Agent skill

Data Loss Gate

by garrytan in garrytan/gbrain

Confirmation gate before any bulk delete, cleanup, or destructive operation that could result in data loss — shell-level (rm -rf, git rm, bulk sed) or brain-level (bulk forget, delete sweeps…

MITAuto-check passedDatabases

Install Data Loss Gate

skills CLI
$ npx skills add garrytan/gbrain --skill data-loss-gate -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garrytan/gbrain data-loss-gate --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garrytan/gbrain.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/data-loss-gate .claude/skills/data-loss-gate && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
data-loss-gate
GitHub stars
31k
Token cost
~2.8k tokens
SKILL.md length
1,323 words
Files
2
Skills in repo
47
Repo updated
First seen
Licence
MIT

At a glance

Confirmation gate before any bulk delete, cleanup, or destructive operation that could result in data loss — shell-level (rm -rf, git rm, bulk sed) or brain-level (bulk forget, delete sweeps…

  • Works in 4 steps: STOP before executing → The Confirmation Card → Wait for explicit "yes" → …
  • Databases work in your project
  • SKILL.md covers What This Is, When This Fires, What To Do and No Exception Classes, plus 6 more sections
  • Calls git

What it does

Data Loss Gate is an agent skill from garrytan/gbrain. Confirmation gate before any bulk delete, cleanup, or destructive operation that could result in data loss — shell-level (rm -rf, git rm, bulk sed) or brain-level (bulk forget, delete sweeps, purge-deleted, source removal, raw-SQL truncation). Presents a recoverability card and requires an explicit "yes" from the user before proceeding. Routing convention, not an operation-boundary enforcement.

Its SKILL.md is about 2.8k tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Databases. It works with Git and SQL. The repository describes itself as: Garry's Opinionated OpenClaw/Hermes Agent Brain. The licence is MIT.

When your agent uses it

  • Databases work in your project

Example prompts

  • “/data-loss-gate”

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. STOP before executing
  2. The Confirmation Card
  3. Wait for explicit "yes"
  4. Execute with logging

What it can do on your machine

Read from SKILL.md and the folder at commit fc54831. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Data Loss Gate loads about 2.8k tokens when it runs. Until then it costs about 103 tokens; SKILL.md has 1,323 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~103
When it runs · the whole SKILL.md, loaded when a task matches
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garrytan/gbrain at commit fc54831, republished under its MIT licence (© garrytan). 1,323 words, ~2,816 tokens.

Download SKILL.mdSave it as .claude/skills/data-loss-gate/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
data-loss-gate
description
Confirmation gate before any bulk delete, cleanup, or destructive operation that could result in data loss — shell-level (rm -rf, git rm, bulk sed) or brain-level (bulk forget, delete sweeps, purge-deleted, source removal, raw-SQL truncation). Presents a recoverability card and requires an explicit "yes" from the user before proceeding. Routing convention, not an operation-boundary enforcement.
version
1.0.0
triggers
bulk delete, wipe the, rm -rf, purge the, truncate, free up space, bulk forget, remove the source, drop the table
mutating
true
writes_pages
true
writes_to
daily/
upstream
data-loss-gate@fc834ee
brain_first
true

Data Loss Gate — Confirmation Before Destructive Operations

Convention: see conventions/brain-first.md — inspect the actual target before proposing deletion: get_backlinks, gbrain graph <slug>, git log on the underlying files. The confirmation card below is only as good as the inspection behind it.

Convention: see _brain-filing-rules.md — the post-confirmation deletion log files date-keyed under daily/.

What This Is

A gate that fires BEFORE any destructive operation and requires explicit user confirmation. The agent stops, presents a recoverability card, and waits.

Scope honesty: this gate is a routing convention — the harness resolves it into context when a destructive intent matches, and a well-behaved agent follows it. It is NOT an operation-boundary enforcement: nothing in the gbrain runtime mechanically blocks a delete if the skill never loads. (A native confirm gate at the operation boundary is a filed TODO; until it lands, this convention is the line of defense.) Some CLI surfaces carry their own flag gates — e.g. gbrain sources remove requires --confirm-destructive — but the flag confirms that the AGENT is sure. This skill exists to confirm that the USER is.

When This Fires

Before ANY of these operations:

Shell / filesystem level:

  • rm -rf on any directory with data
  • rm / unlink on more than 10 files
  • sed -i that modifies more than 10 files
  • git rm on tracked files
  • Truncating or stripping content from files in bulk
  • Overwriting files with smaller versions (content stripping)
  • Any operation described as "cleanup" or "freeing space" that touches data files

Brain / database level (gbrain-specific):

  • Bulk forget — scripting or looping gbrain forget <fact-id> over many facts. One forget is a considered, idempotent act; a forget sweep is data loss.
  • Page-delete sweeps — gbrain delete <slug> in a loop, or any script that sweeps delete_page across a set of slugs. Deletes are soft (recoverable via gbrain restore <slug>) until purged — say so on the card, then gate anyway: a sweep that's wrong in bulk is expensive to un-wrong in bulk.
  • gbrain pages purge-deleted — permanently removes soft-deleted pages from every source of the brain. This is the point of no return for the soft-delete safety net. Show the user gbrain pages purge-deleted --dry-run --json first; the command itself asks (exit 3 without a terminal) and runs with --yes only after the user agrees.
  • Source removal — gbrain sources remove <id> deletes the source AND every page in it. The --confirm-destructive flag does not substitute for the card.
  • Mount removal — gbrain mounts remove <id> only removes the local registration (the mounted brain's database survives; re-add to recover). Gate it anyway when the flow ALSO plans to delete the mount's underlying database or files — then the full card applies to those.
  • Raw-SQL truncation — any DROP TABLE, TRUNCATE, or DELETE without a narrow WHERE against the brain database, via any path (psql, a migration script, an engine executeRaw call).
  • Deleting database rows in bulk; dropping tables, collections, or indexes.

What To Do

Step 1: STOP before executing

Do NOT run the destructive command. Inspect the actual target first (backlinks, graph edges, git history, file contents — whatever grounds the card), then present the user with:

Step 2: The Confirmation Card
⚠️ DATA DELETION — Confirmation Required

What: [exactly what will be deleted/modified]
Count: [number of files/rows/pages/facts affected]
Size: [how much data will be removed]
Location: [exact paths, slugs, or source/mount ids]

Why: [the reason for the deletion]

Recoverable?
- [ ] Backed up to a remote (git remote, database backup, object storage)
- [ ] In git history (can git checkout)
- [ ] Soft-deleted in the brain (restorable via `gbrain restore` until purged)
- [ ] Re-fetchable from an upstream source (which one, how long)
- [ ] NOT recoverable — permanent data loss

What we'd lose:
- [specific data/capability that would be gone]
- [any downstream systems that depend on this data]

Alternative to deletion:
- [compress instead of delete?]
- [move to cold storage?]
- [archive to a remote backup?]
- [soft-delete and defer the purge?]

Proceed? (yes/no)
Step 3: Wait for explicit "yes"
  • Do NOT proceed on "ok", "sure", "go ahead" — require "yes" or "do it"
  • If the user says "wait" or asks a question, answer it and re-present the card
  • If the user says "no", stop immediately and suggest alternatives

For the mechanics of presenting the gate and stopping the turn, use the ask-user choice-gate pattern — this skill supplies the card content and the explicit-yes strictness; ask-user supplies the stop-and-wait discipline.

Step 4: Execute with logging

After confirmation:

  1. Log what was deleted to daily/notes/YYYY-MM-DD.md under ## Data Deletions
  2. Include: timestamp, what, count, size, recovery path
  3. If the deletion is large (>1GB or >1000 files/pages), do it in chunks with progress updates

No Exception Classes

There are no categories of data that are disposable by default. Old logs, git stash entries, build artifacts, caches — each of these has, at some point, been the source of truth for something. Disposability is a property of the SPECIFIC target, verified by inspecting it (backlinks, git status, what depends on it, whether it's re-fetchable and at what cost) — never a property of its category. If the inspection genuinely shows the target is ephemeral and regenerable, the card is quick to fill out and the user's "yes" is quick to get. That's the cost of the gate working.

Why This Exists

A downstream agent once deleted a multi-gigabyte cache of raw source files from its brain's data directory to free disk space. The files looked like "just cache" — but they were the source data for a planned feature. The data happened to be re-fetchable from its upstream source, but the deletion was still wrong because:

  1. It destroyed work that had a planned use
  2. It happened without the data owner's consent
  3. The "cleanup" framing made it seem safe when it wasn't

The rule: if it's data and it's bulk, ASK FIRST. Always.

Show full SKILL.md (498 more words)Show less

When it fails

Follow the agent operator protocol for any gbrain error code, exit code, [AGENT] block or notice block. Specific to this skill:

  • A destructive command exits 3 (confirmation_required) or asks for --confirm-destructive: that flag confirms the agent is sure, not the user. Show the recoverability card and wait for the user's explicit yes.
  • gbrain pages purge-deleted removes soft-deleted pages for good, so gbrain restore cannot bring them back afterwards: say so on the card. Never promise physical erasure or a recovery you cannot verify.
  • A delete or forget returns write_pending (exit 10): poll the receipt before writing the deletion log entry.

Anti-Patterns

  • ❌ "These are just cache files" — cache files can be the source of truth
  • ❌ "We can re-fetch from the API" — re-fetching costs time, money, and may not produce identical data
  • ❌ "It's gitignored so it doesn't matter" — gitignored ≠ unimportant
  • ❌ "The disk is full, I need to free space NOW" — even under pressure, ask first
  • ❌ "I'll clean up and tell the user after" — the confirmation must come BEFORE the deletion
  • ❌ "It's only a soft delete" — a wrong sweep is still expensive to un-wrong in bulk, and purge makes it permanent
  • ❌ "The command already has --confirm-destructive" — the flag confirms the agent's intent, not the user's consent
  • ❌ Presenting deletion as the only option without listing alternatives

Dedup (sharp boundaries)

  • conventions/test-before-bulk.md — the write-side sibling. test-before-bulk gates bulk WRITE quality (test 3-5 items before running 170); data-loss-gate gates bulk DESTRUCTION (confirm before deleting anything in bulk). A flow that rewrites pages in place needs both: test-before-bulk for the new content, data-loss-gate for what the rewrite destroys.
  • ask-user — the confirmation MECHANICS (2-4 options, escape hatch, stop the turn, handle the response). data-loss-gate is a specialized caller: it supplies the destructive-op card and the strict explicit-yes rule ("ok" is not consent). Route to ask-user for any non-destructive decision gate.
  • maintain — brain health checks and routine cleanup (orphans, backlinks, stale detection). maintain FINDS candidates for cleanup; when acting on them crosses into bulk deletion, data-loss-gate fires before execution. "Check brain health" routes to maintain, not here.

Contract

This skill guarantees:

  • No destructive operation in scope (the "When This Fires" list) executes before the confirmation card is presented and the user answers with an explicit "yes" / "do it".
  • The card always includes the recoverability checklist, what-we'd-lose, and at least one alternative to deletion.
  • Confirmed deletions are logged to daily/notes/YYYY-MM-DD.md under ## Data Deletions with timestamp, scope, and recovery path.
  • Routing matches the canonical triggers in the frontmatter.
  • Output written under the directories listed in writes_to:.
  • Privacy contract preserved: no real names, no fork-specific filesystem path literals, no upstream-fork references.

The full behavior contract is documented in the body sections above; this section exists for the conformance test.

Output Format

Two artifacts:

  1. The confirmation card (pre-execution) — the exact fenced block in Step 2, presented via the ask-user stop-and-wait pattern. The turn ends after the card; no further tool calls until the user responds.
  2. The deletion log entry (post-execution, only after explicit "yes") — appended to daily/notes/YYYY-MM-DD.md:
markdown
## Data Deletions

- **[HH:MM]** [what was deleted] — [count], [size]. Reason: [why].
  Recovery: [backup/git/restore path, or "none — permanent"].

© garrytan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/data-loss-gate of garrytan/gbrain.

  • SKILL.md
  • routing-eval.jsonl

Open the folder on GitHubat commit fc54831

Compare with similar skills

Data Loss Gate next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Data Loss Gate compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Data Loss Gate this skillgarrytan/gbrain31k—~2.8kAutomated safety check: PassMIT
Citus Check Style Reindentcitusdata/citus13k—~1.5kAutomated safety check: NotesAGPL-3.0
BisectClickHouse/ClickHouse50k—~1.4kAutomated safety check: PassApache-2.0
Wtfnoobnooc/agent1.4k—~2.1kAutomated safety check: NotesNone
Notcrawlopenclaw/notcrawl134—~698Automated safety check: PassMIT
Drizzle Migration Conflictsickn33/agentic-awesome-skills47k1 repos~2.5kAutomated safety check: NotesApache-2.0

Similar skills

  • Fix a failing citusdata/citus check-style job by running make reindent with the exact uncrustify/citusindent versions the currently checked-out branch pins (read from its own STYLEGUIDE.md and its…

    13k GitHub stars~1.5k tokensUpdated yesterday
    DatabasesAuto-check: notes
  • Bisect

    ClickHouse/ClickHouse

    Bisect a ClickHouse regression using pre-built master binaries from CI.

    50k GitHub stars~1.4k tokensUpdated today
    DatabasesAuto-check passed
  • Wtf

    noobnooc/agent

    Pre-launch and pre-commit audit for vibe coding projects. An agent skill from noobnooc/agent.

    1.4k GitHub stars~2.1k tokensUpdated 1 mo ago
    DatabasesAuto-check: notes
  • Notcrawl

    openclaw/notcrawl

    A skill your agent uses for local Notion archive search, sync freshness, Markdown/database exports, git-share snapshots, and Notcrawl repo/release work.

    134 GitHub stars~698 tokensUpdated 2 days ago
    DatabasesAuto-check passed
  • Drizzle Migration Conflict

    sickn33/agentic-awesome-skills

    Diagnose, repair, and prevent Drizzle Kit migration conflicts involving generated SQL, snapshots, journals, merge queues, and team workflows.

    47k GitHub starsUsed in 1 repo~2.5k tokens
    DatabasesAuto-check: notes
  • Close Flaky Issues

    ClickHouse/ClickHouse

    Audit open "flaky test" GitHub issues and close those whose tests are no longer failing on master.

    50k GitHub stars~1.9k tokensUpdated today
    Testing & QAAuto-check: notes

More from garrytan/gbrain

All 47 skills in this repo
  • Traces a factual error the user points out back to its source (a brain page, a memory file, SOUL.md or USER.md, or a hallucination) and fixes that source instead of just noting the correction.

    31k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Searches and writes a company-wide knowledge brain through the gbrain CLI, so durable decisions and facts about people, projects and history stay findable beyond one session.

    31k GitHub stars~875 tokensUpdated today
    Auto-check passed
  • Idea Ingest

    garrytan/gbrain

    Ingest links, articles, tweets, and ideas into the brain. An agent skill from garrytan/gbrain.

    31k GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Sends what your notes already know about a topic to Perplexity, so the cited web search reports only what is new, such as entity updates or deal changes.

    31k GitHub stars~2k tokensUpdated today
    Auto-check: notes
  • Schema Unify

    garrytan/gbrain

    Migrate a brain from gbrain-base (or any pack) to gbrain-base-v2's 14-canonical-type taxonomy via gbrain onboard --check + the unify-types Minion handler.

    31k GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Skillpack Check

    garrytan/gbrain

    Run gbrain skillpack-check to produce an agent-readable JSON health report for the gbrain install.

    31k GitHub stars~1.4k tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Data Loss Gate

What does Data Loss Gate do?

Confirmation gate before any bulk delete, cleanup, or destructive operation that could result in data loss — shell-level (rm -rf, git rm, bulk sed) or brain-level (bulk forget, delete sweeps…. Data Loss Gate is an agent skill from garrytan/gbrain. Confirmation gate before any bulk delete, cleanup, or destructive operation that could result in data loss — shell-level (rm -rf, git rm, bulk sed) or brain-level (bulk forget, delete sweeps, purge-deleted, source removal, raw-SQL truncation).

When should I use Data Loss Gate?

Data Loss Gate fits situations like: databases work in your project.

How do I install Data Loss Gate in Claude Code?

Run `npx skills add garrytan/gbrain --skill data-loss-gate -a claude-code`. Or copy the skill folder (skills/data-loss-gate in garrytan/gbrain) into .claude/skills/data-loss-gate in your project. Claude Code loads it when a task matches its description.

How do I install Data Loss Gate in Codex?

Run `npx skills add garrytan/gbrain --skill data-loss-gate -a codex`. Or copy the skill folder (skills/data-loss-gate in garrytan/gbrain) into .agents/skills/data-loss-gate in your project. Codex loads it when a task matches its description.

Can I use Data Loss Gate in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garrytan/gbrain --skill data-loss-gate -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/data-loss-gate, .gemini/skills/data-loss-gate, .github/skills/data-loss-gate and .opencode/skills/data-loss-gate in your project.

What does Data Loss Gate need to run?

Going by SKILL.md and its folder, Data Loss Gate needs the command-line tools its instructions call (git).

Does Data Loss Gate access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Data Loss Gate safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Data Loss Gate use?

Data Loss Gate is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Data Loss Gate use?

About 2.8k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Data Loss Gate?

Skills that share tags, products or a category with Data Loss Gate: Citus Check Style Reindent (citusdata/citus, 13k stars), Bisect (ClickHouse/ClickHouse, 50k stars), Wtf (noobnooc/agent, 1.4k stars) and Notcrawl (openclaw/notcrawl, 134 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Data Loss Gate?

garrytan (a GitHub user) maintains it in garrytan/gbrain, which has 30,701 GitHub stars. The repository holds 47 skills in this directory. The repository was last updated on October 9, 2026.

Source: garrytan/gbrain on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.