Agent skill

Guard Mode

by garrytan in garrytan/gstack

Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.

MITAuto-check: notesAgent Workflows

Install Guard Mode

skills CLI
$ npx skills add garrytan/gstack --skill guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install garrytan/gstack guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/guard .claude/skills/guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guard
GitHub stars
136k
Token cost
~1k tokens
SKILL.md length
297 words
Files
2
Skills in repo
56
Repo updated
First seen
Licence
MIT

At a glance

Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.

  • Working directly on production systems where one wrong command is costly
  • SKILL.md covers When to invoke this skill, Setup and What's protected
  • Calls git and bash
  • Debugging a live system while keeping every edit inside one folder

What it does

Guard joins two sibling gstack skills, careful and freeze, into a single command. When it starts, it asks you to type the one directory that edits may touch, then records that boundary through a shared helper script. It reports the boundary as active only if the helper succeeds; on failure it keeps the existing state and tells you how to recover, rather than writing the state file directly.

Two protections then apply. Commands such as rm -rf, DROP TABLE and force-push produce a warning you can override, while catastrophic cases, like recursively deleting / or ~ or force-pushing to the default branch, are refused outright. File edits outside the chosen path are blocked. The boundary is lifted with /unfreeze; ending the session stops the hooks but leaves the saved boundary in place. Both /careful and /freeze must be installed, which the gstack setup script does.

When your agent uses it

  • Working directly on production systems where one wrong command is costly
  • Debugging a live system while keeping every edit inside one folder
  • Starting a session you want locked down with maximum safety

Example prompts

  • “Guard mode on. Limit edits to ./services/billing while I debug this outage.”
  • “Lock it down: I need to touch production config and don't want any stray deletes.”
  • “Switch on full safety before we investigate the live worker queue.”

Requirements

  • The gstack skills /careful and /freeze, installed by the gstack setup script
  • Pre-approved tools (allowed-tools): Bash, Read, AskUserQuestion

What it can do on your machine

Read from SKILL.md and the folder at commit 20eb620. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • bash

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Guard Mode loads about 1k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 297 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~22
When it runs · the whole SKILL.md, loaded when a task matches
~1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from garrytan/gstack at commit 20eb620, republished under its MIT licence (© garrytan). 297 words, ~1,032 tokens.

Download SKILL.mdSave it as .claude/skills/guard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
guard
description
Full safety mode: destructive command warnings + directory-scoped edits. (gstack)
allowed-tools
Bash, Read, AskUserQuestion
version
0.1.0
triggers
full safety mode, guard against mistakes, maximum safety
<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly -->
<!-- Regenerate: bun run gen:skill-docs -->

When to invoke this skill

Combines /careful (warns before rm -rf, DROP TABLE, force-push, etc.) with /freeze (blocks edits outside a specified directory). Use for maximum safety when touching prod or debugging live systems. Use when asked to "guard mode", "full safety", "lock it down", or "maximum safety".

/guard — Full Safety Mode

Activates both destructive command warnings and directory-scoped edit restrictions. This is the combination of /careful + /freeze in a single command.

Dependency note: This skill references hook scripts from the sibling /careful and /freeze skill directories. Both must be installed (they are installed together by the gstack setup script).

bash
GSTACK_STATE_ROOT=$(~/.claude/skills/gstack/bin/gstack-paths --get GSTACK_STATE_ROOT); : "${GSTACK_STATE_ROOT:?gstack-paths failed; reinstall with ./setup or /gstack-upgrade}"
mkdir -p "$GSTACK_STATE_ROOT"/analytics
echo '{"skill":"guard","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}'  >> "$GSTACK_STATE_ROOT"/analytics/skill-usage.jsonl 2>/dev/null || true

Setup

Ask the user which directory to restrict edits to. Use AskUserQuestion:

  • Question: "Guard mode: which directory should edits be restricted to? Destructive command warnings are always on. Files outside the chosen path will be blocked from editing."
  • Text input (not multiple choice) — the user types a path.

Once the user provides a directory path:

Set the user-selected boundary with the shared writer, which resolves a physical absolute path and serializes replacement with investigation cleanup:

bash
bash "$HOME/.claude/skills/gstack/freeze/bin/freeze-state.sh" set "<user-provided-path>"

On helper failure, do not claim the boundary is active. Preserve the state and report recovery; never bypass the shared writer with a direct write or deletion.

Tell the user:

  • "Guard mode active. Two protections are now running:"
  • "1. Destructive command guard — rm -rf, DROP TABLE, force-push, etc. warn before executing (overridable); catastrophic shapes (recursive delete of / or ~, force-push to the default branch) are hard-denied"
  • "2. Edit boundary — file edits restricted to <path>/. Edits outside this directory are blocked."
  • "To remove the persistent edit boundary, run /unfreeze. Ending the session stops its hooks but does not delete that boundary."

What's protected

See /careful for the full list of destructive command patterns and safe exceptions. See /freeze for how edit boundary enforcement works.

© garrytan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in guard of garrytan/gstack.

  • SKILL.md
  • SKILL.md.tmpl

Open the folder on GitHubat commit 20eb620

Compare with similar skills

Guard Mode next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guard Mode compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guard Mode this skillgarrytan/gstack136k—~1kAutomated safety check: NotesMIT
Nonstop Autonomous Modeandylizf/nonstop263—~2kAutomated safety check: WarnMIT
Safe Moderohitg00/pro-workflow2.9k—~1.4kAutomated safety check: NotesNone
Loop FactoryJuliusBrussee/skills162—~2kAutomated safety check: PassMIT
Iron Proxy Gateway Rulesnanocoai/nanoclaw31k—~598Automated safety check: PassMIT
Hitl Approvalnwiizo/ccswarm153—~290Automated safety check: PassMIT

Similar skills

  • Nonstop Autonomous Mode

    andylizf/nonstop

    Lets Claude keep working while you are away, after a pre-flight that surfaces blockers, risky operations and open decisions, with a stop hook scoped to the session.

    263 GitHub stars~2k tokensUpdated 6 mo ago
    Agent WorkflowsAuto-check: warnings
  • Safe Mode

    rohitg00/pro-workflow

    Prevent destructive operations using Claude Code hooks. An agent skill from rohitg00/pro-workflow.

    2.9k GitHub stars~1.4k tokensUpdated 9 days ago
    Agent WorkflowsAuto-check: notes
  • Loop Factory

    JuliusBrussee/skills

    Run a spec-driven agent loop where coding tasks live as markdown specs that move through inbox → active → archive, get implemented by Claude Code or Codex, and pass a review gate before they count…

    162 GitHub stars~2k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Iron Proxy Gateway Rules

    nanocoai/nanoclaw

    Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

    31k GitHub stars~598 tokensUpdated 2 days ago
    Agent WorkflowsAuto-check passed
  • Hitl Approval

    nwiizo/ccswarm

    Human-in-the-loop approval workflow for high-risk agent operations (file deletions, deployments, config changes).

    153 GitHub stars~290 tokensUpdated 24 days ago
    Agent WorkflowsAuto-check passed
  • Openiap Workflows

    hyodotdev/openiap

    A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…

    155 GitHub stars~766 tokensUpdated today
    Agent WorkflowsAuto-check passed

More from garrytan/gstack

All 56 skills in this repo
  • Gstack Skill Router

    garrytan/gstack

    Router for the gstack skill suite. (gstack)

    136k GitHub stars~4k tokensUpdated today
    Auto-check: notes
  • Root Cause Debugging

    garrytan/gstack

    Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.

    136k GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Builds a weekly engineering retrospective from git history: commit counts, per-person contributions, work patterns and code quality numbers over a chosen window.

    136k GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Aside Browser Driver

    garrytan/gstack

    Drives a real browser through Aside so the agent can open a page, read it, click through a flow, take screenshots and check console errors.

    136k GitHub stars~8.5k tokensUpdated today
    Auto-check: notes
  • Live-Device iOS QA

    garrytan/gstack

    Tests a SwiftUI app on a real iPhone connected by USB, reading the Swift source and then looping through screenshot, analysis and action to find bugs.

    136k GitHub stars~11k tokensUpdated today
    Auto-check: notes
  • Cross-Model Benchmark

    garrytan/gstack

    Sends one prompt to Claude, GPT through the Codex CLI and Gemini, then tabulates response time, token use and cost, with an optional judged quality score.

    136k GitHub stars~4k tokensUpdated today
    Auto-check: notes

Questions about Guard Mode

What does Guard Mode do?

Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems. Guard joins two sibling gstack skills, careful and freeze, into a single command. When it starts, it asks you to type the one directory that edits may touch, then records that boundary through a shared helper script.

When should I use Guard Mode?

Guard Mode fits situations like: working directly on production systems where one wrong command is costly; debugging a live system while keeping every edit inside one folder; starting a session you want locked down with maximum safety.

How do I install Guard Mode in Claude Code?

Run `npx skills add garrytan/gstack --skill guard -a claude-code`. Or copy the skill folder (guard in garrytan/gstack) into .claude/skills/guard in your project. Claude Code loads it when a task matches its description.

How do I install Guard Mode in Codex?

Run `npx skills add garrytan/gstack --skill guard -a codex`. Or copy the skill folder (guard in garrytan/gstack) into .agents/skills/guard in your project. Codex loads it when a task matches its description.

Can I use Guard Mode in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garrytan/gstack --skill guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guard, .gemini/skills/guard, .github/skills/guard and .opencode/skills/guard in your project.

What does Guard Mode need to run?

Going by SKILL.md and its folder, Guard Mode needs the command-line tools its instructions call (git and bash). Our summary lists: The gstack skills /careful and /freeze, installed by the gstack setup script. Its frontmatter pre-approves these tools: Bash, Read, AskUserQuestion.

Does Guard Mode access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Guard Mode safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Guard Mode use?

Guard Mode is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guard Mode use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Guard Mode?

Skills that share tags, products or a category with Guard Mode: Nonstop Autonomous Mode (andylizf/nonstop, 263 stars), Safe Mode (rohitg00/pro-workflow, 2.9k stars), Loop Factory (JuliusBrussee/skills, 162 stars) and Iron Proxy Gateway Rules (nanocoai/nanoclaw, 31k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guard Mode?

garrytan (a GitHub user) maintains it in garrytan/gstack, which has 135,670 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 9, 2026.

Source: garrytan/gstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.