Agent skill

Git Guardrails Claude Code

by devcxl in devcxl/mattpocock-skills-zh

设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。

MITAuto-check passedAI & LLM Engineering

Install Git Guardrails Claude Code

skills CLI
$ npx skills add devcxl/mattpocock-skills-zh --skill git-guardrails-claude-code -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install devcxl/mattpocock-skills-zh git-guardrails-claude-code --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/devcxl/mattpocock-skills-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/misc/git-guardrails-claude-code .claude/skills/git-guardrails-claude-code && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
git-guardrails-claude-code
GitHub stars
433
Token cost
~420 tokens
SKILL.md length
67 words
Files
3 (incl. scripts)
Skills in repo
20
Repo updated
First seen
Licence
MIT

At a glance

设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。

  • Works in 5 steps: 询问安装范围 → 复制钩子脚本 → 将钩子添加到设置文件 → …
  • Tasks that involve Git workflow
  • SKILL.md covers 会被阻止的命令 and 步骤
  • Runs Shell scripts from its folder; calls git

What it does

Git Guardrails Claude Code is an agent skill from devcxl/mattpocock-skills-zh. 设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。

Its SKILL.md is about 420 tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including scripts (for example `agents/openai.yaml` and `scripts/block-dangerous-git.sh`).

It sits in AI & LLM Engineering, covering Git workflow and LLM guardrails. It works with Git. The repository describes itself as: Matt Pocock 技能集的中文翻译版 — 地道中文,原汁原味的技术术语。基于 mattpocock/skills 复刻。每日中午12点钟同步. The licence is MIT.

When your agent uses it

  • Tasks that involve Git workflow
  • Tasks that involve LLM guardrails

Example prompts

  • “/git-guardrails-claude-code”

Requirements

  • A Bash shell

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. 询问安装范围
  2. 复制钩子脚本
  3. 将钩子添加到设置文件
  4. 询问自定义
  5. 验证

What it can do on your machine

Read from SKILL.md and the folder at commit b72cc5b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Git Guardrails Claude Code loads about 420 tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 67 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~420

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from devcxl/mattpocock-skills-zh at commit b72cc5b, republished under its MIT licence (© devcxl). 67 words, ~420 tokens.

Download SKILL.mdSave it as .claude/skills/git-guardrails-claude-code/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
git-guardrails-claude-code
description
设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。

设置 Git 护栏

设置一个 PreToolUse 钩子,在 Claude 执行危险 Git 命令之前拦截并阻止它们。

会被阻止的命令

  • git push(包括 --force 在内的所有变体)
  • git reset --hard
  • git clean -f / git clean -fd
  • git branch -D
  • git checkout . / git restore .

当命令被阻止时,Claude 会看到一条消息,告知它没有权限访问这些命令。

步骤

1. 询问安装范围

询问用户:是仅针对当前项目安装(.claude/settings.json),还是所有项目安装(~/.claude/settings.json)?

2. 复制钩子脚本

打包的脚本位于:scripts/block-dangerous-git.sh

根据安装范围将其复制到目标位置:

  • 项目级:.claude/hooks/block-dangerous-git.sh
  • 全局:~/.claude/hooks/block-dangerous-git.sh

使用 chmod +x 使其可执行。

3. 将钩子添加到设置文件

添加到相应的设置文件中:

项目级(.claude/settings.json):

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

全局(~/.claude/settings.json):

json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

如果设置文件已存在,将钩子合并到现有的 hooks.PreToolUse 数组中:不要覆盖其他设置。

4. 询问自定义

询问用户是否需要从阻止列表中添加或移除任何模式。根据需求编辑已复制的脚本。

5. 验证

运行一个快速测试:

bash
echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>

应退出并返回代码 2,并向 stderr 打印一条 BLOCKED 消息。

© devcxl, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in skills/misc/git-guardrails-claude-code of devcxl/mattpocock-skills-zh.

  • SKILL.md
  • agents/openai.yaml
  • scripts/block-dangerous-git.sh

Open the folder on GitHubat commit b72cc5b

Compare with similar skills

Git Guardrails Claude Code next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Git Guardrails Claude Code compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Git Guardrails Claude Code this skilldevcxl/mattpocock-skills-zh433—~420Automated safety check: PassMIT
Git Guardrails Claude Codefossasia/eventyay-interpretation1.6k12 repos~578Automated safety check: PassApache-2.0
Git Guardrails Claude Codevinvcn/mattpocock-skills-zh-CN4.6k—~474Automated safety check: PassMIT
GuardHouseofmvps/ultraship123—~790Automated safety check: NotesMIT
Swe CLI SkillsSylphAI-Inc/skills111—~1.7kAutomated safety check: PassMIT
Code Engineeringkangarooking/system-prompt-skills205—~769Automated safety check: PassMIT

Similar skills

  • Git Guardrails Claude Code

    fossasia/eventyay-interpretation

    Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.

    1.6k GitHub starsUsed in 12 repos~578 tokens
    AI & LLM EngineeringAuto-check passed
  • Git Guardrails Claude Code

    vinvcn/mattpocock-skills-zh-CN

    设置 Claude Code hooks,在危险 git commands(push、reset --hard、clean、branch -D 等)执行前阻止它们。适用于用户想防止破坏性 git 操作、添加 git safety hooks,或在 Claude Code 中阻止 git push/reset 时。

    4.6k GitHub stars~474 tokensUpdated 9 days ago
    AI & LLM EngineeringAuto-check passed
  • Guard

    Houseofmvps/ultraship

    Safety guardrails — blocks destructive commands (rm -rf, DROP TABLE, force-push, git reset --hard) and optionally restricts file edits to a specific directory.

    123 GitHub stars~790 tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Swe CLI Skills

    SylphAI-Inc/skills

    Senior engineer CLI expertise for AI agents — workflows, safety guardrails, gotchas, and anti-patterns across cloud, IaC, containers, databases, dev tools, and platforms

    111 GitHub stars~1.7k tokensUpdated 14 days ago
    DevOps & CloudAuto-check passed
  • Code Engineering

    kangarooking/system-prompt-skills

    当系统提示面向编程代理(Coding Agent)场景时调用。适用于构建代码编辑、文件操作、Git 工作流、自动化编程助手的系统提示。不适用于代码解释或教学场景(无文件修改),不适用于 DevOps 基础设施配置(非代码层),不适用于纯对话式代码问答(无工具调用)。

    205 GitHub stars~769 tokensUpdated 5 mo ago
    AI & LLM EngineeringAuto-check passed
  • Careful

    mr-daedalium/ostack-saas

    Safety guardrails for destructive commands. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~545 tokens
    AI & LLM EngineeringAuto-check: notes

More from devcxl/mattpocock-skills-zh

All 20 skills in this repo
  • Triage

    devcxl/mattpocock-skills-zh

    将 issue 和外部 PR 推过一组分诊角色的状态机——分类、验证、必要时盘问,并写出 agent 就绪的任务简报. An agent skill from devcxl/mattpocock-skills-zh.

    433 GitHub starsUsed in 1 repo~816 tokens
    Auto-check passed
  • Codebase Design

    devcxl/mattpocock-skills-zh

    设计深度模块的共享词汇。当用户想要设计或改进模块的接口、寻找深化机会、决定 seam 的位置、让代码更可测试或更易被 AI 导航,或者其他 skill 需要深度模块词汇时使用。

    433 GitHub stars~809 tokensUpdated 2 days ago
    Auto-check passed
  • Diagnosing Bugs

    devcxl/mattpocock-skills-zh

    针对棘手 bug 和性能回归的诊断循环。当用户说"诊断"/"调试这个",或报告某处崩溃/报错/不正常/缓慢时使用. An agent skill from devcxl/mattpocock-skills-zh.

    433 GitHub stars~958 tokensUpdated 2 days ago
    Auto-check passed
  • Domain Modeling

    devcxl/mattpocock-skills-zh

    构建和完善项目的领域模型。当讨论代码库术语、编写或编辑 GLOSSARY.md,或记录或编辑 ADR 时使用. An agent skill from devcxl/mattpocock-skills-zh.

    433 GitHub stars~412 tokensUpdated 2 days ago
    Auto-check passed
  • Migrate To Shoehorn

    devcxl/mattpocock-skills-zh

    将测试文件从 as 类型断言迁移到 @total-typescript/shoehorn。当用户提到 shoehorn、想要在测试中替换 as、或需要部分测试数据时使用。

    433 GitHub stars~522 tokensUpdated 2 days ago
    Auto-check passed
  • Scaffold Exercises

    devcxl/mattpocock-skills-zh

    创建包含 section、problem、solution 和 explainer 的练习目录结构,且能通过 lint 检查。当用户想要搭建练习框架、创建练习模板或设置新的课程章节时使用。

    433 GitHub stars~659 tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Git Guardrails Claude Code

What does Git Guardrails Claude Code do?

设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。. Git Guardrails Claude Code is an agent skill from devcxl/mattpocock-skills-zh.

When should I use Git Guardrails Claude Code?

Git Guardrails Claude Code fits situations like: tasks that involve Git workflow; tasks that involve LLM guardrails.

How do I install Git Guardrails Claude Code in Claude Code?

Run `npx skills add devcxl/mattpocock-skills-zh --skill git-guardrails-claude-code -a claude-code`. Or copy the skill folder (skills/misc/git-guardrails-claude-code in devcxl/mattpocock-skills-zh) into .claude/skills/git-guardrails-claude-code in your project. Claude Code loads it when a task matches its description.

How do I install Git Guardrails Claude Code in Codex?

Run `npx skills add devcxl/mattpocock-skills-zh --skill git-guardrails-claude-code -a codex`. Or copy the skill folder (skills/misc/git-guardrails-claude-code in devcxl/mattpocock-skills-zh) into .agents/skills/git-guardrails-claude-code in your project. Codex loads it when a task matches its description.

Can I use Git Guardrails Claude Code in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add devcxl/mattpocock-skills-zh --skill git-guardrails-claude-code -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/git-guardrails-claude-code, .gemini/skills/git-guardrails-claude-code, .github/skills/git-guardrails-claude-code and .opencode/skills/git-guardrails-claude-code in your project.

What does Git Guardrails Claude Code need to run?

Going by SKILL.md and its folder, Git Guardrails Claude Code needs a shell for the scripts in its folder and the command-line tools its instructions call (git). Our summary lists: A Bash shell.

Does Git Guardrails Claude Code access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Git Guardrails Claude Code safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Git Guardrails Claude Code use?

Git Guardrails Claude Code is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Git Guardrails Claude Code use?

About 420 tokens (SKILL.md is roughly 1.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Git Guardrails Claude Code?

Skills that share tags, products or a category with Git Guardrails Claude Code: Git Guardrails Claude Code (fossasia/eventyay-interpretation, 1.6k stars), Git Guardrails Claude Code (vinvcn/mattpocock-skills-zh-CN, 4.6k stars), Guard (Houseofmvps/ultraship, 123 stars) and Swe CLI Skills (SylphAI-Inc/skills, 111 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Git Guardrails Claude Code?

devcxl (a GitHub user) maintains it in devcxl/mattpocock-skills-zh, which has 433 GitHub stars. The repository holds 20 skills in this directory. The repository was last updated on October 5, 2026.

Source: devcxl/mattpocock-skills-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.