Requirements
rizsotto/Bear
Write, modify, or review a requirement file under docs/requirements -- pick the single owning file, keep the text contract-only, name IDs so they need no explanation, and verify cross-references and…
Add and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of…
$ npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install kajisho5/ffmpeg-skill guarding-destructive-operations --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/destructive-operations .claude/skills/guarding-destructive-operations && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "guarding-destructive-operations" agent skill from https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operations into .claude/skills/guarding-destructive-operations/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guarding-destructive-operations", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operationsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install kajisho5/ffmpeg-skill guarding-destructive-operations --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/destructive-operations .agents/skills/guarding-destructive-operations && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "guarding-destructive-operations" agent skill from https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operations into .agents/skills/guarding-destructive-operations/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guarding-destructive-operations", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install kajisho5/ffmpeg-skill guarding-destructive-operations --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/destructive-operations .cursor/skills/guarding-destructive-operations && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "guarding-destructive-operations" agent skill from https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operations into .cursor/skills/guarding-destructive-operations/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guarding-destructive-operations", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/kajisho5/ffmpeg-skill.git --path .claude/skills/destructive-operations--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install kajisho5/ffmpeg-skill guarding-destructive-operations --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/destructive-operations .gemini/skills/guarding-destructive-operations && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "guarding-destructive-operations" agent skill from https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operations into .gemini/skills/guarding-destructive-operations/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guarding-destructive-operations", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install kajisho5/ffmpeg-skill guarding-destructive-operationsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/destructive-operations .github/skills/guarding-destructive-operations && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "guarding-destructive-operations" agent skill from https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operations into .github/skills/guarding-destructive-operations/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guarding-destructive-operations", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install kajisho5/ffmpeg-skill guarding-destructive-operations --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/kajisho5/ffmpeg-skill.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/destructive-operations .opencode/skills/guarding-destructive-operations && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "guarding-destructive-operations" agent skill from https://github.com/kajisho5/ffmpeg-skill/tree/main/.claude/skills/destructive-operations into .opencode/skills/guarding-destructive-operations/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guarding-destructive-operations", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
guarding-destructive-operationsAdd and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of…
Guarding Destructive Operations is an agent skill from kajisho5/ffmpeg-skill. Add and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of the first mutation, structural classification rather than string-prefix matching, name validation plus resolved-path containment as two independent checks, why a guard on the destructive path is invisible to the dry-run, and mutation-testing each half separately. Use when writing or reviewing a --rebuild/--reset/--purge…
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Testing & QA, covering Test coverage. The licence is MIT.
Read from SKILL.md and the folder at commit 1f7e7e3. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are go and python).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
github.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Guarding Destructive Operations loads about 2.6k tokens when it runs. Until then it costs about 169 tokens; SKILL.md has 1,205 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from kajisho5/ffmpeg-skill at commit 1f7e7e3, republished under its MIT licence (© kajisho5). 1,205 words, ~2,628 tokens.
.claude/skills/guarding-destructive-operations/SKILL.md (or your agent's skills folder).Some operations have no undo: an orphan-branch rewrite, a recursive delete of
every tracked file, an overwrite of a stored artifact, a DROP/purge path. The
implementation is usually short and usually correct for the setup its author had
in mind. The bug is never the deletion itself — it is that nothing checked
whether the target was the thing the author imagined.
Two shapes recur, and they take the same fix:
A destructive operation that discovers its precondition is violated should return
an error and change nothing. A warning is read by nobody, and a --force escape
hatch turns the guard into documentation.
// A rebuild that recreates history does `checkout --orphan` then
// `rm -rf --ignore-unmatch .`, keeping only the state files it rewrites.
// That is correct in a dedicated mirror repository whose ONLY tracked content
// is `.state/`. Run it where source code also lives and the new branch loses
// the source code.
func (e *Engine) rebuild() error {
if err := e.ensureDedicatedRepo(); err != nil {
return err // nothing mutated yet
}
...
}The honest justification for having no override flag: there is no situation where the operator wants this command to delete unrelated tracked files. If a real one appears later, that is a separate, differently-named command — not a boolean on this one.
"Refuses" is only true if the refusal happens before anything has changed. Walk the function and find the first statement with an effect — it is often not the obvious deletion. In-memory state clearing, a branch checkout, and a read-then-rewrite of the very files you are preserving all count.
// Order that makes the refusal safe:
// 1. reject detached HEAD / ambiguous state
// 2. ensureDedicatedRepo() <-- the new guard, nothing mutated yet
// 3. read the state files to preserve
// 4. CheckoutOrphan()
// 5. RemoveAllTrackedFiles()
// 6. ClearAllProgressCounts()Steps 3-6 are all mutations of something (3 is not, but it is where the "what to preserve" snapshot is taken, and a guard after it has already committed you to a shape). Land the guard at 2 and a rejected run leaves the working tree byte-identical.
Also refuse ambiguous state before rewriting it. A history rewrite that assumes a named branch should reject detached HEAD up front rather than silently recreating the wrong ref.
The guard needs to answer "is every tracked path inside the directory this
command owns?". A HasPrefix/startswith on the bare directory name is the
wrong answer and looks right in every test you would think to write.
// Bad — admits `.state-backup/notes.md` and `.stateful.txt`, so a repository
// full of unrelated content passes the guard and gets deleted.
func owned(path string) bool {
return strings.HasPrefix(path, ".state")
}
// Good — the directory itself, or something genuinely under it.
func owned(path string) bool {
return path == ".state" || strings.HasPrefix(path, ".state/")
}The same distinction in Python is Path(p) == base or base in Path(p).parents,
not p.startswith(str(base)). Any time a check compares paths as strings, ask
what a sibling with a longer name does to it.
When a public argument selects a file — a baseline name, a template id, a report slug — do both, in this order:
NAME_RE = re.compile(r"^[A-Za-z0-9][A-Za-z0-9._-]*$")
def _validate_name(name: str) -> str:
if ".." in name or not NAME_RE.match(name):
raise ValueError(f"invalid name: {name!r}")
return name
def _resolve(name: str, base: Path) -> Path:
candidate = (base / f"{_validate_name(name)}.json").resolve()
if not candidate.is_relative_to(base.resolve()):
raise ValueError(f"name escapes {base}: {name!r}")
return candidateThe containment half is not redundant with the regex. The regex stops ..
segments and absolute paths; only the resolve() + containment check stops a
symlink placed inside the directory that points out of it — a name matching
^[A-Za-z0-9] all the way through can still resolve anywhere. Route every entry
point through both: the loader, the saver, and any path-building helper a public
method still calls directly. A single unrouted helper reinstates the whole hole.
Without this, an implicit suffix (name + ".json") plus an absolute-path
argument reads any file on disk whose name happens to end in that suffix.
If the real run reaches the guard but --dry-run short-circuits earlier, the
preview cheerfully describes an operation the real run will refuse. That is a
defensible design — the destructive path is the one that must be safe — but be
explicit about it:
Say which one you chose in the PR description; a reviewer cannot tell from the diff whether the dry-run gap is intentional.
Tightening validation only helps if the new error reaches somebody. A broad
except Exception two frames up will turn a hard refusal into an ordinary
result shape:
try:
features = self._load(baseline)
except Exception as e: # already there, catches your ValueError
return {"error": f"Analysis failed: {e}", "features": {}, "flags": {...}}This is often fine — an API boundary that never raises is a real contract, and
the refusal surfaces as a normal error-shaped response rather than a protocol
error. But check it deliberately: if that shape is what your caller sees, the
integration test asserts on result["error"], not on pytest.raises.
..
fixture fails; neuter only the containment check and confirm a symlink
fixture fails. One combined test passes with either half deleted and proves
neither..state/data.json passes against HasPrefix(path, ".state") too. The test
that separates the implementations tracks .state-backup/old.json and asserts
the operation is refused.app.txt
alongside the state directory, because nothing cared. After the guard, such a
test no longer reaches the code it was written to cover; it now exercises the
refusal. Tighten those fixtures to the allowed shape and add the refusal case
as a new test, or you silently lose coverage of the destructive path.--force, no warn-and-continuex-backup/) and a symlink fixture both existThis repo's actual exposure is much narrower than the examples above — there is
no --rebuild/--purge-shaped command, no history rewriting, and "Keep
originals" is already a stated design principle (README.md design principle
#9: no tool overwrites its input; a test hashes every input after every run,
see tests/test_all.py/tests/test_contract.py's input-hash checks). The
closest analogue is -o/output-path handling: every tool takes a
caller-supplied output path and ffmpeg_base() always passes -y (overwrite
without prompting) — there is no confirmation step before an existing file at
that path is silently replaced. Since this is a local CLI a human or agent
invokes directly (not a server resolving untrusted network input against a
base directory), the "boundary escape" half of this skill is low-stakes here;
the "refuse before the first mutation" and "existing input-hash tests still
prove nothing was touched" halves are the parts that actually apply.
Source: wdm0006/python-skills (MIT).
© kajisho5, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/destructive-operations of kajisho5/ffmpeg-skill.
Open the folder on GitHubat commit 1f7e7e3
Guarding Destructive Operations next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Guarding Destructive Operations this skillkajisho5/ffmpeg-skill | 1.9k | — | ~2.6k | Automated safety check: Pass | MIT | |
| Requirementsrizsotto/Bear | 6.5k | — | ~2k | Automated safety check: Pass | GPL-3.0 | |
| Crap Analysisardalis/RiverBooks | 135 | 2 repos | ~3.4k | Automated safety check: Pass | None | |
| Bmad Testarch Automatechenjackle45/SayIt | 115 | 2 repos | ~867 | Automated safety check: Pass | MIT | |
| Code Coverages3s-project/s3s | 311 | — | ~789 | Automated safety check: Pass | Apache-2.0 | |
| Project Statusbactopia/bactopia | 522 | — | ~787 | Automated safety check: Pass | MIT |
rizsotto/Bear
Write, modify, or review a requirement file under docs/requirements -- pick the single owning file, keep the text contract-only, name IDs so they need no explanation, and verify cross-references and…
ardalis/RiverBooks
Analyze code coverage and CRAP (Change Risk Anti-Patterns) scores to identify high-risk code.
chenjackle45/SayIt
Expand test automation coverage for codebase. An agent skill from chenjackle45/SayIt.
s3s-project/s3s
Measure and grow the line coverage of the s3s crate. An agent skill from s3s-project/s3s.
bactopia/bactopia
Show a live snapshot of the Bactopia project state — component counts, GroovyDoc coverage, nf-test coverage, and structural issues.
ldayton/Dippy
Ensure comprehensive test coverage for a CLI handler. An agent skill from ldayton/Dippy.
kajisho5/ffmpeg-skill
Edit video and audio with local FFmpeg from natural-language requests: cut, trim, join, resize/reframe (9:16, 1:1), speed change, captions and subtitles (SRT/ASS, animated, karaoke), logos and text…
kajisho5/ffmpeg-skill
Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.
kajisho5/ffmpeg-skill
Review a change to the ffmpeg-skill repository for the failures its own contract makes possible — a claim in a result document that is true at one layer and false at the layer a caller reads, a new…
kajisho5/ffmpeg-skill
Builds robust Python MCP (Model Context Protocol) servers with FastMCP — tool design, error contracts, event-loop-safe blocking work, subprocess/CLI wrapping, single-file vs packaged distribution…
kajisho5/ffmpeg-skill
Resolve conflicts and merges when several branches are open against one repo at the same time — the hotspot files every change must touch (registry manifests, a single version field, shared tool…
kajisho5/ffmpeg-skill
Prevents, detects, and remediates files that should never be committed — secrets (.env, API tokens, hardcoded credentials) and dev artifacts (build output, scratch databases, editor/OS files).
Categories
Add and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of…. Guarding Destructive Operations is an agent skill from kajisho5/ffmpeg-skill. Add and review preconditions on operations that delete, overwrite, rewrite history, or resolve a caller-supplied name to a filesystem path — refusing instead of warning, placing the guard ahead of the first mutation, structural classification rather than string-prefix matching, name validation plus resolved-path containment as two independent checks, why a guard on the destructive path is invisible to the dry-run, and mutation-testing each half separately.
Guarding Destructive Operations fits situations like: reviewing a --rebuild/--reset/--purge command; A history rewrite; an rm -rf-shaped step; any code that turns an argument into a file path.
Run `npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a claude-code`. Or copy the skill folder (.claude/skills/destructive-operations in kajisho5/ffmpeg-skill) into .claude/skills/guarding-destructive-operations in your project. Claude Code loads it when a task matches its description.
Run `npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a codex`. Or copy the skill folder (.claude/skills/destructive-operations in kajisho5/ffmpeg-skill) into .agents/skills/guarding-destructive-operations in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kajisho5/ffmpeg-skill --skill guarding-destructive-operations -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guarding-destructive-operations, .gemini/skills/guarding-destructive-operations, .github/skills/guarding-destructive-operations and .opencode/skills/guarding-destructive-operations in your project.
SKILL.md names no scripts, command-line tools or credentials: Guarding Destructive Operations is instructions for the agent only. Our summary lists: Python 3.
SKILL.md names 1 domain. As links in the text: github.com. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Guarding Destructive Operations is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 11k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Guarding Destructive Operations: Requirements (rizsotto/Bear, 6.5k stars), Crap Analysis (ardalis/RiverBooks, 135 stars), Bmad Testarch Automate (chenjackle45/SayIt, 115 stars) and Code Coverage (s3s-project/s3s, 311 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
kajisho5 (a GitHub user) maintains it in kajisho5/ffmpeg-skill, which has 1,909 GitHub stars. The repository holds 14 skills in this directory. The repository was last updated on October 10, 2026.
Source: kajisho5/ffmpeg-skill on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.