PluginBench
Skill
Pass
Audit score 90

safety-guard

affaan-m/ecc

Prevent destructive operations on production systems and autonomous agents with configurable safety modes.

What is safety-guard?

Safety Guard intercepts dangerous commands (rm -rf, git push --force, DROP TABLE, etc.) before execution and optionally locks file edits to a specific directory. Use it when working on production systems, running agents in full-auto mode, or during sensitive operations like migrations and deploys.

  • Intercepts destructive commands (rm -rf, git push --force, git reset --hard, DROP TABLE, docker system prune, kubectl delete, etc.) and requests confirmation before execution
  • Suggests safer alternatives to dangerous operations
  • Locks file edits to a specified directory tree while allowing reads elsewhere
  • Combines Careful Mode (command warnings) and Freeze Mode (directory restrictions) into Guard Mode for maximum autonomous safety
  • Logs all blocked actions to ~/.claude/safety-guard.log for audit trails

How to install safety-guard

npx skills add null --skill safety-guard
Claude Code
Cursor
Windsurf
Cline

How to use safety-guard

  1. 1.Install the skill using: npx skills add null --skill safety-guard
  2. 2.Enable Careful Mode to intercept and warn about destructive commands: /safety-guard careful
  3. 3.Enable Freeze Mode to lock edits to a directory: /safety-guard freeze src/components/
  4. 4.Enable Guard Mode for combined protection: /safety-guard guard --dir src/api/ --allow-read-all
  5. 5.Disable protection when needed: /safety-guard off
  6. 6.Check blocked actions in the log file: ~/.claude/safety-guard.log

Use cases

Good for
  • Protect production systems from accidental destructive commands while developing or debugging
  • Run autonomous agents safely in full-auto mode by restricting writes to a specific codebase directory
  • Prevent unintended git force-pushes, database drops, or permission changes during sensitive migrations
  • Allow agents to read across the entire codebase but only modify code in a designated component or API directory
  • Audit and track all blocked dangerous operations for compliance and incident review
Who it's for
  • DevOps engineers and SREs managing production systems
  • Teams running autonomous coding agents without human supervision
  • Developers working on critical systems who want an extra safety net
  • Engineering leads enforcing guardrails during deployments and migrations

safety-guard FAQ

What commands does Safety Guard block?

It intercepts rm -rf (especially on /, ~, or project root), git push --force, git reset --hard, git checkout ., DROP TABLE/DATABASE, docker system prune, kubectl delete, chmod 777, sudo rm, npm publish, and any command with --no-verify.

Can I still read files outside the frozen directory?

Yes. In Freeze Mode, agents can read anywhere but only write to the specified directory. Use --allow-read-all flag in Guard Mode to make this explicit.

How do I unlock Safety Guard?

Run /safety-guard off to disable all protections.

Where are blocked actions logged?

All blocked actions are logged to ~/.claude/safety-guard.log for audit and compliance purposes.

Should I enable this for autonomous agents?

Yes. Safety Guard is recommended by default for codex -a never sessions and any full-auto agent mode to prevent unintended destructive operations.

Full instructions (SKILL.md)

Source of truth, from affaan-m/ecc.


name: safety-guard description: Use this skill to prevent destructive operations when working on production systems or running agents autonomously. metadata: origin: ECC

Safety Guard — Prevent Destructive Operations

When to Use

  • When working on production systems
  • When agents are running autonomously (full-auto mode)
  • When you want to restrict edits to a specific directory
  • During sensitive operations (migrations, deploys, data changes)

How It Works

Three modes of protection:

Mode 1: Careful Mode

Intercepts destructive commands before execution and warns:

Watched patterns:
- rm -rf (especially /, ~, or project root)
- git push --force
- git reset --hard
- git checkout . (discard all changes)
- DROP TABLE / DROP DATABASE
- docker system prune
- kubectl delete
- chmod 777
- sudo rm
- npm publish (accidental publishes)
- Any command with --no-verify

When detected: shows what the command does, asks for confirmation, suggests safer alternative.

Mode 2: Freeze Mode

Locks file edits to a specific directory tree:

/safety-guard freeze src/components/

Any Write/Edit outside src/components/ is blocked with an explanation. Useful when you want an agent to focus on one area without touching unrelated code.

Mode 3: Guard Mode (Careful + Freeze combined)

Both protections active. Maximum safety for autonomous agents.

/safety-guard guard --dir src/api/ --allow-read-all

Agents can read anything but only write to src/api/. Destructive commands are blocked everywhere.

Unlock

/safety-guard off

Implementation

Uses PreToolUse hooks to intercept Bash, Write, Edit, and MultiEdit tool calls. Checks the command/path against the active rules before allowing execution.

Integration

  • Enable by default for codex -a never sessions
  • Pair with observability risk scoring in ECC 2.0
  • Logs all blocked actions to ~/.claude/safety-guard.log