git.sh [blocked]

Copy it to the target location based on scope:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

Make it executable with chmod +x.

3. Add hook to settings

Add to the appropriate settings file:

Project (.claude/settings.json):

json
{  "hooks": {    "PreToolUse": [      {        "matcher": "Bash",        "hooks": [          {            "type": "command",            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"          }        ]      }    ]  }}

Global (~/.claude/settings.json):

json
{  "hooks": {    "PreToolUse": [      {        "matcher": "Bash",        "hooks": [          {            "type": "command",            "command": "~/.claude/hooks/block-dangerous-git.sh"          }        ]      }    ]  }}

If the settings file already exists, merge the hook into the existing hooks.PreToolUse array. Don't overwrite other settings.

4. Ask about customization

Ask if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.

5. Verify

Run a quick test:

bash
echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

Should exit with code 2 and print a BLOCKED message to stderr.

来源与署名

来源:mattpocock/skills位于skills/misc/git-guardrails-claude-code提交c55ee46

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架