Agent skill

Guard

by garagon in garagon/nanostack

A skill your agent uses when working near production, sensitive systems, or destructive operations.

Apache-2.0Auto-check: notesDevOps & Cloud

Install Guard

skills CLI
$ npx skills add garagon/nanostack --skill guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garagon/nanostack guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garagon/nanostack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/guard .claude/skills/guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guard
GitHub stars
207
Token cost
~2k tokens
SKILL.md length
917 words
Files
7
Skills in repo
14
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when working near production, sensitive systems, or destructive operations.

  • Works in 3 steps: Ask which directories/files are in scope… → Store the scope in guard/config.json → For the remainder of the session, keep…
  • Working near production
  • SKILL.md covers Telemetry preamble, Modes, The Check Script and Telemetry finalize, plus 1 more section
  • Runs Shell scripts from its folder; calls git, docker and kubectl

What it does

Guard is an agent skill from garagon/nanostack. Use when working near production, sensitive systems, or destructive operations. Activates on-demand safety hooks that block dangerous commands. Supports modes — careful (warn), freeze (guided, keeps writes within scope), unfreeze (remove restrictions). Triggers on /guard, /careful, /freeze, /unfreeze.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `agents/openai.yaml`, `bin/budget-gate.sh` and `bin/check-dangerous.sh`).

It sits in DevOps & Cloud. The repository describes itself as: A workflow harness that helps AI coding agents plan, review, test, and ship safer code. The licence is Apache-2.0.

When your agent uses it

  • Working near production
  • Sensitive systems
  • Destructive operations

Example prompts

  • “/guard”

Requirements

  • Python 3
  • A Bash shell
  • Docker

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Ask which directories/files are in scope (or accept them as arguments)
  2. Store the scope in guard/config.json
  3. For the remainder of the session, keep Edit and Write operations within the

What it can do on your machine

Read from SKILL.md and the folder at commit 0372aed. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • docker
    • kubectl
    • python
    • node
    • sh
    • jq

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, docker and kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Guard loads about 2k tokens when it runs. Until then it costs about 77 tokens; SKILL.md has 917 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~77
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:54
    - Writing to production configs or `.env` files
  • NoteMentions a .env fileSKILL.md:109
    ed against known-bad patterns (e.g. `cat .env`, `find . -delete`).

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garagon/nanostack at commit 0372aed, republished under its Apache-2.0 licence (© garagon). 917 words, ~2,012 tokens.

Download SKILL.mdSave it as .claude/skills/guard/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
guard
description
Use when working near production, sensitive systems, or destructive operations. Activates on-demand safety hooks that block dangerous commands. Supports modes — careful (warn), freeze (guided, keeps writes within scope), unfreeze (remove restrictions). Triggers on /guard, /careful, /freeze, /unfreeze.
concurrency
exclusive
summary
Safety guardrails. Blocks dangerous commands near production or sensitive systems.
estimated_tokens
200

/guard — Safety Guardrails

You have activated safety guardrails. These protect against accidental destructive operations during this session.

Telemetry preamble

Defensive telemetry init. No-op if telemetry is disabled via NANOSTACK_NO_TELEMETRY=1, ~/.nanostack/.telemetry-disabled, or if the helpers are removed.

bash
_P="$HOME/.claude/skills/nanostack/bin/lib/skill-preamble.sh"
[ -f "$_P" ] && . "$_P" guard
unset _P

Modes

The user may activate a specific mode. If no mode is specified, default to careful.

Careful Mode (default)

What it does: Warns before any potentially destructive operation but does not block.

When you detect a destructive operation, pause and present:

⚠️  GUARD: Potentially destructive operation detected
Operation: {{what you're about to do}}
Impact: {{what could go wrong}}
Reversible: {{yes/no — if yes, how}}

Proceed? [y/n]

Use AskUserQuestion to get explicit confirmation before proceeding.

Destructive operations include:

  • rm -rf, rm -r on directories
  • git reset --hard, git push --force, git branch -D
  • DROP TABLE, DELETE FROM without WHERE, TRUNCATE
  • kubectl delete, docker rm, docker system prune
  • Writing to production configs or .env files
  • Modifying CI/CD pipeline files
  • Any operation the guard/bin/check-dangerous.sh script flags
Freeze Mode

What it does: Asks the agent to keep its file writes (Edit, Write) within a chosen scope for the rest of the session. This is a guided instruction the agent follows, not a hook-enforced block: unlike the secret and system-path denylist in check-write.sh, the Write/Edit hook does not currently reject an out-of-scope write. Treat freeze as agent-level discipline, not a wall.

When the user says /freeze or /guard freeze:

  1. Ask which directories/files are in scope (or accept them as arguments)
  2. Store the scope in guard/config.json
  3. For the remainder of the session, keep Edit and Write operations within the frozen scope and decline anything outside it
json
// guard/config.json
{
  "mode": "freeze",
  "allowed_paths": [
    "src/feature/**",
    "tests/feature/**"
  ],
  "frozen_at": "2025-01-01T00:00:00Z"
}

When you are about to write outside the frozen scope, decline and say so (the hook does not stop the write for you, so this is on the agent to honor):

🔒 GUARD FREEZE: declining write outside the frozen scope
File: {{path}}
Reason: not in the allowed scope
Allowed: {{list of allowed paths}}

To unfreeze: /unfreeze
Unfreeze Mode

What it does: Removes freeze restrictions.

When the user says /unfreeze or /guard unfreeze:

  1. Remove the freeze config
  2. Confirm guardrails are now in careful mode (not fully off)
🔓 GUARD: Freeze lifted. Returning to careful mode.

The Check Script

guard/bin/check-dangerous.sh runs every Bash call through a layered check pipeline. The order is deliberate: block rules run first so commands whose binary is on the allowlist (cat, find, head, tail) still get matched against known-bad patterns (e.g. cat .env, find . -delete).

Block rules (run first, no exceptions). Matched against the full command string. The current rule counts are loaded from guard/rules.json; this doc does not hand-maintain them.

Allowlist. Commands like git status, ls, jq short-circuit when no block rule matched.

Phase-aware concurrency. When a session is active and the current phase declares concurrency: read (built-in or custom), write commands are blocked with category concurrency-safety. The active phase's SKILL.md is resolved through bin/lib/phases.sh so custom phases get the same protection as built-in ones. Detection covers more than the obvious utilities: output redirection to anything except /dev/*, in-place editors (sed -i, perl -i), tee/truncate/patch/install, inline interpreter code (python -c, node -e, sh -c, whose quoted body is invisible to pattern checks), and git worktree mutations (stash, restore, checkout, merge, rebase, apply, clean). Quoted segments are stripped first so a read like awk '$3 > 5' file is never mistaken for redirection. The regression lock is ci/e2e-read-phase-writes.sh.

In-project fast-path. Operations that only touch files inside the current git repo pass through. Reviewable via version control. Runs after the concurrency check so an in-project touch ./foo cannot bypass a read-phase block.

Sprint phase gate. Blocks git commit / git push until the required-before-ship ancestors of the active phase_graph have completed. The built-in sprint defaults to review + security + qa; custom graphs gate on their own ancestor list.

Show full SKILL.md (347 more words)Show less

Budget gate. Blocks all commands when the configured budget is exceeded. A small set of safe reads (git status, git diff, ls, cat) stay runnable so you can inspect and save work behind the wall. This gate is a cost cap, not a sandbox: it does not defend against a repository whose own git config runs helper programs (diff.external, textconv, core.fsmonitor, filters, hooks), since those run on any git command regardless of the gate. Command-line vectors that turn a read into command execution (-c, --ext-diff, --output, --exec-path=) are rejected from the read exemption.

Warn rules. Final pass: matched commands are allowed but flagged in the output so the user is reminded what they're doing.

When a command is blocked, guard suggests a safer alternative instead of just failing:

BLOCKED [G-007] Force push overwrites remote history
Category: history-destruction
Command: git push --force origin main

Safer alternative: git push --force-with-lease (safer, fails if remote changed)
Configurable rules

Rules live in guard/rules.json. Each rule has an ID, regex pattern, category, description, and (for block rules) a safer alternative. The shipped categories include mass-deletion, history-destruction, database-destruction, infra-destruction, production-access, remote-code-execution, security-degradation, and safety-bypass. Run jq '[.tiers.block.rules[].id] | length' guard/rules.json (or the equivalent for warn rules) to inspect the live counts; the CI lint job derives them from this file.

Users can add custom rules by editing guard/rules.json.

Telemetry finalize

Before returning control:

bash
_F="$HOME/.claude/skills/nanostack/bin/lib/skill-finalize.sh"
[ -f "$_F" ] && . "$_F" guard success
unset _F

Pass abort or error instead of success if guard did not complete normally.

Gotchas

  • Guard is session-scoped. It activates when you invoke /guard and lasts until the session ends. It does not persist across sessions. This is intentional — always-on guardrails train people to ignore them.
  • Careful mode warns, it does not block. The user can always say "yes, proceed." The point is to force a conscious decision, not to prevent all risk.
  • Freeze mode is for focus, not security. It prevents accidental edits to unrelated files during debugging. It's not an access control mechanism.
  • Don't guard trivial operations. rm on a single test file is not dangerous. rm -rf / is. The script is calibrated for genuinely destructive patterns.
  • The script is a first line, not the only line. Use your judgment too. A command that passes the script but clearly targets production should still be flagged.

© garagon, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files in guard of garagon/nanostack.

  • SKILL.md
  • agents/openai.yaml
  • bin/budget-gate.sh
  • bin/check-dangerous.sh
  • bin/check-write.sh
  • bin/phase-gate.sh
  • rules.json

Open the folder on GitHubat commit 0372aed

Compare with similar skills

Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guard this skillgaragon/nanostack207—~2kAutomated safety check: NotesApache-2.0
Agent Lightningmicrosoft/agent-lightning19k—~1.7kAutomated safety check: PassMIT
Caveman Gateway SetupJuliusBrussee/caveman110k1 repos~2.6kAutomated safety check: WarnApache-2.0
SageMaker Production Defaultshuggingface/skills11k1 repos~6.9kAutomated safety check: PassApache-2.0
Megatron-LM Base Image BumpNVIDIA/Megatron-LM18k—~2.8kAutomated safety check: PassApache-2.0
Opik Local Dev Environmentcomet-ml/opik22k—~734Automated safety check: PassApache-2.0

Similar skills

  • Agent Lightning

    microsoft/agent-lightning

    Official

    Provides the action space, tradeoffs, and evaluation context for improving an editable AI agent against a benchmark while preserving its deployment contract.

    19k GitHub stars~1.7k tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed
  • Caveman Gateway Setup

    JuliusBrussee/caveman

    Routes every LLM call in a repository through the Caveman Cloud gateway in record mode, so requests and costs are measured without changing behavior.

    110k GitHub starsUsed in 1 repo~2.6k tokens
    DevOps & CloudAuto-check: warnings
  • Official

    Deploys SageMaker endpoints with autoscaling, CloudWatch alarms and tags on by default, using scripts for real-time, scale-to-zero and async setups.

    11k GitHub starsUsed in 1 repo~6.9k tokens
    DevOps & CloudAuto-check passed
  • Megatron-LM Base Image Bump

    NVIDIA/Megatron-LM

    Official

    Moves Megatron-LM CI to a newer NVIDIA PyTorch base image, updating both the GitHub and GitLab pins together and handling the CI follow-up.

    18k GitHub stars~2.8k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Starts, rebuilds, and troubleshoots the Opik local dev stack, including an optional Comet Platform integration mode for the Opik team.

    22k GitHub stars~734 tokensUpdated today
    DevOps & CloudAuto-check passed
  • Agent Kill Switch

    vivekchand/clawmetry

    Give the human an off switch and a cost meter for the coding agents on this machine, using ClawMetry.

    425 GitHub stars~1.1k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from garagon/nanostack

All 14 skills in this repo
  • Nano

    garagon/nanostack

    A skill your agent uses when starting non-trivial work (touching 3+ files, new features, refactors, bug investigations).

    207 GitHub stars~3.3k tokensUpdated 28 days ago
    Auto-check passed
  • Nano Run

    garagon/nanostack

    First-time setup and guided sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~3k tokensUpdated 28 days ago
    Auto-check passed
  • Security

    garagon/nanostack

    Use before shipping to production. An agent skill from garagon/nanostack.

    207 GitHub stars~3.7k tokensUpdated 28 days ago
    Auto-check: notes
  • Ship

    garagon/nanostack

    A skill your agent uses when code is ready to ship — creates PRs, merges, deploys, and verifies.

    207 GitHub stars~4.2k tokensUpdated 28 days ago
    Auto-check passed
  • Compound

    garagon/nanostack

    Document what you learned during this sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.2k tokensUpdated 28 days ago
    Auto-check passed
  • Conductor

    garagon/nanostack

    Orchestrate parallel agent sessions through a sprint. An agent skill from garagon/nanostack.

    207 GitHub stars~2.6k tokensUpdated 28 days ago
    Auto-check passed

Questions about Guard

What does Guard do?

A skill your agent uses when working near production, sensitive systems, or destructive operations. Guard is an agent skill from garagon/nanostack. Use when working near production, sensitive systems, or destructive operations.

When should I use Guard?

Guard fits situations like: working near production; sensitive systems; destructive operations.

How do I install Guard in Claude Code?

Run `npx skills add garagon/nanostack --skill guard -a claude-code`. Or copy the skill folder (guard in garagon/nanostack) into .claude/skills/guard in your project. Claude Code loads it when a task matches its description.

How do I install Guard in Codex?

Run `npx skills add garagon/nanostack --skill guard -a codex`. Or copy the skill folder (guard in garagon/nanostack) into .agents/skills/guard in your project. Codex loads it when a task matches its description.

Can I use Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garagon/nanostack --skill guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guard, .gemini/skills/guard, .github/skills/guard and .opencode/skills/guard in your project.

What does Guard need to run?

Going by SKILL.md and its folder, Guard needs a shell for the scripts in its folder and the command-line tools its instructions call (git, docker, kubectl, python, node and sh). Our summary lists: Python 3; A Bash shell; Docker.

Does Guard access the network?

SKILL.md contains no URLs. Its commands use git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Guard safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Guard use?

Guard is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guard use?

About 2k tokens (SKILL.md is roughly 8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Guard?

Skills that share tags, products or a category with Guard: Agent Lightning (microsoft/agent-lightning, 19k stars), Caveman Gateway Setup (JuliusBrussee/caveman, 110k stars), SageMaker Production Defaults (huggingface/skills, 11k stars) and Megatron-LM Base Image Bump (NVIDIA/Megatron-LM, 18k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guard?

garagon (a GitHub user) maintains it in garagon/nanostack, which has 207 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on September 10, 2026.

Source: garagon/nanostack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.