Agent skill

Safe File Deletion

by MemTensor in MemTensor/MemOS

“Enforces explicit user permission before any file deletion. Activates when you're about to use rm, unlink, fs.rm, or any operation that removes files from disk. MUST be followed…”

— description from SKILL.md by MemTensor
Apache-2.0Auto-check passedAgent Workflows

Install Safe File Deletion

skills CLI
$ npx skills add MemTensor/MemOS --skill safe-file-deletion -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install MemTensor/MemOS safe-file-deletion --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/MemTensor/MemOS.git skills-src && mkdir -p .claude/skills && cp -r skills-src/apps/openwork-memos-integration/apps/desktop/skills/safe-file-deletion .claude/skills/safe-file-deletion && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
safe-file-deletion
GitHub stars
12k
Token cost
~291 tokens
SKILL.md length
103 words
Files
1
Skills in repo
6
Repo updated
First seen
Licence
Apache-2.0

At a glance

  • Works in 5 steps: Call request_file_permission with… → For multiple files, use filePaths array… → Wait for response → …
  • SKILL.md covers Rule, Applies To, Examples and No Workarounds
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

About this skill

“Enforces explicit user permission before any file deletion. Activates when you're about to use rm, unlink, fs.rm, or any operation that removes files from disk. MUST be followed for all delete operations.”

— description from SKILL.md by MemTensor

Safe File Deletion is a skill in MemTensor/MemOS (12k stars). Its SKILL.md is about 291 tokens. Licence: Apache-2.0.

Workflow steps

5 steps, taken from the first numbered list in SKILL.md.

  1. Call request_file_permission with operation: "delete"
  2. For multiple files, use filePaths array (not multiple calls)
  3. Wait for response
  4. Only proceed if "allowed"
  5. If "denied", acknowledge and do NOT delete

What it can do on your machine

Read from SKILL.md and the folder at commit a7367d0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are json).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Safe File Deletion loads about 291 tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 103 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~291

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from MemTensor/MemOS at commit a7367d0, republished under its Apache-2.0 licence (© MemTensor). 103 words, ~291 tokens.

Download SKILL.mdSave it as .claude/skills/safe-file-deletion/SKILL.md (or your agent's skills folder).
name
safe-file-deletion
description
Enforces explicit user permission before any file deletion. Activates when you're about to use rm, unlink, fs.rm, or any operation that removes files from disk. MUST be followed for all delete operations.

Safe File Deletion

Rule

Before deleting ANY file, you MUST:

  1. Call request_file_permission with operation: "delete"
  2. For multiple files, use filePaths array (not multiple calls)
  3. Wait for response
  4. Only proceed if "allowed"
  5. If "denied", acknowledge and do NOT delete

Applies To

  • rm commands (single or multiple files)
  • rm -rf (directories)
  • unlink, fs.rm, fs.rmdir
  • Any script or tool that deletes files

Examples

Single file:

json
{
  "operation": "delete",
  "filePath": "/path/to/file.txt"
}

Multiple files (batched into one prompt):

json
{
  "operation": "delete",
  "filePaths": ["/path/to/file1.txt", "/path/to/file2.txt"]
}

No Workarounds

Never bypass deletion warnings by:

  • Emptying files instead of deleting
  • Moving to hidden/temp locations
  • Using obscure commands

The user will see a prominent warning. Wait for explicit approval.

© MemTensor, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in apps/openwork-memos-integration/apps/desktop/skills/safe-file-deletion of MemTensor/MemOS.

Open the folder on GitHubat commit a7367d0

Compare with similar skills

Safe File Deletion next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Safe File Deletion compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Safe File Deletion this skillMemTensor/MemOS12k—~291Automated safety check: PassApache-2.0
Loop FactoryJuliusBrussee/skills161—~2kAutomated safety check: PassMIT
Guard Modegarrytan/gstack136k—~919Automated safety check: NotesMIT
Iron Proxy Gateway Rulesnanocoai/nanoclaw31k1 repos~598Automated safety check: PassMIT
Show Me Your Work Decision Logcursor/plugins10k9 repos~1.6kAutomated safety check: PassNone
Darwin Skill Optimizeralchaincyf/darwin-skill6.2k1 repos~4.7kAutomated safety check: PassMIT

Similar skills

  • Loop Factory

    JuliusBrussee/skills

    Run a spec-driven agent loop where coding tasks live as markdown specs that move through inbox → active → archive, get implemented by Claude Code or Codex, and pass a review gate before they count…

    161 GitHub stars~2k tokensUpdated 2 mo ago
    Agent WorkflowsAuto-check passed
  • Guard Mode

    garrytan/gstack

    Switches on full safety by combining warnings before destructive commands with a block on edits outside one directory you choose, for work on production or live systems.

    136k GitHub stars~919 tokensUpdated today
    Agent WorkflowsAuto-check: notes
  • Iron Proxy Gateway Rules

    nanocoai/nanoclaw

    Rules for working behind Iron Proxy: connect external accounts without handling raw tokens, treat blocked requests as policy outcomes, and never claim a connection before it works.

    31k GitHub starsUsed in 1 repo~598 tokens
    Agent WorkflowsAuto-check passed
  • Official

    Keeps a TSV decision log for long or unattended agent runs, one row per decision with what, why, evidence and result, so a reviewer can check the work later.

    10k GitHub starsUsed in 9 repos~1.6k tokens
    Agent WorkflowsAuto-check passed
  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed
  • Loop Constraints Enforcer

    cobusgreyling/loop-engineering

    Loads a project's loop-constraints.md before any other action and blocks pushes, edits or merges that violate the rules it defines.

    11k GitHub starsUsed in 1 repo~475 tokens
    Agent WorkflowsAuto-check: notes

More from MemTensor/MemOS

  • Dev Browser Automation

    MemTensor/MemOS

    Automates a real browser through short TypeScript scripts that keep page state between runs, for navigating, filling forms, taking screenshots and extracting data.

    12k GitHub starsUsed in 3 repos~1.7k tokens
    Auto-check passed
  • Controls a browser through BrowserWing's local HTTP API: navigation, clicks, typing, data extraction, accessibility snapshots, screenshots and batch operations.

    12k GitHub starsUsed in 2 repos~3.9k tokens
    Auto-check passed
  • Ask User Question

    MemTensor/MemOS

    Shows a question as a modal in the interface to clarify a task, collect a preference or get approval, since the user cannot see terminal output.

    12k GitHub stars~1k tokensUpdated 9 days ago
    Auto-check passed
  • BrowserWing Admin

    MemTensor/MemOS

    Installs, configures and operates BrowserWing, a browser automation platform, covering Chrome setup, LLM provider configuration, and creating or running automation scripts.

    12k GitHub stars~4.1k tokensUpdated 9 days ago
    Auto-check: notes
  • Explains when to call MemOS's own memory tools to search past conversations, after the automatic per-turn recall hook comes up empty.

    12k GitHub stars~3.5k tokensUpdated 9 days ago
    Auto-check: warnings

Questions about Safe File Deletion

How do I install Safe File Deletion in Claude Code?

Run `npx skills add MemTensor/MemOS --skill safe-file-deletion -a claude-code`. Or copy the skill folder (apps/openwork-memos-integration/apps/desktop/skills/safe-file-deletion in MemTensor/MemOS) into .claude/skills/safe-file-deletion in your project. Claude Code loads it when a task matches its description.

How do I install Safe File Deletion in Codex?

Run `npx skills add MemTensor/MemOS --skill safe-file-deletion -a codex`. Or copy the skill folder (apps/openwork-memos-integration/apps/desktop/skills/safe-file-deletion in MemTensor/MemOS) into .agents/skills/safe-file-deletion in your project. Codex loads it when a task matches its description.

Can I use Safe File Deletion in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add MemTensor/MemOS --skill safe-file-deletion -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/safe-file-deletion, .gemini/skills/safe-file-deletion, .github/skills/safe-file-deletion and .opencode/skills/safe-file-deletion in your project.

What does Safe File Deletion need to run?

SKILL.md names no scripts, command-line tools or credentials: Safe File Deletion is instructions for the agent only.

Does Safe File Deletion access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Safe File Deletion safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Safe File Deletion use?

Safe File Deletion is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Safe File Deletion use?

About 291 tokens (SKILL.md is roughly 1.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Safe File Deletion?

Skills that share tags, products or a category with Safe File Deletion: Loop Factory (JuliusBrussee/skills, 161 stars), Guard Mode (garrytan/gstack, 136k stars), Iron Proxy Gateway Rules (nanocoai/nanoclaw, 31k stars) and Show Me Your Work Decision Log (cursor/plugins, 10k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Safe File Deletion?

MemTensor (a GitHub organization) maintains it in MemTensor/MemOS, which has 11,754 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on September 29, 2026.

Source: MemTensor/MemOS on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.