Agent skill

Careful

by mr-daedalium in mr-daedalium/ostack-saas

Safety guardrails for destructive commands. An agent skill from mr-daedalium/ostack-saas.

MITAuto-check: notesAI & LLM Engineering

Install Careful

skills CLI
$ npx skills add mr-daedalium/ostack-saas --skill careful -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mr-daedalium/ostack-saas careful --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mr-daedalium/ostack-saas.git skills-src && mkdir -p .claude/skills && cp -r skills-src/careful .claude/skills/careful && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
careful
GitHub stars
114
Used in
1 other repo
Token cost
~545 tokens
SKILL.md length
186 words
Files
3
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Safety guardrails for destructive commands. An agent skill from mr-daedalium/ostack-saas.

  • Debugging live systems
  • SKILL.md covers What's protected, Safe exceptions and How it works
  • Runs Shell scripts from its folder; calls git, docker and kubectl
  • Working in a shared environment

What it does

Careful is an agent skill from mr-daedalium/ostack-saas. Safety guardrails for destructive commands. Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".

Its SKILL.md is about 550 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files (for example `bin/check-careful.sh`).

It sits in AI & LLM Engineering, covering Container orchestration and LLM guardrails. It works with Git, Kubernetes and Docker. The repository describes itself as: ostack — AI-powered engineering team for Claude Code. Fork of gstack by Garry Tan. The licence is MIT.

When your agent uses it

  • Debugging live systems
  • Working in a shared environment
  • Asked to be careful

Example prompts

  • “be careful”
  • “safety mode”
  • “prod mode”
  • “/careful”

Requirements

  • A Bash shell
  • Docker
  • Pre-approved tools (allowed-tools): Bash, Read

What it can do on your machine

Read from SKILL.md and the folder at commit a67256d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships script files (Shell), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • docker
    • kubectl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, docker and kubectl, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Careful loads about 545 tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 186 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~545

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mr-daedalium/ostack-saas at commit a67256d, republished under its MIT licence (© mr-daedalium). 186 words, ~545 tokens.

Download SKILL.mdSave it as .claude/skills/careful/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
careful
description
Safety guardrails for destructive commands. Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".
allowed-tools
Bash, Read
version
0.1.0
<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly -->
<!-- Regenerate: bun run gen:skill-docs -->

/careful — Destructive Command Guardrails

Safety mode is now active. Every bash command will be checked for destructive patterns before running. If a destructive command is detected, you'll be warned and can choose to proceed or cancel.

What's protected

PatternExampleRisk
rm -rf / rm -r / rm --recursiverm -rf /var/dataRecursive delete
DROP TABLE / DROP DATABASEDROP TABLE users;Data loss
TRUNCATETRUNCATE orders;Data loss
git push --force / -fgit push -f origin mainHistory rewrite
git reset --hardgit reset --hard HEAD~3Uncommitted work loss
git checkout . / git restore .git checkout .Uncommitted work loss
kubectl deletekubectl delete podProduction impact
docker rm -f / docker system prunedocker system prune -aContainer/image loss

Safe exceptions

These patterns are allowed without warning:

  • rm -rf node_modules / .next / dist / __pycache__ / .cache / build / .turbo / coverage

How it works

The hook reads the command from the tool input JSON, checks it against the patterns above, and returns permissionDecision: "ask" with a warning message if a match is found. You can always override the warning and proceed.

To deactivate, end the conversation or start a new one. Hooks are session-scoped.

© mr-daedalium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files in careful of mr-daedalium/ostack-saas.

  • SKILL.md
  • SKILL.md.tmpl
  • bin/check-careful.sh

Open the folder on GitHubat commit a67256d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in mr-daedalium/ostack-saas, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Careful next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Careful compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Careful this skillmr-daedalium/ostack-saas1141 repos~545Automated safety check: NotesMIT
HypaHypabolic/Hypa212—~2.6kAutomated safety check: PassCustom licence
Tokf Runmpecan/tokf199—~571Automated safety check: PassMIT
Alloygrafana/skills282—~1.3kAutomated safety check: PassApache-2.0
Performing Container Security Scanning With Trivymukul975/Anthropic-Cybersecurity-Skills34k—~818Automated safety check: PassApache-2.0
Devops Automationrohitg00/awesome-claude-code-toolkit2.7k—~1.6kAutomated safety check: PassApache-2.0

Similar skills

  • Hypa

    Hypabolic/Hypa

    Context-optimized command runtime. An agent skill from Hypabolic/Hypa.

    212 GitHub stars~2.6k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Tokf Run

    mpecan/tokf

    Compress verbose CLI output with tokf before returning results.

    199 GitHub stars~571 tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Alloy

    grafana/skills

    Official

    Build a unified telemetry pipeline with Grafana Alloy — one OpenTelemetry-compatible binary that collects metrics, logs, traces, and profiles and ships to Grafana Cloud / Prometheus / Loki / Tempo /…

    282 GitHub stars~1.3k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Performing Container Security Scanning With Trivy

    mukul975/Anthropic-Cybersecurity-Skills

    Runs Trivy across every target type it supports - container images, filesystems, Git repositories, and Kubernetes clusters - for OS and dependency vulnerabilities, IaC misconfiguration, exposed…

    34k GitHub stars~818 tokensUpdated 1 mo ago
    DevOps & CloudAuto-check passed
  • Devops Automation

    rohitg00/awesome-claude-code-toolkit

    CI/CD pipeline design with GitHub Actions, Docker, Kubernetes, Helm, and GitOps patterns

    2.7k GitHub stars~1.6k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check passed
  • Dstack Prototyping

    dstackai/dstack

    Use with the dstack skill for model-serving work when the image, serving command, resources, backend/fleet choice, or service behavior is not proven.

    2.3k GitHub stars~1.6k tokensUpdated 2 days ago
    AI & LLM EngineeringAuto-check passed

More from mr-daedalium/ostack-saas

All 23 skills in this repo
  • Browse

    mr-daedalium/ostack-saas

    Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~5.3k tokens
    Auto-check: notes
  • Benchmark

    mr-daedalium/ostack-saas

    Performance regression detection using the browse daemon. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~5k tokens
    Auto-check: notes
  • Freeze

    mr-daedalium/ostack-saas

    Restrict file edits to a specific directory for the session.

    114 GitHub starsUsed in 1 repo~681 tokens
    Auto-check: notes
  • Ostack

    mr-daedalium/ostack-saas

    Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub stars~6.1k tokensUpdated 6 mo ago
    Auto-check: notes
  • Guard

    mr-daedalium/ostack-saas

    Full safety mode: destructive command warnings + directory-scoped edits.

    114 GitHub starsUsed in 1 repo~720 tokens
    Auto-check: notes
  • Investigate

    mr-daedalium/ostack-saas

    Systematic debugging with root cause investigation. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check: notes

Questions about Careful

What does Careful do?

Safety guardrails for destructive commands. An agent skill from mr-daedalium/ostack-saas. Careful is an agent skill from mr-daedalium/ostack-saas. Safety guardrails for destructive commands.

When should I use Careful?

Careful fits situations like: debugging live systems; working in a shared environment; asked to be careful.

How do I install Careful in Claude Code?

Run `npx skills add mr-daedalium/ostack-saas --skill careful -a claude-code`. Or copy the skill folder (careful in mr-daedalium/ostack-saas) into .claude/skills/careful in your project. Claude Code loads it when a task matches its description.

How do I install Careful in Codex?

Run `npx skills add mr-daedalium/ostack-saas --skill careful -a codex`. Or copy the skill folder (careful in mr-daedalium/ostack-saas) into .agents/skills/careful in your project. Codex loads it when a task matches its description.

Can I use Careful in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mr-daedalium/ostack-saas --skill careful -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/careful, .gemini/skills/careful, .github/skills/careful and .opencode/skills/careful in your project.

What does Careful need to run?

Going by SKILL.md and its folder, Careful needs a shell for the scripts in its folder and the command-line tools its instructions call (git, docker and kubectl). Our summary lists: A Bash shell; Docker. Its frontmatter pre-approves these tools: Bash, Read.

Does Careful access the network?

SKILL.md contains no URLs. Its commands use git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Careful safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Careful use?

Careful is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Careful use?

About 545 tokens (SKILL.md is roughly 2.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Careful?

Skills that share tags, products or a category with Careful: Hypa (Hypabolic/Hypa, 212 stars), Tokf Run (mpecan/tokf, 199 stars), Alloy (grafana/skills, 282 stars) and Performing Container Security Scanning With Trivy (mukul975/Anthropic-Cybersecurity-Skills, 34k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Careful?

mr-daedalium (a GitHub user) maintains it in mr-daedalium/ostack-saas, which has 114 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on March 31, 2026.

Source: mr-daedalium/ostack-saas on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.