Aisafetyhot
wuyoscar/AISafetyHot-Hub
Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.
Configure the shared guard against catastrophic shell commands in local AI agents.
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install davidondrej/skills global-agent-guardrails --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .claude/skills/global-agent-guardrails && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "global-agent-guardrails" agent skill from https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrails into .claude/skills/global-agent-guardrails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "global-agent-guardrails", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrailsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install davidondrej/skills global-agent-guardrails --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .agents/skills/global-agent-guardrails && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "global-agent-guardrails" agent skill from https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrails into .agents/skills/global-agent-guardrails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "global-agent-guardrails", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install davidondrej/skills global-agent-guardrails --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .cursor/skills/global-agent-guardrails && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "global-agent-guardrails" agent skill from https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrails into .cursor/skills/global-agent-guardrails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "global-agent-guardrails", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/davidondrej/skills.git --path skills/ops-and-setup/global-agent-guardrails--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install davidondrej/skills global-agent-guardrails --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .gemini/skills/global-agent-guardrails && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "global-agent-guardrails" agent skill from https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrails into .gemini/skills/global-agent-guardrails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "global-agent-guardrails", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install davidondrej/skills global-agent-guardrailsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .github/skills/global-agent-guardrails && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "global-agent-guardrails" agent skill from https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrails into .github/skills/global-agent-guardrails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "global-agent-guardrails", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install davidondrej/skills global-agent-guardrails --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .opencode/skills/global-agent-guardrails && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "global-agent-guardrails" agent skill from https://github.com/davidondrej/skills/tree/main/skills/ops-and-setup/global-agent-guardrails into .opencode/skills/global-agent-guardrails/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "global-agent-guardrails", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
global-agent-guardrailsConfigure the shared guard against catastrophic shell commands in local AI agents.
Global Agent Guardrails is an agent skill from davidondrej/skills. Configure the shared guard against catastrophic shell commands in local AI agents. Use when changing block patterns, adding an agent or machine, or investigating why a command was or wasn't blocked.
Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering, covering LLM guardrails. The repository describes itself as: access to david ondrej's personal agent skills. The licence is MIT.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit 387c2b8. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitpython3pythonFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Global Agent Guardrails loads about 1.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 620 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from davidondrej/skills at commit 387c2b8, republished under its MIT licence (© davidondrej). 620 words, ~1,616 tokens.
.claude/skills/global-agent-guardrails/SKILL.md (or your agent's skills folder).Block catastrophic shell commands before execution. One patterns file feeds a shared hook script or native adapter for each agent. This guards against accidents, not malicious agents (obfuscation like python -c "shutil.rmtree(...)" can slip past regex).
<GUARD_DIR>/dangerous-patterns.txt # THE denylist: one POSIX-ERE regex per line, # comments
<GUARD_DIR>/deny-dangerous.sh # shared guard: hook JSON on stdin -> exit 2 blocks
<GUARD_DIR>/test-guard.sh # test suite: run after ANY pattern change
~/.config/opencode/plugins/command-guard.ts # OpenCode adapter (throws to block)
~/.pi/agent/extensions/command-guard.ts # Pi adapter (returns {block:true})
~/.hermes/plugins/command-guard/ # Hermes plugin (returns {"action":"block"})ls <GUARD_DIR>/deny-dangerous.sh <GUARD_DIR>/dangerous-patterns.txt
<GUARD_DIR>/test-guard.sh # must end "failed: 0"If missing, rebuild from the wiring table (history: project research notes).
<GUARD_DIR>/dangerous-patterns.txt. Write POSIX ERE (grep -E). Use [[:space:]], never \\s — adapters auto-convert [:space:] to \\s for JS/Python and compile in multiline mode.test-guard.sh, then run it; all must pass.python3 -c 'import re,pathlib; [re.compile(l.strip().replace("[:space:]",r"\s"),re.M) for l in pathlib.Path("<GUARD_DIR>/dangerous-patterns.txt").read_text().splitlines() if l.strip() and not l.startswith("#")]; print("ok")'commandBlocklist in ~/.factory/settings.json — mirror changes there manually.Block only catastrophic commands (irreversible data loss, disk wipes, repo deletion). Recoverable local commands (git status, git clean -fdx, rm -rf node_modules) stay allowed; avoid over-blocking. Keep routine login and credential-management commands outside catastrophic-command rules.
Password-manager and secret-store access should be governed by a separate, locally chosen policy; do not publish private denylist entries or storage locations here.
| Agent | Config | Event | Blocks via |
|---|---|---|---|
| Claude Code | ~/.claude/settings.json | PreToolUse matcher Bash | shared script, exit 2 |
| Codex CLI/app/IDE | ~/.codex/hooks.json | PreToolUse matcher Bash | shared script, exit 2 |
| Cursor IDE + CLI | ~/.cursor/hooks.json | beforeShellExecution | shared script with cursor arg, deny JSON |
| Grok (xAI) | auto-loads Claude + Cursor hook files (compat on by default); native option ~/.grok/hooks/*.json | PreToolUse | shared script (reads .toolInput.command) |
| OpenCode | ~/.config/opencode/plugins/command-guard.ts | tool.execute.before | adapter throws Error |
| Pi | ~/.pi/agent/extensions/command-guard.ts | pi.on("tool_call") | adapter returns {block:true} |
| Hermes | ~/.hermes/plugins/command-guard/ (plugin.yaml + __init__.py) | pre_tool_call hook | plugin returns {"action":"block"} |
| Droid (Factory) | ~/.factory/settings.json | native commandBlocklist | hard-block, no approval possible |
| Devin CLI | ~/.config/devin/config.json | PreToolUse matcher ^exec$ | shared script, exit 2 |
Claude/Codex hook entry; for Devin, replace Bash with ^exec$. Merge into the existing hooks object; never overwrite it:
{"hooks": {"PreToolUse": [{"matcher": "Bash", "hooks": [{"type": "command", "command": "/ABSOLUTE/PATH/TO/deny-dangerous.sh"}]}]}}Cursor entry (payload has .command, so pass the cursor arg):
{"beforeShellExecution": [{"command": "/ABSOLUTE/PATH/TO/deny-dangerous.sh cursor", "failClosed": false}]}Use absolute paths in configs (~ expansion is inconsistent across agents).
hooks.json (not the patterns file) invalidates trust; run /hooks in Codex and re-trust, else Codex silently skips the guard. Trust hashes live in [hooks.state] in ~/.codex/config.toml and are shared by CLI, desktop app, and IDE extension. For CI or scripts, follow the tool's documented trust configuration.failClosed behavior depends on the runtime. Check the agent's documentation and choose a setting appropriate to its support for hook scripts.provides_hooks (not hooks). Plugin must be enabled in its configuration. The CLI enable command may prompt interactively and hang non-interactive shells. Hermes hooks are fail-open on exceptions — keep the plugin trivial. Shell tool name is terminal.tool_call handler errors block the tool (fail-safe) — adapter must catch its own errors and fail open, or a broken patterns file bricks every bash call.commandDenylist = ask for confirmation; commandBlocklist = never runs, even at full autonomy. Use blocklist for catastrophic entries..tool_input.command (Claude/Codex/Devin), .toolInput.command (Grok), .command (Cursor). Keep all three in the jq fallback chain.m flag and Python's re.M so ^ matches each shell line like grep.git push --force on a CLI) gets blocked. Workaround: put the text in a file and reference it.Safe probe: ask the agent to run git push --force from a NON-git directory — blocked = guard works; "not a git repository" = guard failed but no harm done. Run probes using the agent's documented command interface and permission settings.
Direct script test:
echo '{"tool_input":{"command":"rm -rf /"}}' | <GUARD_DIR>/deny-dangerous.sh; echo "exit=$?" # expect exit=2© davidondrej, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in skills/ops-and-setup/global-agent-guardrails of davidondrej/skills.
Open the folder on GitHubat commit 387c2b8
Global Agent Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Global Agent Guardrails this skilldavidondrej/skills | 4.1k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Aisafetyhotwuyoscar/AISafetyHot-Hub | 827 | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| ObliteratusRedWoodOG/Hermes-Desktop | 177 | 5 repos | ~3.8k | Automated safety check: Pass | MIT | |
| Lemonade Router Builderamd/skills | 408 | — | ~4k | Automated safety check: Pass | MIT | |
| Writing Eval Scenariosopen-bias/open-bias | 143 | — | ~1.5k | Automated safety check: Pass | Apache-2.0 | |
| Wp Project Triagegambitph/Stackable | 351 | 3 repos | ~371 | Automated safety check: Pass | GPL-3.0 |
wuyoscar/AISafetyHot-Hub
Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.
RedWoodOG/Hermes-Desktop
Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…
amd/skills
Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.
open-bias/open-bias
Guide for writing eval conversation JSONs and running them through policy engines
gambitph/Stackable
A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…
aws-samples/sample-well-architected-skills-and-steering
Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…
davidondrej/skills
Launch a new bb worker thread with the right project, model, worktree, and task brief.
davidondrej/skills
Direct browser control via CDP. An agent skill from davidondrej/skills.
davidondrej/skills
Manage persistent dev servers, APIs, and other local processes on a port using macOS LaunchAgents.
davidondrej/skills
Reset a stuck Cursor ACP thread in <chat-system and reload its configuration.
davidondrej/skills
Keep a Mac awake for a set duration or while a process runs.
davidondrej/skills
Use this when controlling bb. An agent skill from davidondrej/skills.
Categories
Configure the shared guard against catastrophic shell commands in local AI agents. Global Agent Guardrails is an agent skill from davidondrej/skills. Configure the shared guard against catastrophic shell commands in local AI agents.
Global Agent Guardrails fits situations like: changing block patterns; adding an agent; investigating why a command was.
Run `npx skills add davidondrej/skills --skill global-agent-guardrails -a claude-code`. Or copy the skill folder (skills/ops-and-setup/global-agent-guardrails in davidondrej/skills) into .claude/skills/global-agent-guardrails in your project. Claude Code loads it when a task matches its description.
Run `npx skills add davidondrej/skills --skill global-agent-guardrails -a codex`. Or copy the skill folder (skills/ops-and-setup/global-agent-guardrails in davidondrej/skills) into .agents/skills/global-agent-guardrails in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davidondrej/skills --skill global-agent-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/global-agent-guardrails, .gemini/skills/global-agent-guardrails, .github/skills/global-agent-guardrails and .opencode/skills/global-agent-guardrails in your project.
Going by SKILL.md and its folder, Global Agent Guardrails needs the command-line tools its instructions call (git, python3 and python). Our summary lists: Python 3.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Global Agent Guardrails is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Global Agent Guardrails: Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars), Lemonade Router Builder (amd/skills, 408 stars) and Writing Eval Scenarios (open-bias/open-bias, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
davidondrej (a GitHub user) maintains it in davidondrej/skills, which has 4,112 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 10, 2026.
Source: davidondrej/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.