Agent skill

Freeze Edit Boundary

by garrytan in garrytan/gstack

Locks file edits for the session to one directory by blocking Edit and Write calls anywhere else, useful when debugging or scoping a change.

MITAuto-check: notesAgent Workflows

Install Freeze Edit Boundary

skills CLI
$ npx skills add garrytan/gstack --skill freeze -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garrytan/gstack freeze --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/freeze .claude/skills/freeze && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
freeze
GitHub stars
136k
Token cost
~1.1k tokens
SKILL.md length
436 words
Files
4
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Locks file edits for the session to one directory by blocking Edit and Write calls anywhere else, useful when debugging or scoping a change.

  • Keeping an agent inside one module while debugging a bug
  • SKILL.md covers When to invoke this skill, Setup, How it works and Notes
  • Runs Shell scripts from its folder; calls git and bash
  • Scoping a refactor so nothing outside a chosen folder is edited

What it does

Run /freeze and the agent asks, with a typed path rather than a menu, which directory edits should be limited to. From then on any Edit or Write call that targets a file outside that directory is blocked, not merely warned about. It is meant for debugging, so the agent does not wander off and fix unrelated code, or for confining a change to one module.

The boundary is stored through freeze-state.sh, and success is reported only if that helper succeeds. A hook reads file_path from the tool input, checks whether it starts with the frozen directory and returns a deny decision otherwise. It fails closed: a payload it cannot parse is denied, while one without a file path, from a non-file tool, is allowed. Symlinks are resolved.

Run /freeze again to move the boundary and /unfreeze to remove it. The parsing code is shared with the /careful skill, and the skill depends on the gstack setup being installed, since its state and helper scripts live there.

When your agent uses it

  • Keeping an agent inside one module while debugging a bug
  • Scoping a refactor so nothing outside a chosen folder is edited
  • Setting a hard edit boundary before handing a task to an agent

Example prompts

  • “Freeze edits to src/billing for this session.”
  • “Only edit the packages/parser folder from now on.”
  • “Lock down edits to the auth module while we chase this bug.”
  • “Unfreeze so I can edit the whole repo again.”

Requirements

  • The gstack skill set installed, which provides the freeze helper scripts
  • Bash
  • Pre-approved tools (allowed-tools): Bash, Read, AskUserQuestion

What it can do on your machine

Read from SKILL.md and the folder at commit 20eb620. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Freeze Edit Boundary loads about 1.1k tokens when it runs. Until then it costs about 19 tokens; SKILL.md has 436 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~19
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garrytan/gstack at commit 20eb620, republished under its MIT licence (© garrytan). 436 words, ~1,138 tokens.

Download SKILL.mdSave it as .claude/skills/freeze/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
freeze
description
Restrict file edits to a specific directory for the session. (gstack)
allowed-tools
Bash, Read, AskUserQuestion
version
0.1.0
triggers
freeze edits to directory, lock editing scope, restrict file changes
<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly -->
<!-- Regenerate: bun run gen:skill-docs -->

When to invoke this skill

Blocks Edit, Write and NotebookEdit outside the allowed path. Use when debugging to prevent accidentally "fixing" unrelated code, or when you want to scope changes to one module. Use when asked to "freeze", "restrict edits", "only edit this folder", or "lock down edits".

/freeze — Restrict Edits to a Directory

Lock file edits to a specific directory. Any Edit, Write or NotebookEdit operation targeting a file outside the allowed path will be blocked (not just warned).

bash
GSTACK_STATE_ROOT=$(~/.claude/skills/gstack/bin/gstack-paths --get GSTACK_STATE_ROOT); : "${GSTACK_STATE_ROOT:?gstack-paths failed; reinstall with ./setup or /gstack-upgrade}"
mkdir -p "$GSTACK_STATE_ROOT"/analytics
echo '{"skill":"freeze","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}'  >> "$GSTACK_STATE_ROOT"/analytics/skill-usage.jsonl 2>/dev/null || true

Setup

Ask the user which directory to restrict edits to. Use AskUserQuestion:

  • Question: "Which directory should I restrict edits to? Files outside this path will be blocked from editing."
  • Text input (not multiple choice) — the user types a path.

Once the user provides a directory path:

Set the user-selected boundary with the shared state writer. It resolves the physical absolute path and serializes replacement with investigation cleanup:

bash
bash "$HOME/.claude/skills/gstack/freeze/bin/freeze-state.sh" set "<user-provided-path>"

Only report success if the helper succeeds. On FREEZE_BUSY or unexpected state, preserve it and ask the user to inspect recovery after any active writer finishes; never write or delete the state file directly.

Tell the user: "Edits are now restricted to <path>/. Any Edit, Write or NotebookEdit outside this directory will be blocked. To change the boundary, run /freeze again. To remove it, run /unfreeze."

Show full SKILL.md (223 more words)Show less

How it works

The hook reads file_path from the Edit/Write tool input JSON, or notebook_path from a NotebookEdit (Jupyter notebook) call (shared real-JSON extractor with /careful — one copy, sourced by both hooks), then checks whether the path starts with the freeze directory. If not, it returns a hookSpecificOutput payload with permissionDecision: "deny" to block the operation (nested under hookSpecificOutput — Claude Code ignores a top-level permissionDecision).

Polarity is fail-closed: a tool payload the hook cannot parse is DENIED, not allowed — a boundary that fails open is not a boundary. A payload that parses but has neither path field (a non-file tool) is allowed. A deny names the tool, the path field, the boundary and /unfreeze. Symlinks are resolved through their FINAL component, so an in-boundary symlink pointing outside the boundary is checked against its target.

The freeze boundary persists until explicitly removed via the state file. The hook script reads it on every Edit/Write/NotebookEdit invocation. Boundaries containing spaces are supported.

Notes

  • The trailing / on the freeze directory prevents /src from matching /src-old
  • Freeze applies to Edit, Write and NotebookEdit only — Read, Bash, PowerShell, Glob, Grep are unaffected
  • This prevents accidental edits, not a security boundary — Bash or PowerShell commands like sed or Set-Content can still modify files outside the boundary
  • To deactivate, run /unfreeze; ending or killing a conversation does not remove persisted state

© garrytan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files in freeze of garrytan/gstack.

  • SKILL.md
  • SKILL.md.tmpl
  • bin/check-freeze.sh
  • bin/freeze-state.sh

Open the folder on GitHubat commit 20eb620

Compare with similar skills

Freeze Edit Boundary next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Freeze Edit Boundary compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Freeze Edit Boundary this skillgarrytan/gstack136k—~1.1kAutomated safety check: NotesMIT
Token-Saver Configurationppgranger/token-saver153—~1kAutomated safety check: PassApache-2.0
Verify Setup Health Checkdiet103/claude-code-infrastructure-showcase10k—~363Automated safety check: PassMIT
LazyCodex Doctorcode-yeongyu/oh-my-openagent70k—~2.6kAutomated safety check: PassCustom licence
Braintrust Tracingparcadei/Continuous-Claude-v33.9k1 repos~3.2kAutomated safety check: PassMIT
Debug Hooksparcadei/Continuous-Claude-v33.9k1 repos~863Automated safety check: NotesMIT

Similar skills

  • Token-Saver Configuration

    ppgranger/token-saver

    Checks and tunes token-saver output compression: reads stats, explains why a command was or was not compressed, and edits config files or environment variables.

    153 GitHub stars~1k tokensUpdated 20 days ago
    Agent WorkflowsAuto-check passed
  • Verify Setup Health Check

    diet103/claude-code-infrastructure-showcase

    Run the infrastructure health check and fix anything that fails

    10k GitHub stars~363 tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • LazyCodex Doctor

    code-yeongyu/oh-my-openagent

    Audits a local LazyCodex and Codex CLI install against the latest upstream sources and reports PASS, WARN or FAIL per check without changing anything.

    70k GitHub stars~2.6k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Braintrust Tracing

    parcadei/Continuous-Claude-v3

    Braintrust tracing for Claude Code - hook architecture, sub-agent correlation, debugging

    3.9k GitHub starsUsed in 1 repo~3.2k tokens
    Agent WorkflowsAuto-check passed
  • Debug Hooks

    parcadei/Continuous-Claude-v3

    Systematic hook debugging workflow. An agent skill from parcadei/Continuous-Claude-v3.

    3.9k GitHub starsUsed in 1 repo~863 tokens
    DevelopmentAuto-check: notes
  • cmux Diagnostics

    manaflow-ai/cmux

    Runs a read-only health check for cmux and explains what it finds, covering the CLI and socket, settings, agent hooks, session restore and notifications.

    28k GitHub starsUsed in 1 repo~819 tokens
    Productivity & AutomationAuto-check passed

More from garrytan/gstack

All 56 skills in this repo
  • Gstack Skill Router

    garrytan/gstack

    Router for the gstack skill suite. (gstack)

    136k GitHub stars~4k tokensUpdated yesterday
    Auto-check: notes
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated yesterday
    Auto-check passed
  • Builds a weekly engineering retrospective from git history: commit counts, per-person contributions, work patterns and code quality numbers over a chosen window.

    136k GitHub stars~2.4k tokensUpdated yesterday
    Auto-check passed
  • Aside Browser Driver

    garrytan/gstack

    Drives a real browser through Aside so the agent can open a page, read it, click through a flow, take screenshots and check console errors.

    136k GitHub stars~8.5k tokensUpdated yesterday
    Auto-check: notes
  • Live-Device iOS QA

    garrytan/gstack

    Tests a SwiftUI app on a real iPhone connected by USB, reading the Swift source and then looping through screenshot, analysis and action to find bugs.

    136k GitHub stars~11k tokensUpdated yesterday
    Auto-check: notes
  • Cross-Model Benchmark

    garrytan/gstack

    Sends one prompt to Claude, GPT through the Codex CLI and Gemini, then tabulates response time, token use and cost, with an optional judged quality score.

    136k GitHub stars~4k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Freeze Edit Boundary

What does Freeze Edit Boundary do?

Locks file edits for the session to one directory by blocking Edit and Write calls anywhere else, useful when debugging or scoping a change. Run /freeze and the agent asks, with a typed path rather than a menu, which directory edits should be limited to. From then on any Edit or Write call that targets a file outside that directory is blocked, not merely warned about.

When should I use Freeze Edit Boundary?

Freeze Edit Boundary fits situations like: keeping an agent inside one module while debugging a bug; scoping a refactor so nothing outside a chosen folder is edited; setting a hard edit boundary before handing a task to an agent.

How do I install Freeze Edit Boundary in Claude Code?

Run `npx skills add garrytan/gstack --skill freeze -a claude-code`. Or copy the skill folder (freeze in garrytan/gstack) into .claude/skills/freeze in your project. Claude Code loads it when a task matches its description.

How do I install Freeze Edit Boundary in Codex?

Run `npx skills add garrytan/gstack --skill freeze -a codex`. Or copy the skill folder (freeze in garrytan/gstack) into .agents/skills/freeze in your project. Codex loads it when a task matches its description.

Can I use Freeze Edit Boundary in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garrytan/gstack --skill freeze -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/freeze, .gemini/skills/freeze, .github/skills/freeze and .opencode/skills/freeze in your project.

What does Freeze Edit Boundary need to run?

Going by SKILL.md and its folder, Freeze Edit Boundary needs a shell for the scripts in its folder and the command-line tools its instructions call (git and bash). Our summary lists: The gstack skill set installed, which provides the freeze helper scripts; Bash. Its frontmatter pre-approves these tools: Bash, Read, AskUserQuestion.

Does Freeze Edit Boundary access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Freeze Edit Boundary safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Freeze Edit Boundary use?

Freeze Edit Boundary is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Freeze Edit Boundary use?

About 1.1k tokens (SKILL.md is roughly 4.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Freeze Edit Boundary?

Skills that share tags, products or a category with Freeze Edit Boundary: Token-Saver Configuration (ppgranger/token-saver, 153 stars), Verify Setup Health Check (diet103/claude-code-infrastructure-showcase, 10k stars), LazyCodex Doctor (code-yeongyu/oh-my-openagent, 70k stars) and Braintrust Tracing (parcadei/Continuous-Claude-v3, 3.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Freeze Edit Boundary?

garrytan (a GitHub user) maintains it in garrytan/gstack, which has 135,670 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 9, 2026.

Source: garrytan/gstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.