Agent skill

Global Agent Guardrails

by davidondrej in davidondrej/skills

Configure the shared guard against catastrophic shell commands in local AI agents.

MITAuto-check passedAI & LLM Engineering

Install Global Agent Guardrails

skills CLI
$ npx skills add davidondrej/skills --skill global-agent-guardrails -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install davidondrej/skills global-agent-guardrails --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/davidondrej/skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/ops-and-setup/global-agent-guardrails .claude/skills/global-agent-guardrails && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
global-agent-guardrails
GitHub stars
4.1k
Token cost
~1.6k tokens
SKILL.md length
620 words
Files
1
Skills in repo
51
Repo updated
First seen
Licence
MIT

At a glance

Configure the shared guard against catastrophic shell commands in local AI agents.

  • Works in 4 steps: Edit /dangerous-patterns.txt. Write… → Add block and allow cases to… → Verify the new pattern compiles in the… → …
  • Changing block patterns
  • SKILL.md covers File map, Check installation, Add or tune a pattern and Per-agent wiring (user-global), plus 2 more sections
  • Calls git, python3 and python

What it does

Global Agent Guardrails is an agent skill from davidondrej/skills. Configure the shared guard against catastrophic shell commands in local AI agents. Use when changing block patterns, adding an agent or machine, or investigating why a command was or wasn't blocked.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering LLM guardrails. The repository describes itself as: access to david ondrej's personal agent skills. The licence is MIT.

When your agent uses it

  • Changing block patterns
  • Adding an agent
  • Investigating why a command was

Example prompts

  • “/global-agent-guardrails”

Requirements

  • Python 3

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Edit /dangerous-patterns.txt. Write POSIX ERE (grep -E). Use [[:space:]], never \s — adapters auto-convert [:space:] to \s for JS/Python…
  2. Add block and allow cases to test-guard.sh, then run it; all must pass.
  3. Verify the new pattern compiles in the adapter engines
  4. Consumers re-read patterns for every command. Exception: Droid uses commandBlocklist in ~/.factory/settings.json — mirror changes there…

What it can do on your machine

Read from SKILL.md and the folder at commit 387c2b8. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • python3
    • python

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Global Agent Guardrails loads about 1.6k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 620 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from davidondrej/skills at commit 387c2b8, republished under its MIT licence (© davidondrej). 620 words, ~1,616 tokens.

Download SKILL.mdSave it as .claude/skills/global-agent-guardrails/SKILL.md (or your agent's skills folder).
name
global-agent-guardrails
description
Configure the shared guard against catastrophic shell commands in local AI agents. Use when changing block patterns, adding an agent or machine, or investigating why a command was or wasn't blocked.

Global Agent Guardrails

Block catastrophic shell commands before execution. One patterns file feeds a shared hook script or native adapter for each agent. This guards against accidents, not malicious agents (obfuscation like python -c "shutil.rmtree(...)" can slip past regex).

File map

<GUARD_DIR>/dangerous-patterns.txt   # THE denylist: one POSIX-ERE regex per line, # comments
<GUARD_DIR>/deny-dangerous.sh        # shared guard: hook JSON on stdin -> exit 2 blocks
<GUARD_DIR>/test-guard.sh            # test suite: run after ANY pattern change
~/.config/opencode/plugins/command-guard.ts   # OpenCode adapter (throws to block)
~/.pi/agent/extensions/command-guard.ts       # Pi adapter (returns {block:true})
~/.hermes/plugins/command-guard/              # Hermes plugin (returns {"action":"block"})

Check installation

bash
ls <GUARD_DIR>/deny-dangerous.sh <GUARD_DIR>/dangerous-patterns.txt
<GUARD_DIR>/test-guard.sh   # must end "failed: 0"

If missing, rebuild from the wiring table (history: project research notes).

Add or tune a pattern

  1. Edit <GUARD_DIR>/dangerous-patterns.txt. Write POSIX ERE (grep -E). Use [[:space:]], never \\s — adapters auto-convert [:space:] to \\s for JS/Python and compile in multiline mode.
  2. Add block and allow cases to test-guard.sh, then run it; all must pass.
  3. Verify the new pattern compiles in the adapter engines:
bash
python3 -c 'import re,pathlib; [re.compile(l.strip().replace("[:space:]",r"\s"),re.M) for l in pathlib.Path("<GUARD_DIR>/dangerous-patterns.txt").read_text().splitlines() if l.strip() and not l.startswith("#")]; print("ok")'
  1. Consumers re-read patterns for every command. Exception: Droid uses commandBlocklist in ~/.factory/settings.json — mirror changes there manually.

Block only catastrophic commands (irreversible data loss, disk wipes, repo deletion). Recoverable local commands (git status, git clean -fdx, rm -rf node_modules) stay allowed; avoid over-blocking. Keep routine login and credential-management commands outside catastrophic-command rules.

Password-manager and secret-store access should be governed by a separate, locally chosen policy; do not publish private denylist entries or storage locations here.

Per-agent wiring (user-global)

AgentConfigEventBlocks via
Claude Code~/.claude/settings.jsonPreToolUse matcher Bashshared script, exit 2
Codex CLI/app/IDE~/.codex/hooks.jsonPreToolUse matcher Bashshared script, exit 2
Cursor IDE + CLI~/.cursor/hooks.jsonbeforeShellExecutionshared script with cursor arg, deny JSON
Grok (xAI)auto-loads Claude + Cursor hook files (compat on by default); native option ~/.grok/hooks/*.jsonPreToolUseshared script (reads .toolInput.command)
OpenCode~/.config/opencode/plugins/command-guard.tstool.execute.beforeadapter throws Error
Pi~/.pi/agent/extensions/command-guard.tspi.on("tool_call")adapter returns {block:true}
Hermes~/.hermes/plugins/command-guard/ (plugin.yaml + __init__.py)pre_tool_call hookplugin returns {"action":"block"}
Droid (Factory)~/.factory/settings.jsonnative commandBlocklisthard-block, no approval possible
Devin CLI~/.config/devin/config.jsonPreToolUse matcher ^exec$shared script, exit 2

Claude/Codex hook entry; for Devin, replace Bash with ^exec$. Merge into the existing hooks object; never overwrite it:

json
{"hooks": {"PreToolUse": [{"matcher": "Bash", "hooks": [{"type": "command", "command": "/ABSOLUTE/PATH/TO/deny-dangerous.sh"}]}]}}

Cursor entry (payload has .command, so pass the cursor arg):

json
{"beforeShellExecution": [{"command": "/ABSOLUTE/PATH/TO/deny-dangerous.sh cursor", "failClosed": false}]}

Use absolute paths in configs (~ expansion is inconsistent across agents).

Show full SKILL.md (301 more words)Show less

Gotchas

  • Codex trust is hash-pinned. Any edit to the hook ENTRY in hooks.json (not the patterns file) invalidates trust; run /hooks in Codex and re-trust, else Codex silently skips the guard. Trust hashes live in [hooks.state] in ~/.codex/config.toml and are shared by CLI, desktop app, and IDE extension. For CI or scripts, follow the tool's documented trust configuration.
  • Cursor failClosed behavior depends on the runtime. Check the agent's documentation and choose a setting appropriate to its support for hook scripts.
  • Hermes plugin manifest key is provides_hooks (not hooks). Plugin must be enabled in its configuration. The CLI enable command may prompt interactively and hang non-interactive shells. Hermes hooks are fail-open on exceptions — keep the plugin trivial. Shell tool name is terminal.
  • Pi tool_call handler errors block the tool (fail-safe) — adapter must catch its own errors and fail open, or a broken patterns file bricks every bash call.
  • Droid semantics: commandDenylist = ask for confirmation; commandBlocklist = never runs, even at full autonomy. Use blocklist for catastrophic entries.
  • Guard script payload detection: command lives at .tool_input.command (Claude/Codex/Devin), .toolInput.command (Grok), .command (Cursor). Keep all three in the jq fallback chain.
  • Adapter regexes require multiline mode. Keep JavaScript's m flag and Python's re.M so ^ matches each shell line like grep.
  • False-positive class: a harmless command whose ARGUMENT text contains a dangerous-looking string (e.g. passing a prompt mentioning git push --force on a CLI) gets blocked. Workaround: put the text in a file and reference it.
  • Some agents or remote/background modes may not support local hooks. Verify hook coverage for each runtime you use.

E2E verification

Safe probe: ask the agent to run git push --force from a NON-git directory — blocked = guard works; "not a git repository" = guard failed but no harm done. Run probes using the agent's documented command interface and permission settings.

Direct script test:

bash
echo '{"tool_input":{"command":"rm -rf /"}}' | <GUARD_DIR>/deny-dangerous.sh; echo "exit=$?"   # expect exit=2

© davidondrej, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/ops-and-setup/global-agent-guardrails of davidondrej/skills.

Open the folder on GitHubat commit 387c2b8

Compare with similar skills

Global Agent Guardrails next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Global Agent Guardrails compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Global Agent Guardrails this skilldavidondrej/skills4.1k—~1.6kAutomated safety check: PassMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub827—~1.4kAutomated safety check: PassCustom licence
ObliteratusRedWoodOG/Hermes-Desktop1775 repos~3.8kAutomated safety check: PassMIT
Lemonade Router Builderamd/skills408—~4kAutomated safety check: PassMIT
Writing Eval Scenariosopen-bias/open-bias143—~1.5kAutomated safety check: PassApache-2.0
Wp Project Triagegambitph/Stackable3513 repos~371Automated safety check: PassGPL-3.0

Similar skills

  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    827 GitHub stars~1.4k tokensUpdated today
    AI & LLM EngineeringAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    408 GitHub stars~4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Writing Eval Scenarios

    open-bias/open-bias

    Guide for writing eval conversation JSONs and running them through policy engines

    143 GitHub stars~1.5k tokensUpdated 4 days ago
    AI & LLM EngineeringAuto-check passed
  • Wp Project Triage

    gambitph/Stackable

    A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…

    351 GitHub starsUsed in 3 repos~371 tokens
    AI & LLM EngineeringAuto-check passed
  • Wa Guardrails

    aws-samples/sample-well-architected-skills-and-steering

    Official

    Generate preventive Well-Architected guardrails — AWS Config rules, Service Control Policies, permission boundaries, CloudWatch alarms, and IaC policy checks (CDK Aspects, cfn-guard, OPA/Sentinel) —…

    275 GitHub stars~2.8k tokensUpdated 5 days ago
    AI & LLM EngineeringAuto-check passed

More from davidondrej/skills

All 51 skills in this repo
  • Nagent

    davidondrej/skills

    Launch a new bb worker thread with the right project, model, worktree, and task brief.

    4.1k GitHub stars~1.7k tokensUpdated today
    Auto-check: notes
  • Browser Harness

    davidondrej/skills

    Direct browser control via CDP. An agent skill from davidondrej/skills.

    4.1k GitHub starsUsed in 2 repos~3k tokens
    Auto-check passed
  • Persistent Localhost

    davidondrej/skills

    Manage persistent dev servers, APIs, and other local processes on a port using macOS LaunchAgents.

    4.1k GitHub stars~618 tokensUpdated today
    Auto-check passed
  • Reset Cursor Acp

    davidondrej/skills

    Reset a stuck Cursor ACP thread in <chat-system and reload its configuration.

    4.1k GitHub stars~728 tokensUpdated today
    Auto-check passed
  • Anti Sleep

    davidondrej/skills

    Keep a Mac awake for a set duration or while a process runs.

    4.1k GitHub stars~640 tokensUpdated today
    Auto-check: warnings
  • Bb CLI

    davidondrej/skills

    Use this when controlling bb. An agent skill from davidondrej/skills.

    4.1k GitHub stars~823 tokensUpdated today
    Auto-check passed

Questions about Global Agent Guardrails

What does Global Agent Guardrails do?

Configure the shared guard against catastrophic shell commands in local AI agents. Global Agent Guardrails is an agent skill from davidondrej/skills. Configure the shared guard against catastrophic shell commands in local AI agents.

When should I use Global Agent Guardrails?

Global Agent Guardrails fits situations like: changing block patterns; adding an agent; investigating why a command was.

How do I install Global Agent Guardrails in Claude Code?

Run `npx skills add davidondrej/skills --skill global-agent-guardrails -a claude-code`. Or copy the skill folder (skills/ops-and-setup/global-agent-guardrails in davidondrej/skills) into .claude/skills/global-agent-guardrails in your project. Claude Code loads it when a task matches its description.

How do I install Global Agent Guardrails in Codex?

Run `npx skills add davidondrej/skills --skill global-agent-guardrails -a codex`. Or copy the skill folder (skills/ops-and-setup/global-agent-guardrails in davidondrej/skills) into .agents/skills/global-agent-guardrails in your project. Codex loads it when a task matches its description.

Can I use Global Agent Guardrails in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add davidondrej/skills --skill global-agent-guardrails -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/global-agent-guardrails, .gemini/skills/global-agent-guardrails, .github/skills/global-agent-guardrails and .opencode/skills/global-agent-guardrails in your project.

What does Global Agent Guardrails need to run?

Going by SKILL.md and its folder, Global Agent Guardrails needs the command-line tools its instructions call (git, python3 and python). Our summary lists: Python 3.

Does Global Agent Guardrails access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Global Agent Guardrails safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Global Agent Guardrails use?

Global Agent Guardrails is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Global Agent Guardrails use?

About 1.6k tokens (SKILL.md is roughly 6.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Global Agent Guardrails?

Skills that share tags, products or a category with Global Agent Guardrails: Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars), Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars), Lemonade Router Builder (amd/skills, 408 stars) and Writing Eval Scenarios (open-bias/open-bias, 143 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Global Agent Guardrails?

davidondrej (a GitHub user) maintains it in davidondrej/skills, which has 4,112 GitHub stars. The repository holds 51 skills in this directory. The repository was last updated on October 10, 2026.

Source: davidondrej/skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.