Agent skill

Careful

by yonatangross in yonatangross/orchestkit

Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE /…

MITAuto-check passedDevOps & Cloud

Install Careful

skills CLI
$ npx skills add yonatangross/orchestkit --skill careful -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yonatangross/orchestkit careful --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/careful .claude/skills/careful && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
careful
GitHub stars
292
Token cost
~1.2k tokens
SKILL.md length
554 words
Files
3 (incl. scripts)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE /…

  • Tasks that involve Infrastructure as code
  • SKILL.md covers What it blocks, When a command is blocked and Limits
  • Runs JavaScript scripts from its folder; calls git, terraform and kubectl
  • Tasks that involve Container orchestration

What it does

Careful is an agent skill from yonatangross/orchestkit. Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE / TRUNCATE, kubectl delete and terraform or tofu destroy, including inside ssh remote commands, and makes Claude ask the operator. Use before touching production, a shared branch, a live database or a cluster.

Its SKILL.md is about 1.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `test-cases.json`). Compatibility notes: Claude Code 2.1.277+.

It sits in DevOps & Cloud, covering Infrastructure as code, Container orchestration and Git workflow. It works with Git, Terraform, Kubernetes and Bash. The repository describes itself as: The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install ork for stable (v9.x), or ork-alpha for the v10 line, which ships daily. The licence is MIT.

When your agent uses it

  • Tasks that involve Infrastructure as code
  • Tasks that involve Container orchestration
  • Tasks that involve Git workflow

Example prompts

  • “Use the careful skill to block destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and…”
  • “/careful”

Requirements

  • Python 3
  • Node.js
  • Compatibility (from SKILL.md): Claude Code 2.1.277+.
  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit e4ff8d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • git
    • terraform
    • kubectl
    • bash
    • ssh
    • python
    • make
    • npm
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, kubectl, ssh and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Claude Code 2.1.277+.

    From compatibility in the SKILL.md frontmatter.

Context cost

Careful loads about 1.2k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 554 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~1.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from yonatangross/orchestkit at commit e4ff8d9, republished under its MIT licence (© yonatangross). 554 words, ~1,245 tokens.

Download SKILL.mdSave it as .claude/skills/careful/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
careful
description
Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE / TRUNCATE, kubectl delete and terraform or tofu destroy, including inside ssh remote commands, and makes Claude ask the operator. Use before touching production, a shared branch, a live database or a cluster.
allowed-tools
Read
compatibility
Claude Code 2.1.277+.
license
MIT
context
inherit
user-invocable
true
disable-model-invocation
true
metadata.category
workflow-automation
metadata.version
1.0.0
metadata.author
OrchestKit
metadata.complexity
low
metadata.tags
careful, guard, safety, destructive-commands, hooks, skill-scoped-hooks, production

careful, block destructive commands for this session

Invoking this skill registers a PreToolUse hook on Bash (the hooks: block above). Claude Code keeps a skill's hooks registered for the rest of the session, on every later turn, so careful stays on until the session ends. There is no off switch: start a new session to work without it.

What it blocks

RuleBlocksStill allowed
rm-rfrm with recursive and force flags (-rf, -fr, -r -f, --recursive --force), xargs rm -rf, and any target the shell expands: $TMPDIR/x, $TMP, $TEMP, $X, $( ), globs, braces, ~the same command when every target is a LITERAL absolute path that lands, after following existing symlinks, strictly inside /tmp, /private/tmp or the configured TMPDIR (trusted only when it is two or more levels deep); write /tmp/build, not $TMPDIR/build, because a command can reassign TMPDIR first (TMPDIR=/ ; rm -rf $TMPDIR/usr); rm -r; rm -f file
git-push-forcegit push --force, -f (also inside -uf), --force-with-lease[=...], a +branch refspec, to any branchgit push, git push -u origin <branch>
git-push-deletegit push origin --delete <b>, -d <b>, :<b>git push origin <b>:<b>
git-reset-hardgit reset --hardgit reset --soft, git reset HEAD <file>
sql-dropDROP TABLE, DROP DATABASE, DROP SCHEMA anywhere in the command, heredocs includeda SELECT that mentions drop
sql-truncateTRUNCATE TABLE, or a TRUNCATE <name> statement sent to a SQL clienttruncate -s 0 file.log
kubectl-deletekubectl ... deletekubectl get, kubectl logs
terraform-destroyterraform destroy, terraform apply -destroy, the same with tofuterraform plan, terraform apply

Matching is on shell words, not substrings: a commit message or grep pattern that quotes git push --force is text, not a push. Compound commands are split on ;, &&, | and newlines, and the bodies of bash -c, eval, $( ) and the remote command of ssh host '...' are checked as well.

When a command is blocked

The hook exits 2 and Claude sees the reason, for example:

[ork:careful] blocked by rule git-push-force: git push with --force-with-lease.
careful mode is on for this session, so destructive commands do not run unattended.
To proceed, ask the operator: they can run the command themselves, or confirm it and run it outside careful mode.

Then stop and ask. Do not rewrite the command to slip past the matcher (a different flag spelling, a script file, an alias): the operator turned careful on to be asked, and a workaround defeats that even when the matcher misses it.

Show full SKILL.md (198 more words)Show less

Limits

careful is a pattern matcher on the text of each Bash call. It is a seatbelt, not a sandbox. It does NOT see:

  • shell aliases and functions (alias nuke='rm -rf', then nuke src);

  • scripts, Makefiles, npm scripts or binaries that run these commands inside (./deploy.sh, make clean, npm run reset-db);

  • eval or bash -c built from variables, base64 or other indirection it cannot read as text; it only reads literal strings;

  • interpreters and other shells running the same thing (python -c "shutil.rmtree(...)", node -e, fish -c, pwsh), or a remote shell other than plain ssh host '...';

  • a link created in the same command (ln -s / /tmp/r9 && rm -rf /tmp/r9/usr): the guard follows links that already exist when it runs (a temp path through a link to /usr is denied), but one made by the command itself is out of reach for a text check, like python -c "shutil.rmtree(...)";

  • MCP tools, file edits, and anything outside the Bash tool.

  • If the hook cannot read its input it blocks (exit 2) rather than guess.

  • To also fence file edits to one directory, use the freeze skill.

The guard is scripts/careful-guard.mjs (Node, no dependencies); its matcher cases live in tests/unit/test-careful-guard.mjs.

© yonatangross, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in src/skills/careful of yonatangross/orchestkit.

  • SKILL.md
  • scripts/careful-guard.mjs
  • test-cases.json

Open the folder on GitHubat commit e4ff8d9

Compare with similar skills

Careful next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Careful compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Careful this skillyonatangross/orchestkit292—~1.2kAutomated safety check: PassMIT
Asdfjjmartres/opencode133—~2.1kAutomated safety check: NotesMIT
Eks Best Practicesaws-samples/appmod-blueprints115—~5kAutomated safety check: PassMIT-0
Supercheck Infrastructure Deploymentsupercheck-io/supercheck215—~1.4kAutomated safety check: NotesAGPL-3.0
Cloud Devopsdavila7/claude-code-templates33k4 repos~1.4kAutomated safety check: PassMIT
Infrastructuremicrosoft/physical-ai-toolchain126—~1.6kAutomated safety check: PassMIT

Similar skills

  • Asdf

    jjmartres/opencode

    A skill your agent uses whenever the user wants to install, configure, or use asdf (asdf-vm), the universal version manager.

    133 GitHub stars~2.1k tokensUpdated 5 mo ago
    DevOps & CloudAuto-check: notes
  • Eks Best Practices

    aws-samples/appmod-blueprints

    Official

    Advisory guidance for Amazon EKS architecture and configuration decisions — compute strategy, networking, security, reliability, cost, autoscaling, observability, multi-tenancy, and upgrade planning.

    115 GitHub stars~5k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Supercheck Infrastructure Deployment

    supercheck-io/supercheck

    Work on Supercheck Docker Compose, K3s, Kubernetes manifests, gVisor, OpenTofu/Hetzner, secrets, external services, autoscaling, backups, disaster recovery, DNS/TLS, or production deployment.

    215 GitHub stars~1.4k tokensUpdated yesterday
    DevOps & CloudAuto-check: notes
  • Cloud Devops

    davila7/claude-code-templates

    Cloud infrastructure and DevOps workflow covering AWS, Azure, GCP, Kubernetes, Terraform, CI/CD, monitoring, and cloud-native development.

    33k GitHub starsUsed in 4 repos~1.4k tokens
    DevOps & CloudAuto-check passed
  • Infrastructure

    microsoft/physical-ai-toolchain

    Official

    Deploy and manage Azure infrastructure for the Physical AI Toolchain including Terraform IaC, Kubernetes setup, GPU configuration, and network topology

    126 GitHub stars~1.6k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Oci

    oracle/skills

    Official

    Oracle Cloud Infrastructure guidance for designing, operating, and troubleshooting OCI services, including OCI Kubernetes Engine (OKE), OCI Internet of Things Platform, OCI Functions deployment and…

    877 GitHub stars~2.4k tokensUpdated yesterday
    DevOps & CloudAuto-check passed

More from yonatangross/orchestkit

All 108 skills in this repo
  • API Design

    yonatangross/orchestkit

    API contract design for REST and GraphQL, covering resource shape, URL and header versioning with deprecation windows, RFC 9457 Problem Details error handling, and OpenAPI specs.

    292 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Architecture Decision Record

    yonatangross/orchestkit

    ADR templates in the Nygard format with context, decision, consequences, and alternatives.

    292 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Audit Full

    yonatangross/orchestkit

    Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.

    292 GitHub stars~3.5k tokensUpdated today
    Auto-check: notes
  • Code Review Playbook

    yonatangross/orchestkit

    Structured review processes, conventional comments, language-specific checklists, and feedback templates.

    292 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Create PR

    yonatangross/orchestkit

    Creates GitHub pull requests with pre-flight validation, conventional title formatting, and structured summary generation.

    292 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Explore

    yonatangross/orchestkit

    Multi-angle codebase exploration spawning 3-5 parallel agents for code structure, data flow, architecture patterns, and health assessment.

    292 GitHub stars~3.9k tokensUpdated today
    Auto-check: notes

Categories

Questions about Careful

What does Careful do?

Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE /…. Careful is an agent skill from yonatangross/orchestkit. Blocks destructive shell commands once invoked: a PreToolUse Bash guard denies rm -rf outside temp dirs, force pushes and remote branch deletes, git reset --hard, DROP TABLE / DROP DATABASE / TRUNCATE, kubectl delete and terraform or tofu destroy, including inside ssh remote commands, and makes Claude ask the operator.

When should I use Careful?

Careful fits situations like: tasks that involve Infrastructure as code; tasks that involve Container orchestration; tasks that involve Git workflow.

How do I install Careful in Claude Code?

Run `npx skills add yonatangross/orchestkit --skill careful -a claude-code`. Or copy the skill folder (src/skills/careful in yonatangross/orchestkit) into .claude/skills/careful in your project. Claude Code loads it when a task matches its description.

How do I install Careful in Codex?

Run `npx skills add yonatangross/orchestkit --skill careful -a codex`. Or copy the skill folder (src/skills/careful in yonatangross/orchestkit) into .agents/skills/careful in your project. Codex loads it when a task matches its description.

Can I use Careful in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yonatangross/orchestkit --skill careful -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/careful, .gemini/skills/careful, .github/skills/careful and .opencode/skills/careful in your project.

What does Careful need to run?

Going by SKILL.md and its folder, Careful needs JavaScript for the scripts in its folder and the command-line tools its instructions call (git, terraform, kubectl, bash, ssh and python). Our summary lists: Python 3; Node.js. Its frontmatter pre-approves these tools: Read. Compatibility (from SKILL.md): Claude Code 2.1.277+..

Does Careful access the network?

SKILL.md contains no URLs. Its commands use git, ssh and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Careful safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Careful use?

Careful is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Careful use?

About 1.2k tokens (SKILL.md is roughly 5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Careful?

Skills that share tags, products or a category with Careful: Asdf (jjmartres/opencode, 133 stars), Eks Best Practices (aws-samples/appmod-blueprints, 115 stars), Supercheck Infrastructure Deployment (supercheck-io/supercheck, 215 stars) and Cloud Devops (davila7/claude-code-templates, 33k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Careful?

yonatangross (a GitHub user) maintains it in yonatangross/orchestkit, which has 292 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 10, 2026.

Source: yonatangross/orchestkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.