Safety guard against destructive commands in production and autonomous agents
Block destructive ops before they run — rm -rf, git push --force, DROP TABLE, kubectl delete — plus directory-freeze modes for autonomous agents
- What
- Block destructive ops before they run — rm -rf, git push --force, DROP TABLE, kubectl delete — plus directory-freeze modes for autonomous agents
- Cost
- Free
- Needs
- an agent harness that supports pre-execution hooks (the design uses PreToolUse hooks); production or autonomous-agent work where destructive commands are a real risk; no accounts or keys required
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor — @affaan-m's safety guard for working in production systems or running agents autonomously. Three protection modes: Careful mode detects destructive commands before execution and warns with confirmation plus a safer alternative (watched patterns include `rm -rf` — especially on `/`, `~` or the project root — `git push --force`, `git reset --hard`, `git checkout .`, `DROP TABLE`/`DROP DATABASE`, `docker system prune`, `kubectl delete`, `chmod 777`, `sudo rm`, `npm publish` against accidental publishes, and any command with `--no-verify`); Freeze mode locks file edits to one directory tree (`/safety-guard freeze src/components/` — writes outside it are blocked with explanation), useful to keep an agent focused on one area; Guard mode combines both for maximum safety with autonomous agents (read everything, write only in the allowed directory). The implementation uses PreToolUse hooks on Bash, Write, Edit and MultiEdit calls, logs every blocked action to `~/.claude/safety-guard.log`, and integrates with full-auto agent sessions and ECC 2.0 observability risk scoring. Honest caveats: **the skill is written in Japanese** (lives under `docs/ja-JP/`); it describes a hook-based design — wiring it into your agent harness is your own setup work; MIT-licensed. Skill Harbor never reviews the code, review it yourself before use. Discovered via skills.sh.
Version:
Install
Prerequisites: an agent harness that supports pre-execution hooks (the design uses PreToolUse hooks); production or autonomous-agent work where destructive commands are a real risk; no accounts or keys required Install "Safety guard against destructive commands in production and autonomous agents" for me. It gives my agent @affaan-m's safety guard: Careful mode warns before destructive commands (rm -rf, git push --force, git reset --hard, DROP TABLE/DATABASE, docker system prune, kubectl delete, npm publish, --no-verify flags) with confirmation and safer alternatives; Freeze mode locks file writes to one directory tree; Guard mode combines both for autonomous agents — implemented via PreToolUse hooks on Bash/Write/Edit/MultiEdit, with blocked actions logged to ~/.claude/safety-guard.log. Written in Japanese; MIT-licensed. Repository: https://github.com/affaan-m/ecc/blob/main/docs/ja-JP/skills/safety-guard/SKILL.md 1. Fetch the SKILL.md file (and any helper files) from the repository path into a temporary folder and summarize what it does in one or two sentences. 2. Safety check: review the SKILL.md and scripts for anything suspicious (unexpected network calls, shell commands, credential harvesting). This repo should contain zero secrets in code, credentials only via the secure vault, allowed hosts declared in the SKILL.md. Verify that holds here; STOP on any red flag and tell me. 3. Install it as a skill: copy SKILL.md and its helper files into the agent's skills directory, in a folder named "safety-guard". 4. Verify with no network calls: frontmatter valid, files in place. 5. Report what was installed, where, and what I still need to do myself (e.g. wire the PreToolUse hooks into my agent harness per the skill's implementation section — the SKILL.md describes what to detect, the hook wiring is harness-specific). GitHub is optional: if I have a GitHub account or the gh CLI, you may use it; otherwise public access is fine. Never require it unless it's in the prerequisites above. Rules: don't touch anything outside the temp folder and the install target. If anything looks off, stop and ask me.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.