safety-guard
affaan-m/ecc
Prevent destructive operations on production systems and autonomous agents with configurable safety modes.
What is safety-guard?
Safety Guard intercepts dangerous commands (rm -rf, git push --force, DROP TABLE, etc.) before execution and optionally locks file edits to a specific directory. Use it when working on production systems, running agents in full-auto mode, or during sensitive operations like migrations and deploys.
- Intercepts destructive commands (rm -rf, git push --force, git reset --hard, DROP TABLE, docker system prune, kubectl delete, etc.) and requests confirmation before execution
- Suggests safer alternatives to dangerous operations
- Locks file edits to a specified directory tree while allowing reads elsewhere
- Combines Careful Mode (command warnings) and Freeze Mode (directory restrictions) into Guard Mode for maximum autonomous safety
- Logs all blocked actions to ~/.claude/safety-guard.log for audit trails
How to install safety-guard
npx skills add null --skill safety-guardHow to use safety-guard
- 1.Install the skill using: npx skills add null --skill safety-guard
- 2.Enable Careful Mode to intercept and warn about destructive commands: /safety-guard careful
- 3.Enable Freeze Mode to lock edits to a directory: /safety-guard freeze src/components/
- 4.Enable Guard Mode for combined protection: /safety-guard guard --dir src/api/ --allow-read-all
- 5.Disable protection when needed: /safety-guard off
- 6.Check blocked actions in the log file: ~/.claude/safety-guard.log
Use cases
- Protect production systems from accidental destructive commands while developing or debugging
- Run autonomous agents safely in full-auto mode by restricting writes to a specific codebase directory
- Prevent unintended git force-pushes, database drops, or permission changes during sensitive migrations
- Allow agents to read across the entire codebase but only modify code in a designated component or API directory
- Audit and track all blocked dangerous operations for compliance and incident review
- DevOps engineers and SREs managing production systems
- Teams running autonomous coding agents without human supervision
- Developers working on critical systems who want an extra safety net
- Engineering leads enforcing guardrails during deployments and migrations
safety-guard FAQ
It intercepts rm -rf (especially on /, ~, or project root), git push --force, git reset --hard, git checkout ., DROP TABLE/DATABASE, docker system prune, kubectl delete, chmod 777, sudo rm, npm publish, and any command with --no-verify.
Yes. In Freeze Mode, agents can read anywhere but only write to the specified directory. Use --allow-read-all flag in Guard Mode to make this explicit.
Run /safety-guard off to disable all protections.
All blocked actions are logged to ~/.claude/safety-guard.log for audit and compliance purposes.
Yes. Safety Guard is recommended by default for codex -a never sessions and any full-auto agent mode to prevent unintended destructive operations.
Full instructions (SKILL.md)
Source of truth, from affaan-m/ecc.
name: safety-guard description: Use this skill to prevent destructive operations when working on production systems or running agents autonomously. metadata: origin: ECC
Safety Guard — Prevent Destructive Operations
When to Use
- When working on production systems
- When agents are running autonomously (full-auto mode)
- When you want to restrict edits to a specific directory
- During sensitive operations (migrations, deploys, data changes)
How It Works
Three modes of protection:
Mode 1: Careful Mode
Intercepts destructive commands before execution and warns:
Watched patterns:
- rm -rf (especially /, ~, or project root)
- git push --force
- git reset --hard
- git checkout . (discard all changes)
- DROP TABLE / DROP DATABASE
- docker system prune
- kubectl delete
- chmod 777
- sudo rm
- npm publish (accidental publishes)
- Any command with --no-verify
When detected: shows what the command does, asks for confirmation, suggests safer alternative.
Mode 2: Freeze Mode
Locks file edits to a specific directory tree:
/safety-guard freeze src/components/
Any Write/Edit outside src/components/ is blocked with an explanation. Useful when you want an agent to focus on one area without touching unrelated code.
Mode 3: Guard Mode (Careful + Freeze combined)
Both protections active. Maximum safety for autonomous agents.
/safety-guard guard --dir src/api/ --allow-read-all
Agents can read anything but only write to src/api/. Destructive commands are blocked everywhere.
Unlock
/safety-guard off
Implementation
Uses PreToolUse hooks to intercept Bash, Write, Edit, and MultiEdit tool calls. Checks the command/path against the active rules before allowing execution.
Integration
- Enable by default for
codex -a neversessions - Pair with observability risk scoring in ECC 2.0
- Logs all blocked actions to
~/.claude/safety-guard.log
Related skills
More from affaan-m/ecc and the wider catalog.
santa-method
Multi-agent adversarial verification with convergence loop.
scholar-evaluation
Structured evaluation of academic papers, proposals, and research using a repeatable 9-dimension rubric.
search-first
Research existing solutions before writing custom code—search npm, PyPI, MCP, and GitHub systematically.
security-bounty-hunter
Hunt for exploitable, bounty-worthy security vulnerabilities in repositories with minimal noise.
security-review
Comprehensive security checklist and patterns for authentication, input validation, secrets, and sensitive features.
security-scan
Audit Claude Code configuration for security vulnerabilities, misconfigurations, and injection risks.