Git Guardrails Claude Code

作者 mattpocockc55ee46073ed無授權條款收錄於 2026年10月8日更新於 2026年10月8日

Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute. Use when user wants to prevent destructive git operations, add git safety hooks, or block git push/reset in Claude Code.

AI 產生的概覽

設定 Claude Code 掛鉤,在執行前攔截 push、reset --hard、clean 等危險 git 指令。

功能
此技能會在 Claude Code 中安裝 PreToolUse 掛鉤,攔截 Bash 工具呼叫並阻擋具破壞性的 git 指令,包括 git push、git reset --hard、git clean -f/-fd、git branch -D 以及 git checkout ./git restore .。它會把內附的 shell 指令碼複製到專案層級或全域掛鉤目錄、賦予可執行權限,並將掛鉤項目合併進對應的設定檔,且不覆寫既有設定。它也會詢問是否自訂攔截樣式清單,並提供測試指令以驗證掛鉤以結束碼 2 結束並輸出 BLOCKED 訊息。
適用情境
當你希望避免 Claude Code 執行具破壞性的 git 操作、加入 git 安全掛鉤,或在代理工作階段中阻擋 git push 與 reset 指令時使用。適合需要在單一專案範圍或所有專案中設定防護的使用者。
執行需求
需要支援掛鉤的 Claude Code 以及可寫入的設定檔(.claude/settings.json 或 ~/.claude/settings.json)。它內附可執行的 shell 指令碼(scripts/block-dangerous-git.sh),需要 POSIX shell 環境與 chmod;不需要憑證或網路存取。

Setup Git Guardrails

Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.

What Gets Blocked

  • git push (all variants including --force)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

When blocked, Claude sees a message telling it that it does not have authority to access these commands.

Steps

1. Ask scope

Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?

2. Copy the hook script

The bundled script is at: scripts/block-dangerous-git.sh [blocked]

Copy it to the target location based on scope:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

Make it executable with chmod +x.

3. Add hook to settings

Add to the appropriate settings file:

Project (.claude/settings.json):

json
{  "hooks": {    "PreToolUse": [      {        "matcher": "Bash",        "hooks": [          {            "type": "command",            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"          }        ]      }    ]  }}

Global (~/.claude/settings.json):

json
{  "hooks": {    "PreToolUse": [      {        "matcher": "Bash",        "hooks": [          {            "type": "command",            "command": "~/.claude/hooks/block-dangerous-git.sh"          }        ]      }    ]  }}

If the settings file already exists, merge the hook into the existing hooks.PreToolUse array. Don't overwrite other settings.

4. Ask about customization

Ask if user wants to add or remove any patterns from the blocked list. Edit the copied script accordingly.

5. Verify

Run a quick test:

bash
echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

Should exit with code 2 and print a BLOCKED message to stderr.

來源與署名

來源:mattpocock/skills位於skills/misc/git-guardrails-claude-code提交c55ee46

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架