agentsclimarketplace

Git guardrails

Skill manastalukdar/ai-devstudio/skills/git-guardrails

Professional development studio for Claude Code CLI

Install
npx -y skills add manastalukdar/ai-devstudio --skill git-guardrails

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

One thing to look at

  • 1 stars1 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Install a Claude Code PreToolUse hook that blocks dangerous git operations (force push, reset --hard, clean -f, branch -D, checkout ., restore .) before they execute. Use when setting up git safety hooks or preventing destructive git commands in Claude Code.

SKILL.md

4.3 KB, ~1.1k tokens by cl100k_base, as published. Nobody here has run it

Git Guardrails

Install a PreToolUse hook in Claude Code that intercepts and blocks dangerous git operations before they run.

Arguments: $ARGUMENTS - global to install in ~/.claude/settings.json, or blank for project-level .claude/settings.json

Behavior

1. Determine Scope

if [[ "$ARGUMENTS" == "global" ]]; then
  SETTINGS="$HOME/.claude/settings.json"
  HOOKS_DIR="$HOME/.claude/hooks"
else
  SETTINGS=".claude/settings.json"
  HOOKS_DIR=".claude/hooks"
fi
mkdir -p "$HOOKS_DIR"

2. Create the Block Script

cat > "$HOOKS_DIR/block-dangerous-git.sh" << 'SCRIPT'
#!/bin/bash
set -e

input=$(cat)
command=$(echo "$input" | jq -r '.command // empty')

# Only check Bash tool calls
[ -z "$command" ] && exit 0

dangerous_patterns=(
  "git push"
  "push --force"
  "git reset --hard"
  "reset --hard"
  "git clean -fd"
  "git clean -f"
  "git branch -D"
  "git checkout \."
  "git restore \."
)

for pattern in "${dangerous_patterns[@]}"; do
  if echo "$command" | grep -E "$pattern" > /dev/null 2>&1; then
    echo "BLOCKED: '$command' matches dangerous pattern '$pattern'. The user has prevented this operation." >&2
    exit 2
  fi
done

exit 0
SCRIPT

chmod +x "$HOOKS_DIR/block-dangerous-git.sh"
echo "Hook script created: $HOOKS_DIR/block-dangerous-git.sh"

3. Register in Claude Code Settings

Read or create the settings file, then add the hook:

# Read existing settings or start fresh
if [ -f "$SETTINGS" ]; then
  CURRENT=$(cat "$SETTINGS")
else
  CURRENT='{}'
fi

# Use jq to safely add the PreToolUse hook (preserves existing config)
HOOK_PATH="$(pwd)/$HOOKS_DIR/block-dangerous-git.sh"
[[ "$ARGUMENTS" == "global" ]] && HOOK_PATH="$HOME/.claude/hooks/block-dangerous-git.sh"

echo "$CURRENT" | jq \
  --arg hook "$HOOK_PATH" \
  '.hooks.PreToolUse += [{"matcher": "Bash", "hooks": [{"type": "command", "command": $hook}]}]' \
  > "$SETTINGS"

echo "Hook registered in: $SETTINGS"

4. Verify

# Test the script directly
echo '{"command": "git push origin main"}' | bash "$HOOKS_DIR/block-dangerous-git.sh"
# Should exit 2 and print BLOCKED message to stderr

echo '{"command": "git status"}' | bash "$HOOKS_DIR/block-dangerous-git.sh"
# Should exit 0 (allowed)

5. Report

Git guardrails installed:

  Hook script:  .claude/hooks/block-dangerous-git.sh
  Settings:     .claude/settings.json
  Scope:        project

Blocked operations:
  git push / push --force
  git reset --hard
  git clean -f / -fd
  git branch -D
  git checkout . / git restore .

To customize: edit .claude/hooks/block-dangerous-git.sh
To test: echo '{"command": "git push"}' | bash .claude/hooks/block-dangerous-git.sh
To remove: delete the hook entry from .claude/settings.json

Blocked Operations

PatternWhy dangerous
git push / push --forceOverwrites remote history; hard to recover from
git reset --hardDiscards uncommitted work permanently
git clean -f / -fdDeletes untracked files/dirs permanently
git branch -DDeletes branch without merge check
git checkout . / git restore .Discards all working tree changes

Customization

Edit the dangerous_patterns array in the hook script to add or remove patterns. The script uses grep -E for matching, so regex patterns are supported.

Examples

/git-guardrails           ← project-level (.claude/settings.json)
/git-guardrails global    ← user-level (~/.claude/settings.json)

Edge Cases

  • jq not installed: Reports the required JSON change to make manually
  • Hook already exists: Detects duplicate matcher and skips re-adding
  • Global scope: Uses ~/.claude/ paths instead of project-local

Token Optimization

Expected range: 300–500 tokens

Early exit: Detects if hook already registered in settings before making changes.

Template-based: Script content is fixed — no LLM generation needed.

Patterns used: Early exit, template-based generation, Bash for system queries

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.