Nonstop Autonomous Mode
andylizf/nonstop
Lets Claude keep working while you are away, after a pre-flight that surfaces blockers, risky operations and open decisions, with a stop hook scoped to the session.
Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.
$ npx skills add garrytan/gstack --skill guard -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install garrytan/gstack guard --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .claude/skills && cp -r skills-src/guard .claude/skills/guard && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "guard" agent skill from https://github.com/garrytan/gstack/tree/main/guard into .claude/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/garrytan/gstack/tree/main/guardType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add garrytan/gstack --skill guard -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install garrytan/gstack guard --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .agents/skills && cp -r skills-src/guard .agents/skills/guard && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "guard" agent skill from https://github.com/garrytan/gstack/tree/main/guard into .agents/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garrytan/gstack --skill guard -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install garrytan/gstack guard --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/guard .cursor/skills/guard && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "guard" agent skill from https://github.com/garrytan/gstack/tree/main/guard into .cursor/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/garrytan/gstack.git --path guard--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add garrytan/gstack --skill guard -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install garrytan/gstack guard --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/guard .gemini/skills/guard && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "guard" agent skill from https://github.com/garrytan/gstack/tree/main/guard into .gemini/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install garrytan/gstack guardInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add garrytan/gstack --skill guard -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .github/skills && cp -r skills-src/guard .github/skills/guard && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "guard" agent skill from https://github.com/garrytan/gstack/tree/main/guard into .github/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add garrytan/gstack --skill guard -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install garrytan/gstack guard --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/garrytan/gstack.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/guard .opencode/skills/guard && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "guard" agent skill from https://github.com/garrytan/gstack/tree/main/guard into .opencode/skills/guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guard", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
guardSwitches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.
Guard joins two sibling gstack skills, careful and freeze, into a single command. When it starts, it asks you to type the one directory that edits may touch, then records that boundary through a shared helper script. It reports the boundary as active only if the helper succeeds; on failure it keeps the existing state and tells you how to recover, rather than writing the state file directly.
Two protections then apply. Commands such as rm -rf, DROP TABLE and force-push produce a warning you can override, while catastrophic cases, like recursively deleting / or ~ or force-pushing to the default branch, are refused outright. File edits outside the chosen path are blocked. The boundary is lifted with /unfreeze; ending the session stops the hooks but leaves the saved boundary in place. Both /careful and /freeze must be installed, which the gstack setup script does.
Read from SKILL.md and the folder at commit 20eb620. It shows what the files ask for, not the result of running them.
Pre-approves these tools, so the agent can use them without asking each time:
BashReadAskUserQuestionFrom allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitbashFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Guard Mode loads about 1k tokens when it runs. Until then it costs about 22 tokens; SKILL.md has 297 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check noted patterns worth knowing about, such as sudo or a known installer.
allowed-tools: Bash, Read, AskUserQuestionAutomated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from garrytan/gstack at commit 20eb620, republished under its MIT licence (© garrytan). 297 words, ~1,032 tokens.
.claude/skills/guard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly -->
<!-- Regenerate: bun run gen:skill-docs -->
Combines /careful (warns before rm -rf, DROP TABLE, force-push, etc.) with /freeze (blocks edits outside a specified directory). Use for maximum safety when touching prod or debugging live systems. Use when asked to "guard mode", "full safety", "lock it down", or "maximum safety".
Activates both destructive command warnings and directory-scoped edit restrictions.
This is the combination of /careful + /freeze in a single command.
Dependency note: This skill references hook scripts from the sibling /careful
and /freeze skill directories. Both must be installed (they are installed together
by the gstack setup script).
GSTACK_STATE_ROOT=$(~/.claude/skills/gstack/bin/gstack-paths --get GSTACK_STATE_ROOT); : "${GSTACK_STATE_ROOT:?gstack-paths failed; reinstall with ./setup or /gstack-upgrade}"
mkdir -p "$GSTACK_STATE_ROOT"/analytics
echo '{"skill":"guard","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}' >> "$GSTACK_STATE_ROOT"/analytics/skill-usage.jsonl 2>/dev/null || trueAsk the user which directory to restrict edits to. Use AskUserQuestion:
Once the user provides a directory path:
Set the user-selected boundary with the shared writer, which resolves a physical absolute path and serializes replacement with investigation cleanup:
bash "$HOME/.claude/skills/gstack/freeze/bin/freeze-state.sh" set "<user-provided-path>"On helper failure, do not claim the boundary is active. Preserve the state and report recovery; never bypass the shared writer with a direct write or deletion.
Tell the user:
<path>/. Edits outside this directory are blocked."/unfreeze. Ending the session stops its hooks but does not delete that boundary."See /careful for the full list of destructive command patterns and safe exceptions.
See /freeze for how edit boundary enforcement works.
© garrytan, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file in guard of garrytan/gstack.
Open the folder on GitHubat commit 20eb620
Guard Mode next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Guard Mode this skillgarrytan/gstack | 136k | — | ~1k | Automated safety check: Notes | MIT | |
| Nonstop Autonomous Modeandylizf/nonstop | 263 | — | ~2k | Automated safety check: Warn | MIT | |
| Safe Moderohitg00/pro-workflow | 2.9k | — | ~1.4k | Automated safety check: Notes | None | |
| Loop FactoryJuliusBrussee/skills | 162 | — | ~2k | Automated safety check: Pass | MIT | |
| Iron Proxy Gateway Rulesnanocoai/nanoclaw | 31k | — | ~598 | Automated safety check: Pass | MIT | |
| Hitl Approvalnwiizo/ccswarm | 153 | — | ~290 | Automated safety check: Pass | MIT |
andylizf/nonstop
Lets Claude keep working while you are away, after a pre-flight that surfaces blockers, risky operations and open decisions, with a stop hook scoped to the session.
rohitg00/pro-workflow
Prevent destructive operations using Claude Code hooks. An agent skill from rohitg00/pro-workflow.
JuliusBrussee/skills
Run a spec-driven agent loop where coding tasks live as markdown specs that move through inbox → active → archive, get implemented by Claude Code or Codex, and pass a review gate before they count…
nanocoai/nanoclaw
Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.
nwiizo/ccswarm
Human-in-the-loop approval workflow for high-risk agent operations (file deletions, deployments, config changes).
hyodotdev/openiap
A skill your agent uses for OpenIAP monorepo work that should follow the repository's slash-command workflows when the user asks in natural language instead of typing a slash command, including…
garrytan/gstack
Router for the gstack skill suite. (gstack)
garrytan/gstack
Investigates bugs, errors and stack traces in phases and requires a root-cause hypothesis to be confirmed before any fix is written.
garrytan/gstack
Builds a weekly engineering retrospective from git history: commit counts, per-person contributions, work patterns and code quality numbers over a chosen window.
garrytan/gstack
Drives a real browser through Aside so the agent can open a page, read it, click through a flow, take screenshots and check console errors.
garrytan/gstack
Tests a SwiftUI app on a real iPhone connected by USB, reading the Swift source and then looping through screenshot, analysis and action to find bugs.
garrytan/gstack
Sends one prompt to Claude, GPT through the Codex CLI and Gemini, then tabulates response time, token use and cost, with an optional judged quality score.
Categories
Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems. Guard joins two sibling gstack skills, careful and freeze, into a single command. When it starts, it asks you to type the one directory that edits may touch, then records that boundary through a shared helper script.
Guard Mode fits situations like: working directly on production systems where one wrong command is costly; debugging a live system while keeping every edit inside one folder; starting a session you want locked down with maximum safety.
Run `npx skills add garrytan/gstack --skill guard -a claude-code`. Or copy the skill folder (guard in garrytan/gstack) into .claude/skills/guard in your project. Claude Code loads it when a task matches its description.
Run `npx skills add garrytan/gstack --skill guard -a codex`. Or copy the skill folder (guard in garrytan/gstack) into .agents/skills/guard in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add garrytan/gstack --skill guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guard, .gemini/skills/guard, .github/skills/guard and .opencode/skills/guard in your project.
Going by SKILL.md and its folder, Guard Mode needs the command-line tools its instructions call (git and bash). Our summary lists: The gstack skills /careful and /freeze, installed by the gstack setup script. Its frontmatter pre-approves these tools: Bash, Read, AskUserQuestion.
SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.
Guard Mode is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Guard Mode: Nonstop Autonomous Mode (andylizf/nonstop, 263 stars), Safe Mode (rohitg00/pro-workflow, 2.9k stars), Loop Factory (JuliusBrussee/skills, 162 stars) and Iron Proxy Gateway Rules (nanocoai/nanoclaw, 31k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
garrytan (a GitHub user) maintains it in garrytan/gstack, which has 135,670 GitHub stars. The repository holds 56 skills in this directory. The repository was last updated on October 9, 2026.
Source: garrytan/gstack on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.