Agent skill

Safe Mode

by rohitg00 in rohitg00/pro-workflow

Prevent destructive operations using Claude Code hooks. An agent skill from rohitg00/pro-workflow.

No licenceAuto-check: notesAgent Workflows

Install Safe Mode

skills CLI
$ npx skills add rohitg00/pro-workflow --skill safe-mode -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install rohitg00/pro-workflow safe-mode --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/rohitg00/pro-workflow.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/safe-mode .claude/skills/safe-mode && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
safe-mode
GitHub stars
2.9k
Token cost
~1.4k tokens
SKILL.md length
616 words
Files
1
Skills in repo
41
Repo updated
First seen
Licence
None found

At a glance

Prevent destructive operations using Claude Code hooks. An agent skill from rohitg00/pro-workflow.

  • Works in 3 steps: Set the allowed path (absolute or… → Every Edit/Write call checks if the… → Operations outside the path are blocked…
  • Tasks that involve Human-in-the-loop approvals
  • SKILL.md covers Modes, Implementation, Combining Modes and When to Use, plus 1 more section
  • Calls git and node

What it does

Safe Mode is an agent skill from rohitg00/pro-workflow. Prevent destructive operations using Claude Code hooks. Three modes — cautious (warn on dangerous commands), lockdown (restrict edits to one directory), and clear (remove restrictions). Uses PreToolUse matchers for Bash, Edit, and Write.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Agent Workflows, covering Human-in-the-loop approvals and Hooks and plugins. It works with Bash and Git. The repository describes itself as: Claude Code learns from your corrections: self-correcting memory that compounds over 50+ sessions. Context engineering, parallel worktrees, agent teams, and 17 battle-tested…

When your agent uses it

  • Tasks that involve Human-in-the-loop approvals
  • Tasks that involve Hooks and plugins

Example prompts

  • “/safe-mode”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Set the allowed path (absolute or relative to repo root)
  2. Every Edit/Write call checks if the target file is inside the allowed path
  3. Operations outside the path are blocked with an explanation

What it can do on your machine

Read from SKILL.md and the folder at commit 86d5f27. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Safe Mode loads about 1.4k tokens when it runs. Until then it costs about 62 tokens; SKILL.md has 616 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~62
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteRuns commands with sudoSKILL.md:44
    | `sudo rm` | Elevated deletion |
  • NoteRuns commands with sudoSKILL.md:110
    ell, disk-level writes, fork bombs, and `sudo rm`. A match returns `permissionDecision: "ask"` with the pattern as the r

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 616 words (~1,421 tokens).

“Three levels of protection against destructive operations during AI coding sessions.”

— opening of SKILL.md by rohitg00
name
safe-mode
user-invocable
true

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/safe-mode of rohitg00/pro-workflow.

Open the folder on GitHubat commit 86d5f27

Compare with similar skills

Safe Mode next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Safe Mode compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Safe Mode this skillrohitg00/pro-workflow2.9k—~1.4kAutomated safety check: NotesNone
Fewer Permission Promptsasgeirtj/system_prompts_leaks69k—~1.9kAutomated safety check: PassCC0-1.0
Careful Mode Command Guardrailsgarrytan/gstack136k—~931Automated safety check: NotesMIT
Hns Moaiadk Dev Referencemodu-ai/moai-adk1.2k—~937Automated safety check: PassApache-2.0
Hook Development for Claude Code Pluginsanthropics/claude-plugins-official38k11 repos~4.1kAutomated safety check: NotesApache-2.0
Plugin Settings Patternanthropics/claude-plugins-official38k7 repos~3kAutomated safety check: PassApache-2.0

Similar skills

  • Fewer Permission Prompts

    asgeirtj/system_prompts_leaks

    Scan your transcripts for common read-only Bash and MCP tool calls, then add a prioritized allowlist to project .claude/settings.json to reduce permission prompts.

    69k GitHub stars~1.9k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Checks each shell command for destructive patterns such as recursive deletes, force pushes and dropped tables, and asks before letting them run.

    136k GitHub stars~931 tokensUpdated today
    SecurityAuto-check: notes
  • moai-adk-go local dev reference — version management/release process (sec 5), shell-script hook development (sec 7), build & dev commands (sec 10).

    1.2k GitHub stars~937 tokensUpdated today
    DevelopmentAuto-check passed
  • Hook Development for Claude Code Plugins

    anthropics/claude-plugins-official

    Official

    Explains how to write Claude Code plugin hooks, both prompt-based checks and bash commands, for events such as PreToolUse, Stop and SessionStart.

    38k GitHub starsUsed in 11 repos~4.1k tokens
    Agent WorkflowsAuto-check: notes
  • Plugin Settings Pattern

    anthropics/claude-plugins-official

    Official

    Shows how Claude Code plugins keep per-project settings and state in .claude/plugin-name.local.md files with YAML frontmatter and a markdown body.

    38k GitHub starsUsed in 7 repos~3k tokens
    Agent WorkflowsAuto-check passed
  • Darwin Skill Optimizer

    alchaincyf/darwin-skill

    Scores SKILL.md files on a nine-dimension rubric, then improves them in a keep-or-revert loop with independent judge agents, test prompts, git history and human checkpoints.

    6.2k GitHub starsUsed in 1 repo~4.7k tokens
    Agent WorkflowsAuto-check passed

More from rohitg00/pro-workflow

All 41 skills in this repo
  • Survey Generator

    rohitg00/pro-workflow

    Compile a structured literature survey on any AI/ML topic. An agent skill from rohitg00/pro-workflow.

    2.9k GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed
  • Wiki Builder

    rohitg00/pro-workflow

    Start, structure, and grow a persistent research wiki indexed in pro-workflow's SQLite knowledge base.

    2.9k GitHub stars~1k tokensUpdated 9 days ago
    Auto-check passed
  • Wiki Query

    rohitg00/pro-workflow

    Query pro-workflow wikis via SQLite FTS5 BM25 retrieval. An agent skill from rohitg00/pro-workflow.

    2.9k GitHub starsUsed in 1 repo~554 tokens
    Auto-check passed
  • LLM Council

    rohitg00/pro-workflow

    Provider-agnostic multi-LLM deliberation. An agent skill from rohitg00/pro-workflow.

    2.9k GitHub stars~1.1k tokensUpdated 9 days ago
    Auto-check passed
  • Wiki Research Loop

    rohitg00/pro-workflow

    Auto-grow a pro-workflow wiki by running a budget-capped BFS research loop over pluggable source fetchers (web, arXiv, GitHub).

    2.9k GitHub stars~1.5k tokensUpdated 9 days ago
    Auto-check passed
  • Insights

    rohitg00/pro-workflow

    Show session analytics, learning patterns, correction trends, heatmaps, and productivity metrics.

    2.9k GitHub starsUsed in 1 repo~719 tokens
    Auto-check passed

Works with

Categories

Questions about Safe Mode

What does Safe Mode do?

Prevent destructive operations using Claude Code hooks. An agent skill from rohitg00/pro-workflow. Safe Mode is an agent skill from rohitg00/pro-workflow. Prevent destructive operations using Claude Code hooks.

When should I use Safe Mode?

Safe Mode fits situations like: tasks that involve Human-in-the-loop approvals; tasks that involve Hooks and plugins.

How do I install Safe Mode in Claude Code?

Run `npx skills add rohitg00/pro-workflow --skill safe-mode -a claude-code`. Or copy the skill folder (skills/safe-mode in rohitg00/pro-workflow) into .claude/skills/safe-mode in your project. Claude Code loads it when a task matches its description.

How do I install Safe Mode in Codex?

Run `npx skills add rohitg00/pro-workflow --skill safe-mode -a codex`. Or copy the skill folder (skills/safe-mode in rohitg00/pro-workflow) into .agents/skills/safe-mode in your project. Codex loads it when a task matches its description.

Can I use Safe Mode in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add rohitg00/pro-workflow --skill safe-mode -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/safe-mode, .gemini/skills/safe-mode, .github/skills/safe-mode and .opencode/skills/safe-mode in your project.

What does Safe Mode need to run?

Going by SKILL.md and its folder, Safe Mode needs the command-line tools its instructions call (git and node).

Does Safe Mode access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Safe Mode safe to install?

Our automated static check of SKILL.md found notes only (runs commands with sudo), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Safe Mode use?

No licence was found for Safe Mode or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Safe Mode use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Safe Mode?

Skills that share tags, products or a category with Safe Mode: Fewer Permission Prompts (asgeirtj/system_prompts_leaks, 69k stars), Careful Mode Command Guardrails (garrytan/gstack, 136k stars), Hns Moaiadk Dev Reference (modu-ai/moai-adk, 1.2k stars) and Hook Development for Claude Code Plugins (anthropics/claude-plugins-official, 38k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Safe Mode?

rohitg00 (a GitHub user) maintains it in rohitg00/pro-workflow, which has 2,906 GitHub stars. The repository holds 41 skills in this directory. The repository was last updated on September 29, 2026.

Source: rohitg00/pro-workflow on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.