git-guardrails-claude-code
vinvcn/mattpocock-skills-zh-cn
Prevent destructive git operations in Claude Code by blocking dangerous commands before execution.
What is git-guardrails-claude-code?
Sets up PreToolUse hooks that intercept and block dangerous git commands (push, reset --hard, clean, branch -D, checkout .) before Claude executes them. Use this when you want to prevent accidental destructive git operations or add safety guardrails to your Claude Code workflow.
- Blocks git push (all variants including --force)
- Blocks git reset --hard
- Blocks git clean -f and git clean -fd
- Blocks git branch -D
- Blocks git checkout . and git restore .
- Allows Claude to see a permission-denied message instead of executing the command
How to install git-guardrails-claude-code
npx skills add https://github.com/vinvcn/mattpocock-skills-zh-cn --skill git-guardrails-claude-code- Claude Code installed and configured
- Access to .claude/settings.json (project-level) or ~/.claude/settings.json (global)
- Bash shell available on your system
How to use git-guardrails-claude-code
- 1.Decide whether to install for the current project only (.claude/settings.json) or globally (~/.claude/settings.json)
- 2.Copy the block-dangerous-git.sh script from the skill to the appropriate hooks directory (.claude/hooks/ or ~/.claude/hooks/)
- 3.Make the script executable with chmod +x
- 4.Add the PreToolUse hook configuration to your settings.json file, merging with any existing hooks
- 5.Optionally customize the blocked command patterns by editing the copied script
- 6.Verify the setup by running the test command provided in the skill documentation
Use cases
- Prevent accidental force pushes that could overwrite remote history
- Stop Claude from hard-resetting uncommitted work
- Block destructive branch deletions during automated workflows
- Protect against unintended cleanup operations that remove tracked files
- Add safety guardrails when using Claude Code in production repositories
- Developers using Claude Code for repository management
- Teams wanting to prevent destructive git operations
- Users working with critical or shared repositories
- Anyone concerned about accidental data loss from git commands
git-guardrails-claude-code FAQ
No, this only affects Claude Code's tool execution. You can still run git commands directly in your terminal.
Yes, you can edit the block-dangerous-git.sh script to add or remove patterns from the blocked list after copying it.
Claude receives a permission-denied message and cannot execute the command, allowing it to choose an alternative approach.
Yes, you can choose to install it project-level in .claude/settings.json or globally in ~/.claude/settings.json.
Run the provided test command: echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>, which should exit with code 2 and print a BLOCKED message.
Full instructions (SKILL.md)
Source of truth, from vinvcn/mattpocock-skills-zh-cn.
name: git-guardrails-claude-code description: 设置 Claude Code hooks,在危险 git commands(push、reset --hard、clean、branch -D 等)执行前阻止它们。适用于用户想防止破坏性 git 操作、添加 git safety hooks,或在 Claude Code 中阻止 git push/reset 时。
Setup Git Guardrails
设置一个 PreToolUse hook,在 Claude 执行危险 git commands 前拦截并阻止它们。
What Gets Blocked
git push(包括--force在内的所有 variants)git reset --hardgit clean -f/git clean -fdgit branch -Dgit checkout ./git restore .
被阻止时,Claude 会看到一条 message,说明它无权访问这些 commands。
Steps
1. Ask scope
询问用户:只为当前 project 安装(.claude/settings.json),还是为所有 projects 安装(~/.claude/settings.json)?
2. Copy the hook script
bundled script 位于:scripts/block-dangerous-git.sh
根据 scope 复制到目标位置:
- Project:
.claude/hooks/block-dangerous-git.sh - Global:
~/.claude/hooks/block-dangerous-git.sh
用 chmod +x 让它可执行。
3. Add hook to settings
添加到对应 settings file:
Project (.claude/settings.json):
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
}
]
}
]
}
}
Global (~/.claude/settings.json):
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "~/.claude/hooks/block-dangerous-git.sh"
}
]
}
]
}
}
如果 settings file 已存在,把 hook merge 到现有 hooks.PreToolUse array 中,不要覆盖其他 settings。
4. Ask about customization
询问用户是否要在 blocked list 中添加或移除 patterns。相应编辑复制后的 script。
5. Verify
运行快速测试:
echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>
应以 code 2 退出,并向 stderr 打印 BLOCKED message。
Related skills
More from vinvcn/mattpocock-skills-zh-cn and the wider catalog.

grill-me
Continuous questioning interview to refine plans or designs.

grill-with-docs
Iterative questioning interviews to refine plans and designs while generating ADRs and glossaries.

grilling
Systematically pressure-test plans, decisions, or ideas through structured questioning.

handoff
Compress conversation into a handoff document for the next agent to continue work.

implement
Implement features from specs or tickets with TDD and code review.

improve-codebase-architecture
Scan codebases for architectural deepening opportunities and generate visual refactoring reports.