Agent skill

Freeze

by yonatangross in yonatangross/orchestkit

Confines file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose real location, symlinks followed, falls outside the frozen dir.

MITAuto-check passedDevelopment

Install Freeze

skills CLI
$ npx skills add yonatangross/orchestkit --skill freeze -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install yonatangross/orchestkit freeze --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/yonatangross/orchestkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/src/skills/freeze .claude/skills/freeze && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
freeze
GitHub stars
292
Token cost
~867 tokens
SKILL.md length
359 words
Files
3 (incl. scripts)
Skills in repo
108
Repo updated
First seen
Licence
MIT

At a glance

Confines file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose real location, symlinks followed, falls outside the frozen dir.

  • A change must stay inside one package
  • SKILL.md covers How it works, Usage, When an edit is blocked and Limits
  • Runs JavaScript scripts from its folder; calls node
  • Tasks that involve Git worktrees

What it does

Freeze is an agent skill from yonatangross/orchestkit. Confines file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose real location, symlinks followed, falls outside the frozen dir. Argument: the dir, or off. Use when a change must stay inside one package, module or worktree.

Its SKILL.md is about 870 tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including scripts (for example `test-cases.json`). Compatibility notes: Claude Code 2.1.277+.

It sits in Development, covering Git worktrees. It works with Bash. The repository describes itself as: The Complete AI Development Toolkit for Claude Code. 106 skills, 36 agents, 171 hooks. Install ork for stable (v9.x), or ork-alpha for the v10 line, which ships daily. The licence is MIT.

When your agent uses it

  • A change must stay inside one package
  • Tasks that involve Git worktrees

Example prompts

  • “Use the freeze skill to confine file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose…”
  • “/freeze”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Claude Code 2.1.277+.
  • Pre-approved tools (allowed-tools): Bash(node *freeze-guard.mjs arm *), Read

What it can do on your machine

Read from SKILL.md and the folder at commit e4ff8d9. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Bash(node *freeze-guard.mjs arm *)
    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Claude Code 2.1.277+.

    From compatibility in the SKILL.md frontmatter.

Context cost

Freeze loads about 867 tokens when it runs. Until then it costs about 72 tokens; SKILL.md has 359 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~72
When it runs · the whole SKILL.md, loaded when a task matches
~867

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from yonatangross/orchestkit at commit e4ff8d9, republished under its MIT licence (© yonatangross). 359 words, ~867 tokens.

Download SKILL.mdSave it as .claude/skills/freeze/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
freeze
description
Confines file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose real location, symlinks followed, falls outside the frozen dir. Argument: the dir, or off. Use when a change must stay inside one package, module or worktree.
allowed-tools
Bash(node *freeze-guard.mjs arm *), Read
compatibility
Claude Code 2.1.277+.
license
MIT
argument-hint
<dir> | off
context
inherit
user-invocable
true
disable-model-invocation
true
metadata.category
workflow-automation
metadata.version
1.0.0
metadata.author
OrchestKit
metadata.complexity
low
metadata.tags
freeze, guard, scope, edit-fence, hooks, skill-scoped-hooks, symlink

freeze, keep edits inside one directory

State for this session:

!node "${CLAUDE_SKILL_DIR}/scripts/freeze-guard.mjs" arm "${CLAUDE_PROJECT_DIR}" "${CLAUDE_SESSION_ID}" "$ARGUMENTS"

The line above ran when the skill was invoked: it resolved the argument against the project dir, followed symlinks, and recorded the real path for this session in .claude/state/freeze/<session-id>.json. The argument is double-quoted, so a name with spaces or an apostrophe arrives as typed; a $, backtick or double quote in a dir name would be interpreted by the shell and is not supported. Report that line to the operator as it reads. If it says NOT changed, the freeze did not move; say so and stop.

How it works

Invoking this skill also registers a PreToolUse hook on Edit|Write|MultiEdit|NotebookEdit (the hooks: block above). Claude Code keeps a skill's hooks registered for the rest of the session, so the fence holds on every later turn. For each edit the hook resolves where the write would actually land and denies it (exit 2) when that is outside the frozen dir:

TargetVerdict
<frozen>/a.ts, or a new file in a new subdir of <frozen>allowed
<frozen>/../other/b.tsdenied
<frozen>-evil/x.ts (a prefix sibling)denied
<frozen>/link/b.ts where link points outsidedenied, symlinks are followed
<frozen>/dangling.ts, a link to a missing file outsidedenied, the link is chased
an edit call with no pathdenied
Show full SKILL.md (145 more words)Show less

Usage

/ork:freeze src/hooks        # fence edits to src/hooks
/ork:freeze                  # show the current fence
/ork:freeze off              # lift it

Invoking again with another dir moves the fence; a dir that does not exist is refused and the previous fence stays.

When an edit is blocked

The deny reason names the target and the frozen dir. Stop and ask the operator to widen or lift the freeze. Do not route the change through Bash (sed -i, cat >, cp) instead: the fence covers the edit tools only, and using Bash to get around it defeats the reason it was turned on.

Limits

  • Edit tools only. Bash, MCP tools and subprocesses can still write anywhere. Pair with careful for destructive shell commands, or with a worktree for real isolation.
  • One fence per session, stored under the project's .claude/state/freeze/.
  • If the hook cannot read its input or the state file it blocks rather than guess.

The fence is scripts/freeze-guard.mjs (Node, no dependencies); its cases live in tests/unit/test-freeze-guard.mjs.

© yonatangross, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (scripts) in src/skills/freeze of yonatangross/orchestkit.

  • SKILL.md
  • scripts/freeze-guard.mjs
  • test-cases.json

Open the folder on GitHubat commit e4ff8d9

Compare with similar skills

Freeze next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Freeze compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Freeze this skillyonatangross/orchestkit292—~867Automated safety check: PassMIT
Cursor Composer Task DelegateChachamaru127/claude-code-harness3.2k—~4.4kAutomated safety check: NotesMIT
Worktree Cleanupvchelaru/FlatRedBall578—~810Automated safety check: PassMIT
Knowledge Shell Process And WorktreeechoVic/blade-code181—~1.7kAutomated safety check: PassMIT
Rust Build Hygienenubjs/nub4.4k—~2.2kAutomated safety check: PassMIT
Knowledge Tool And Automation PlatformechoVic/blade-code181—~1.4kAutomated safety check: PassMIT

Similar skills

  • Cursor Composer Task Delegate

    Chachamaru127/claude-code-harness

    Hands one implementation task to Cursor Composer in an isolated git worktree, then reviews its diff and cherry-picks the result into the main branch.

    3.2k GitHub stars~4.4k tokensUpdated 5 days ago
    DevelopmentAuto-check: notes
  • Worktree Cleanup

    vchelaru/FlatRedBall

    Remove a subagent's .claude/worktrees/agent-<id dir after its PR merges.

    578 GitHub stars~810 tokensUpdated today
    DevelopmentAuto-check passed
  • Covers Bash 前后台执行、stdin/终止、输出有界化、进程树与持久租约、Workspace 写沙箱,以及托管 Git worktree 的隔离和交付。

    181 GitHub stars~1.7k tokensUpdated today
    DevelopmentAuto-check passed
  • Best practices for spinning up nub Rust builds so they are PERFORMANT and CLEAN THEMSELVES UP — the prevention side of the recurring orphaned-build problem on the maintainer's dev host.

    4.4k GitHub stars~2.2k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Covers Blade 工具契约、注册与执行,以及文件、搜索、Shell、worktree、Browser 和领域适配工具的协作边界。

    181 GitHub stars~1.4k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    297k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed

More from yonatangross/orchestkit

All 108 skills in this repo
  • API Design

    yonatangross/orchestkit

    API contract design for REST and GraphQL, covering resource shape, URL and header versioning with deprecation windows, RFC 9457 Problem Details error handling, and OpenAPI specs.

    292 GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Architecture Decision Record

    yonatangross/orchestkit

    ADR templates in the Nygard format with context, decision, consequences, and alternatives.

    292 GitHub stars~2k tokensUpdated today
    Auto-check passed
  • Audit Full

    yonatangross/orchestkit

    Single-pass codebase analysis leveraging a 1M-token context window for comprehensive security scanning, architecture review, and dependency auditing.

    292 GitHub stars~3.5k tokensUpdated today
    Auto-check: notes
  • Code Review Playbook

    yonatangross/orchestkit

    Structured review processes, conventional comments, language-specific checklists, and feedback templates.

    292 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Create PR

    yonatangross/orchestkit

    Creates GitHub pull requests with pre-flight validation, conventional title formatting, and structured summary generation.

    292 GitHub stars~4.5k tokensUpdated today
    Auto-check: notes
  • Explore

    yonatangross/orchestkit

    Multi-angle codebase exploration spawning 3-5 parallel agents for code structure, data flow, architecture patterns, and health assessment.

    292 GitHub stars~3.9k tokensUpdated today
    Auto-check: notes

Works with

Categories

Questions about Freeze

What does Freeze do?

Confines file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose real location, symlinks followed, falls outside the frozen dir. Freeze is an agent skill from yonatangross/orchestkit. Confines file edits to one directory until lifted: an Edit, Write, MultiEdit and NotebookEdit hook refuses any path whose real location, symlinks followed, falls outside the frozen dir.

When should I use Freeze?

Freeze fits situations like: A change must stay inside one package; tasks that involve Git worktrees.

How do I install Freeze in Claude Code?

Run `npx skills add yonatangross/orchestkit --skill freeze -a claude-code`. Or copy the skill folder (src/skills/freeze in yonatangross/orchestkit) into .claude/skills/freeze in your project. Claude Code loads it when a task matches its description.

How do I install Freeze in Codex?

Run `npx skills add yonatangross/orchestkit --skill freeze -a codex`. Or copy the skill folder (src/skills/freeze in yonatangross/orchestkit) into .agents/skills/freeze in your project. Codex loads it when a task matches its description.

Can I use Freeze in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add yonatangross/orchestkit --skill freeze -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/freeze, .gemini/skills/freeze, .github/skills/freeze and .opencode/skills/freeze in your project.

What does Freeze need to run?

Going by SKILL.md and its folder, Freeze needs JavaScript for the scripts in its folder and the command-line tools its instructions call (node). Our summary lists: Node.js. Its frontmatter pre-approves these tools: Bash(node *freeze-guard.mjs arm *), Read. Compatibility (from SKILL.md): Claude Code 2.1.277+..

Does Freeze access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Freeze safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Freeze use?

Freeze is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Freeze use?

About 867 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Freeze?

Skills that share tags, products or a category with Freeze: Cursor Composer Task Delegate (Chachamaru127/claude-code-harness, 3.2k stars), Worktree Cleanup (vchelaru/FlatRedBall, 578 stars), Knowledge Shell Process And Worktree (echoVic/blade-code, 181 stars) and Rust Build Hygiene (nubjs/nub, 4.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Freeze?

yonatangross (a GitHub user) maintains it in yonatangross/orchestkit, which has 292 GitHub stars. The repository holds 108 skills in this directory. The repository was last updated on October 10, 2026.

Source: yonatangross/orchestkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.