PluginBench
Skill
Pass
Audit score 90

git-guardrails-claude-code

vinvcn/mattpocock-skills-zh-cn

Prevent destructive git operations in Claude Code by blocking dangerous commands before execution.

What is git-guardrails-claude-code?

Sets up PreToolUse hooks that intercept and block dangerous git commands (push, reset --hard, clean, branch -D, checkout .) before Claude executes them. Use this when you want to prevent accidental destructive git operations or add safety guardrails to your Claude Code workflow.

  • Blocks git push (all variants including --force)
  • Blocks git reset --hard
  • Blocks git clean -f and git clean -fd
  • Blocks git branch -D
  • Blocks git checkout . and git restore .
  • Allows Claude to see a permission-denied message instead of executing the command

How to install git-guardrails-claude-code

npx skills add https://github.com/vinvcn/mattpocock-skills-zh-cn --skill git-guardrails-claude-code
Prerequisites
  • Claude Code installed and configured
  • Access to .claude/settings.json (project-level) or ~/.claude/settings.json (global)
  • Bash shell available on your system
Claude Code
Cursor
Windsurf
Cline

How to use git-guardrails-claude-code

  1. 1.Decide whether to install for the current project only (.claude/settings.json) or globally (~/.claude/settings.json)
  2. 2.Copy the block-dangerous-git.sh script from the skill to the appropriate hooks directory (.claude/hooks/ or ~/.claude/hooks/)
  3. 3.Make the script executable with chmod +x
  4. 4.Add the PreToolUse hook configuration to your settings.json file, merging with any existing hooks
  5. 5.Optionally customize the blocked command patterns by editing the copied script
  6. 6.Verify the setup by running the test command provided in the skill documentation

Use cases

Good for
  • Prevent accidental force pushes that could overwrite remote history
  • Stop Claude from hard-resetting uncommitted work
  • Block destructive branch deletions during automated workflows
  • Protect against unintended cleanup operations that remove tracked files
  • Add safety guardrails when using Claude Code in production repositories
Who it's for
  • Developers using Claude Code for repository management
  • Teams wanting to prevent destructive git operations
  • Users working with critical or shared repositories
  • Anyone concerned about accidental data loss from git commands

git-guardrails-claude-code FAQ

Will this prevent me from running git commands manually?

No, this only affects Claude Code's tool execution. You can still run git commands directly in your terminal.

Can I customize which git commands are blocked?

Yes, you can edit the block-dangerous-git.sh script to add or remove patterns from the blocked list after copying it.

What happens when Claude tries to run a blocked command?

Claude receives a permission-denied message and cannot execute the command, allowing it to choose an alternative approach.

Can I set this up for just one project instead of globally?

Yes, you can choose to install it project-level in .claude/settings.json or globally in ~/.claude/settings.json.

How do I verify the hook is working correctly?

Run the provided test command: echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>, which should exit with code 2 and print a BLOCKED message.

Full instructions (SKILL.md)

Source of truth, from vinvcn/mattpocock-skills-zh-cn.


name: git-guardrails-claude-code description: 设置 Claude Code hooks,在危险 git commands(push、reset --hard、clean、branch -D 等)执行前阻止它们。适用于用户想防止破坏性 git 操作、添加 git safety hooks,或在 Claude Code 中阻止 git push/reset 时。

Setup Git Guardrails

设置一个 PreToolUse hook,在 Claude 执行危险 git commands 前拦截并阻止它们。

What Gets Blocked

  • git push(包括 --force 在内的所有 variants)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

被阻止时,Claude 会看到一条 message,说明它无权访问这些 commands。

Steps

1. Ask scope

询问用户:只为当前 project 安装(.claude/settings.json),还是为所有 projects 安装(~/.claude/settings.json)?

2. Copy the hook script

bundled script 位于:scripts/block-dangerous-git.sh

根据 scope 复制到目标位置:

  • Project: .claude/hooks/block-dangerous-git.sh
  • Global: ~/.claude/hooks/block-dangerous-git.sh

用 chmod +x 让它可执行。

3. Add hook to settings

添加到对应 settings file:

Project (.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Global (~/.claude/settings.json):

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

如果 settings file 已存在,把 hook merge 到现有 hooks.PreToolUse array 中,不要覆盖其他 settings。

4. Ask about customization

询问用户是否要在 blocked list 中添加或移除 patterns。相应编辑复制后的 script。

5. Verify

运行快速测试:

echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

应以 code 2 退出,并向 stderr 打印 BLOCKED message。