Full safety mode: destructive command warnings + directory-scoped edits.

MITAuto-check: notesDevelopment

Install Guard

skills CLI
$ npx skills add mr-daedalium/ostack-saas --skill guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install mr-daedalium/ostack-saas guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/mr-daedalium/ostack-saas.git skills-src && mkdir -p .claude/skills && cp -r skills-src/guard .claude/skills/guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guard
GitHub stars
114
Used in
1 other repo
Token cost
~720 tokens
SKILL.md length
203 words
Files
2
Skills in repo
23
Repo updated
First seen
Licence
MIT

At a glance

Full safety mode: destructive command warnings + directory-scoped edits.

  • Works in 2 steps: Resolve it to an absolute path → Ensure trailing slash and save to the…
  • Maximum safety when touching prod
  • SKILL.md covers Setup and What's protected
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Guard is an agent skill from mr-daedalium/ostack-saas. Full safety mode: destructive command warnings + directory-scoped edits. Combines /careful (warns before rm -rf, DROP TABLE, force-push, etc.) with /freeze (blocks edits outside a specified directory). Use for maximum safety when touching prod or debugging live systems. Use when asked to "guard mode", "full safety", "lock it down", or "maximum safety".

Its SKILL.md is about 720 tokens, which your agent loads only when the skill is triggered. The skill folder holds 1 other file.

It sits in Development. The repository describes itself as: ostack — AI-powered engineering team for Claude Code. Fork of gstack by Garry Tan. The licence is MIT.

When your agent uses it

  • Maximum safety when touching prod
  • Debugging live systems
  • Asked to guard mode

Example prompts

  • “guard mode”
  • “full safety”
  • “lock it down”
  • “/guard”

Requirements

  • Pre-approved tools (allowed-tools): Bash, Read, AskUserQuestion

Workflow steps

2 steps, taken from the first numbered list in SKILL.md.

  1. Resolve it to an absolute path
  2. Ensure trailing slash and save to the freeze state file

What it can do on your machine

Read from SKILL.md and the folder at commit a67256d. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash
    • Read
    • AskUserQuestion

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Guard loads about 720 tokens when it runs. Until then it costs about 90 tokens; SKILL.md has 203 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~90
When it runs · the whole SKILL.md, loaded when a task matches
~720

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Bash, Read, AskUserQuestion

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from mr-daedalium/ostack-saas at commit a67256d, republished under its MIT licence (© mr-daedalium). 203 words, ~720 tokens.

Download SKILL.mdSave it as .claude/skills/guard/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
guard
description
Full safety mode: destructive command warnings + directory-scoped edits. Combines /careful (warns before rm -rf, DROP TABLE, force-push, etc.) with /freeze (blocks edits outside a specified directory). Use for maximum safety when touching prod or debugging live systems. Use when asked to "guard mode", "full safety", "lock it down", or "maximum safety".
allowed-tools
Bash, Read, AskUserQuestion
version
0.1.0
<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly -->
<!-- Regenerate: bun run gen:skill-docs -->

/guard — Full Safety Mode

Activates both destructive command warnings and directory-scoped edit restrictions. This is the combination of /careful + /freeze in a single command.

Dependency note: This skill references hook scripts from the sibling /careful and /freeze skill directories. Both must be installed (they are installed together by the ostack setup script).

Setup

Ask the user which directory to restrict edits to. Use AskUserQuestion:

  • Question: "Guard mode: which directory should edits be restricted to? Destructive command warnings are always on. Files outside the chosen path will be blocked from editing."
  • Text input (not multiple choice) — the user types a path.

Once the user provides a directory path:

  1. Resolve it to an absolute path:
bash
FREEZE_DIR=$(cd "<user-provided-path>" 2>/dev/null && pwd)
echo "$FREEZE_DIR"
  1. Ensure trailing slash and save to the freeze state file:
bash
FREEZE_DIR="${FREEZE_DIR%/}/"
STATE_DIR="${CLAUDE_PLUGIN_DATA:-$HOME/.ostack}"
mkdir -p "$STATE_DIR"
echo "$FREEZE_DIR" > "$STATE_DIR/freeze-dir.txt"
echo "Freeze boundary set: $FREEZE_DIR"

Tell the user:

  • "Guard mode active. Two protections are now running:"
  • "1. Destructive command warnings — rm -rf, DROP TABLE, force-push, etc. will warn before executing (you can override)"
  • "2. Edit boundary — file edits restricted to <path>/. Edits outside this directory are blocked."
  • "To remove the edit boundary, run /unfreeze. To deactivate everything, end the session."

What's protected

See /careful for the full list of destructive command patterns and safe exceptions. See /freeze for how edit boundary enforcement works.

© mr-daedalium, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in guard of mr-daedalium/ostack-saas.

  • SKILL.md
  • SKILL.md.tmpl

Open the folder on GitHubat commit a67256d

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in mr-daedalium/ostack-saas, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guard this skillmr-daedalium/ostack-saas1141 repos~720Automated safety check: NotesMIT
Vercel Composition Patternssupabase/supabase111k58 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers297k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k4 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 58 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 4 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from mr-daedalium/ostack-saas

All 23 skills in this repo
  • Browse

    mr-daedalium/ostack-saas

    Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~5.3k tokens
    Auto-check: notes
  • Benchmark

    mr-daedalium/ostack-saas

    Performance regression detection using the browse daemon. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~5k tokens
    Auto-check: notes
  • Freeze

    mr-daedalium/ostack-saas

    Restrict file edits to a specific directory for the session.

    114 GitHub starsUsed in 1 repo~681 tokens
    Auto-check: notes
  • Ostack

    mr-daedalium/ostack-saas

    Fast headless browser for QA testing and site dogfooding. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub stars~6.1k tokensUpdated 6 mo ago
    Auto-check: notes
  • Investigate

    mr-daedalium/ostack-saas

    Systematic debugging with root cause investigation. An agent skill from mr-daedalium/ostack-saas.

    114 GitHub starsUsed in 1 repo~4.7k tokens
    Auto-check: notes
  • QA

    mr-daedalium/ostack-saas

    Systematically QA test a web application and fix bugs found.

    114 GitHub starsUsed in 1 repo~10k tokens
    Auto-check: notes

Categories

Questions about Guard

What does Guard do?

Full safety mode: destructive command warnings + directory-scoped edits. Guard is an agent skill from mr-daedalium/ostack-saas. Full safety mode: destructive command warnings + directory-scoped edits.

When should I use Guard?

Guard fits situations like: maximum safety when touching prod; debugging live systems; asked to guard mode.

How do I install Guard in Claude Code?

Run `npx skills add mr-daedalium/ostack-saas --skill guard -a claude-code`. Or copy the skill folder (guard in mr-daedalium/ostack-saas) into .claude/skills/guard in your project. Claude Code loads it when a task matches its description.

How do I install Guard in Codex?

Run `npx skills add mr-daedalium/ostack-saas --skill guard -a codex`. Or copy the skill folder (guard in mr-daedalium/ostack-saas) into .agents/skills/guard in your project. Codex loads it when a task matches its description.

Can I use Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add mr-daedalium/ostack-saas --skill guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guard, .gemini/skills/guard, .github/skills/guard and .opencode/skills/guard in your project.

What does Guard need to run?

SKILL.md names no scripts, command-line tools or credentials: Guard is instructions for the agent only. Its frontmatter pre-approves these tools: Bash, Read, AskUserQuestion.

Does Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Guard safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Guard use?

Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guard use?

About 720 tokens (SKILL.md is roughly 2.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Guard?

Skills that share tags, products or a category with Guard: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 297k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guard?

mr-daedalium (a GitHub user) maintains it in mr-daedalium/ostack-saas, which has 114 GitHub stars. The repository holds 23 skills in this directory. The repository was last updated on March 31, 2026.

Source: mr-daedalium/ostack-saas on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.