Agent skill

Guardrail Patterns

by ZaxbyHub in ZaxbyHub/opencode-swarm

Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()

MITAuto-check passedAI & LLM Engineering

Install Guardrail Patterns

skills CLI
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patterns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .claude/skills/guardrail-patterns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
guardrail-patterns
GitHub stars
494
Token cost
~3.5k tokens
SKILL.md length
1,007 words
Files
1
Skills in repo
91
Repo updated
First seen
Licence
MIT

At a glance

Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()

  • Works in 5 steps: Determine the pattern placement → Choose the regex pattern structure → Handle all platform variants → …
  • Tasks that involve LLM guardrails
  • SKILL.md covers When to load this skill, Architecture overview, Adding a new guardrail block and Known bypass surfaces (must…, plus 4 more sections
  • Calls sh, rsync and git

What it does

Guardrail Patterns is an agent skill from ZaxbyHub/opencode-swarm. Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()

Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in AI & LLM Engineering, covering LLM guardrails. It works with Bash. The repository describes itself as: Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review. The licence is MIT.

When your agent uses it

  • Tasks that involve LLM guardrails

Example prompts

  • “/guardrail-patterns”

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Determine the pattern placement
  2. Choose the regex pattern structure
  3. Handle all platform variants
  4. Handle the .swarm path separator
  5. Handle backslash-prefixed command evasion

What it can do on your machine

Read from SKILL.md and the folder at commit b63a4bd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • sh
    • rsync
    • git
    • bash
    • kubectl
    • docker
    • bun
    • bunx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use rsync, git, kubectl, docker and bunx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Guardrail Patterns loads about 3.5k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,007 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~42
When it runs · the whole SKILL.md, loaded when a task matches
~3.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ZaxbyHub/opencode-swarm at commit b63a4bd, republished under its MIT licence (© ZaxbyHub). 1,007 words, ~3,528 tokens.

Download SKILL.mdSave it as .claude/skills/guardrail-patterns/SKILL.md (or your agent's skills folder).
name
guardrail-patterns
description
Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()
source_knowledge_ids
00cc0fba-5ed8-4e2c-9a3c-96675e09d175, b02ac9d7-9f2b-4ac0-9afe-5ee5f35f54c3
generated_at
2026-06-22T00:00:00.000Z
status
active
version
2
skill_origin
generated
provenance_note
Re-linked to current knowledge entries (version 2). The original 4 source IDs (098926ef, 2c1e4689, 54c33fa4, 4f51d11a) are no longer present in the active…

Skill: Guardrail Patterns for opencode-swarm

Source knowledge: 098926ef, 2c1e4689, 54c33fa4, 4f51d11a

Load this skill before modifying src/hooks/guardrails.ts — adding, removing, or changing guardrail blocks in checkDestructiveCommand(). It documents the pattern structure, known bypass surfaces, regex anti-patterns, and test conventions used across 41 guardrail test files and the ~3900-line guardrails.ts file.

When to load this skill

Load before any change to:

  • src/hooks/guardrails.ts — especially checkDestructiveCommand() or dcNormalizeCommand()
  • tests/unit/hooks/guardrails*.test.ts — any guardrail test file
  • Adding a new section (currently Sections 1–22) to checkDestructiveCommand()
  • Adding regex patterns for shell command blocking

Architecture overview

checkDestructiveCommand() — the shell command guard

Located at src/hooks/guardrails.ts (line 1304). This is the only function that blocks destructive shell commands. It is invoked by the toolBefore hook in guardrails.ts before every bash or shell tool call.

Pipeline (in order):

  1. dcNormalizeCommand() (line ~627) — NFKC normalization + evasion collapse: collapses "" (doubled double-quotes) and '' (doubled single-quotes). Single-quote splice like m'v' remains OPEN.
  2. dcStripOneWrapper() (line ~664) — detects and strips individual shell wrappers: bash, sh, zsh, dash, fish, pwsh, powershell, cmd (with -c/-Command), sudo, nohup, time, nice, env VAR=val, call (batch), Invoke-Command -ScriptBlock, & { } script blocks, wsl, iex
  3. dcUnwrapWrappers() (line ~737) — loops dcStripOneWrapper until no more wrappers remain (max depth 10)
  4. dcSplitSegments() (line ~753) — splits compound commands on &&, ;, |, newlines
  5. Per-segment loop — each segment evaluated against 22+ guardrail sections
  6. dcValidateTargets() — runtime lstat-ancestor walk on destructive targets
Key normalization functions
FunctionLineWhat it normalizes
dcNormalizeCommand~627NFKC, caret escapes (^), backtick escapes, collapsed "" and ''
dcStripOneWrapper~664Detects/strips a single shell wrapper (bash/sh/zsh/pwsh/cmd/powershell/wsl etc)
dcUnwrapWrappers~737Loops dcStripOneWrapper until no more wrappers (max depth 10)
dcSplitSegments~753Splits on &&, ;, `

Known wrapper unwrapping limitation: sh -c and bash -c with single-quoted inner commands (sh -c 'mv ...') are NOT unwrapped because dcStripOneWrapper uses "? (optional double-quote). Only double-quoted inner commands are properly stripped.

Adding a new guardrail block

Step 1 — Determine the pattern placement

Inside checkDestructiveCommand(), the per-segment for loop evaluates each segment against sections 1–22. A new section should be added after the last existing section and before the closing } of the for loop (currently after Section 22 at approximately line 1733).

Step 2 — Choose the regex pattern structure

There are three patterns used in the codebase:

Pattern A — Simple inline regex (single condition):

typescript
// Good for: single-command blocking with no complex extraction
if (/^blockedcommand\b.*\.swarm[\x5c/\s]?/i.test(seg)) {
  throw new Error(`BLOCKED: "blockedcommand" targeting .swarm/ detected — ...`);
}

Pattern B — Multi-condition (flag check + path check):

typescript
// Good for: archive tools with flags + .swarm/ path (prevents argument-order bypass)
if (
  /^toolname\b.*--dangerous-flag\b/i.test(seg) &&
  /\.swarm(?:[\x5c/\s]|$)/i.test(seg)
) {

This is recommended because it handles both tool --flag .swarm/path and tool .swarm/path --flag argument orders.

Pattern C — Argument extraction + stripped check:

typescript
// Good for: commands where you need argument isolation (e.g., `mv` with arg capture)
if (/^\\?command\s/i.test(seg)) {
  const match = seg.match(/^\\?command\s+(.+)$/i);
  if (match) {
    const argsStr = match[1].replace(/["']/g, '');
    if (/\.swarm(?:[\x5c/\s]|$)/.test(argsStr)) {
      throw new Error(`BLOCKED: ...`);
    }
  }
}
Step 3 — Handle all platform variants

POSIX, Windows cmd.exe, and PowerShell often use different commands for the same operation. All three must be covered:

typescript
// POSIX section
if (/^\\?posix-cmd\s/i.test(seg) && /\.swarm/i.test(strippedArgs)) { ... }

// Windows cmd section (case-insensitive, optional .exe)
if (/^\\?(?:cmd-cmd|cmd-cmd-alias)(?:\.exe)?\s/i.test(seg) && /\.swarm/i.test(argsStr)) { ... }

// PowerShell section (case-insensitive, all aliases)
if (/^\\?(?:PowerShell-Cmdlet|alias1|alias2)\b.*\.swarm/i.test(seg)) { ... }
Step 4 — Handle the .swarm path separator

Always use \x5c (backslash) for cross-platform path matching — \ alone is the regex escape character.

typescript
// Correct: matches both / and \
/\.swarm[\x5c/]/

// More complete: also matches .swarm followed by whitespace or end-of-string
// (catches whole-directory targeting like `mv .swarm /tmp/`)
/\.swarm(?:[\x5c/\s]|$)/
Step 5 — Handle backslash-prefixed command evasion

Commands prefixed with \ (e.g., \mv) bypass simple ^command\s anchors. Always add \\?:

typescript
// Correct: catches both mv and \mv
if (/^\\?mv\s/i.test(seg)) { ... }

// Correct for rm (uses \b instead of \s)
if (/^\\?rm\b/i.test(seg)) { ... }

Known bypass surfaces (must document in adversarial tests)

These are documented bypass vectors that the current regex-based approach cannot fully close. Every new guardrail section should include adversarial tests for these patterns:

EvasionExampleStatusMitigation
Backslash prefix\mv .swarm/fileCLOSEDAdd ^\\? to command anchor
Quote splicingm'v' .swarm/fileOPENRequires NFKC normalization change
Quoted command name"mv" .swarm/fileOPENRequires NFKC normalization change
Shell wrapper (double-quoted)sh -c "mv .swarm/file"CLOSEDdcUnwrapWrappers handles "
Shell wrapper (single-quoted)sh -c 'mv .swarm/file'OPENdcUnwrapWrappers regex uses "?
Relative path prefixmv ./swarm/fileOPENRequires path normalization
Env var expansionmv $SWARM_DIR/fileOPENRequires variable resolution
Unicode fullwidthmv .swarm/fileOPENRequires NFKC normalization

Regex anti-patterns (from prior bugs)

Anti-pattern 1: [^-] consuming path characters
typescript
// WRONG — [^-] consumes the first character of the path
if (/^rm\s+(?!\s*-)(?!-)[^-].*\.swarm/i.test(seg)) {
  // "rm .swarm/file" → [^-] consumes '.' → "swarm/file" doesn't match "\.swarm"
}

// CORRECT — use negative lookahead for flag exclusion
if (
  /^rm\b/i.test(seg) &&
  !/^rm\s+(?:-[a-zA-Z]*[rR][a-zA-Z]*|--recursive)\b/i.test(seg) &&
  /\.swarm(?:[\x5c/\s]|$)/i.test(seg)
) {
  // "rm .swarm/file" → BLOCKED ✓
  // "rm -rf .swarm/" → Section 3 handles ✓
  // "rm -v .swarm/file" → BLOCKED ✓
}
Anti-pattern 2: Negative lookahead too broad ((?!-\S))
typescript
// WRONG — (?!-\S) excludes ALL flag-prefixed rm commands,
// but Section 3 only catches recursive/force flags
if (/^rm\s+(?!-\S).*\.swarm/i.test(seg)) {
  // "rm -v .swarm/file" → NOT blocked by S19 (excluded by lookahead)
  // "rm -v .swarm/file" → NOT blocked by S3 (no -r/-f flags)
}

// CORRECT — use three-part condition
Anti-pattern 3: .exec() confused by SAST
typescript
// WRONG — SAST confuses RegExp.prototype.exec() with child_process.exec()
const match = /^command\s+(.+)$/i.exec(seg);  // SAST false positive

// CORRECT — use String.prototype.match()
const match = seg.match(/^command\s+(.+)$/i);  // No SAST false positive
Anti-pattern 4: Argument-order dependent patterns
typescript
// WRONG — .swarm/ must appear AFTER the flag in the command string
if (/^tool\b.*--flag\b.*\.swarm/i.test(seg)) {
  // "tool --flag .swarm/" → BLOCKED ✓
  // "tool .swarm/ --flag" → NOT BLOCKED ✗
}

// CORRECT — split flag check and path check
if (/^tool\b.*--flag\b/i.test(seg) && /\.swarm(?:[\x5c/\s]|$)/i.test(seg)) {
  // Both argument orders BLOCKED ✓
}

Test conventions

Test file structure
typescript
// Positive tests: "command → BLOCKED"
test('mv .swarm/evidence/file.json /tmp/ → BLOCKED', async () => { ... });

// Negative tests: "command → ALLOWED (reason)"
test('ls .swarm/evidence/ → ALLOWED (read-only)', async () => { ... });

// Bypass when feature is disabled
test('mv .swarm/file /tmp/ → ALLOWED when block_destructive_commands=false', async () => { ... });
Show full SKILL.md (403 more words)Show less
Test infrastructure pattern
typescript
import { mkdtempSync, realpathSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { createGuardrailsHooks } from '../../../src/hooks/guardrails';
import { resetSwarmState, startAgentSession } from '../../../src/state';

const TEST_DIR = realpathSync(mkdtempSync(join(tmpdir(), 'guardrail-pattern-')));

function defaultConfig(overrides?: Partial<GuardrailsConfig>): GuardrailsConfig {
  return {
    enabled: true,
    max_tool_calls: 200,
    max_duration_minutes: 30,
    idle_timeout_minutes: 60,
    max_repetitions: 10,
    max_consecutive_errors: 5,
    warning_threshold: 0.75,
    profiles: undefined,
    block_destructive_commands: true,
    ...overrides,
  };
}

function makeBashInput(sessionID = 'test-session', command: string) {
  // Note: command is accepted but passed to makeBashOutput, not makeBashInput
  return { tool: 'bash', sessionID, callID: 'call-1' };
}

function makeBashOutput(command: string) {
  return { args: { command } };
}
Required test categories

Every new guardrail section MUST have tests for:

  1. Positive — command targeting .swarm/ is blocked
  2. Negative — same command with non-.swarm/ path is allowed
  3. Read-only — read-only commands (ls, cat, find) are not blocked
  4. Config bypass — verified unblocked when block_destructive_commands: false
  5. Platform variants — POSIX, Windows cmd, PowerShell forms where applicable
  6. Adversarial — documented bypass surfaces (one test per known evasion type)
Key testing rules
  • Use bun:test only (no Jest/Vitest)
  • Use rejects.toThrow(/BLOCKED/) for positive assertions
  • Use resolves.toBeUndefined() for negative assertions
  • No hardcoded /tmp — use os.tmpdir() + mkdtempSync
  • No hardcoded C:\ strings
  • Wrap mkdtempSync in realpathSync for macOS compatibility

Section pattern reference (current guardrail sections 1–22)

| Section | Line | Commands blocked | Notes | |---|---|---|---|---| | 2 | ~1347 | Junction/symlink CREATION out-of-cwd | dcCheckJunctionCreation — creation of junctions/symlinks targeting outside cwd | | 3 | ~1353 | rm -r[Ff]*, rm -f -r, etc | Recursive + force only ([rRfF]+ flag set) | | 4 | ~1378 | rmdir /s, rd /s | Windows cmd, recursive | | 5 | ~1400 | del /s | Windows cmd | | 6–7 | ~1418 | Remove-Item -Recurse + pipeline form | PowerShell | | 8 | ~1457 | Ransomware-grade | vssadmin, wbadmin, diskpart, bcdedit, sdelete, fsutil, takeown, cipher, format, robocopy /MIR | | 9 | ~1510 | chmod -R 000, chattr +i, icacls /deny | Permission denial-of-service | | 10 | ~1529 | dd with /dev/zero/null/urandom | Data wipe | | 11 | ~1538 | Git destructive | push --force, reset --hard, reset --mixed, clean -fd, worktree remove --force | | 12 | ~1567 | rsync --delete(-before/-after/-during/-delay) | Mirror/sync with delete | | 13 | ~1576 | kubectl delete, docker system prune | Cluster/container | | 14 | ~1590 | DROP TABLE/DATABASE/SCHEMA, TRUNCATE TABLE | SQL DDL | | 15 | ~1604 | mkfs | Disk format | | 16 | ~1615 | mv | POSIX — blocked on .swarm/ | | 17 | ~1635 | move, ren | Windows cmd — blocked on .swarm\ | | 18 | ~1652 | Move-Item, Rename-Item, aliases | PowerShell — blocked on .swarm/ | | 19 | ~1667 | rm (non-recursive) | Blocked on .swarm/ (recursive → Section 3) | | 20 | ~1682 | cp + rm chain | Secondary defense (rm guard is primary) | | 21 | ~1697 | rsync --remove-source-files, tar --remove-files, zip -m, 7z -sdel | Archive tools with delete-source flags | | 22 | ~1728 | git clean -fd, git worktree remove --force | Verified existing patterns cover .swarm/ |

Task checklist for adding a new guardrail block

  • Pattern chosen (A/B/C) and placed in correct section order
  • Command anchor includes ^\\? (backslash prefix)
  • .swarm path check uses (?:[\x5c/\s]|$) (whole-root + subpath)
  • Argument-order independent (split flag check from path check)
  • Platform variants covered (POSIX + cmd + PowerShell)
  • .exec() → .match() to avoid SAST false positives
  • Positive test: .swarm/ path blocked
  • Negative test: non-.swarm/ path allowed
  • Read-only test: read commands not blocked
  • Config bypass test: block_destructive_commands: false
  • Adversarial tests: document known bypasses
  • bun run build succeeds
  • bunx biome ci . clean
  • All guardrail test suites pass

© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .opencode/skills/generated/guardrail-patterns of ZaxbyHub/opencode-swarm.

Open the folder on GitHubat commit b63a4bd

Compare with similar skills

Guardrail Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Guardrail Patterns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Guardrail Patterns this skillZaxbyHub/opencode-swarm494—~3.5kAutomated safety check: PassMIT
Writing Rulesathola/claude-night-market341—~1.4kAutomated safety check: NotesMIT
GuardHouseofmvps/ultraship123—~790Automated safety check: NotesMIT
Aisafetyhotwuyoscar/AISafetyHot-Hub708—~1.4kAutomated safety check: PassCustom licence
ObliteratusRedWoodOG/Hermes-Desktop1775 repos~3.8kAutomated safety check: PassMIT
Lemonade Router Builderamd/skills408—~4kAutomated safety check: PassMIT

Similar skills

  • Writing Rules

    athola/claude-night-market

    Creates behavioral rules in markdown to block dangerous commands or restrict AI behavior.

    341 GitHub stars~1.4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check: notes
  • Guard

    Houseofmvps/ultraship

    Safety guardrails — blocks destructive commands (rm -rf, DROP TABLE, force-push, git reset --hard) and optionally restricts file edits to a specific directory.

    123 GitHub stars~790 tokensUpdated 3 mo ago
    AI & LLM EngineeringAuto-check: notes
  • Aisafetyhot

    wuyoscar/AISafetyHot-Hub

    Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.

    708 GitHub stars~1.4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Obliteratus

    RedWoodOG/Hermes-Desktop

    Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…

    177 GitHub starsUsed in 5 repos~3.8k tokens
    AI & LLM EngineeringAuto-check passed
  • Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.

    408 GitHub stars~4k tokensUpdated yesterday
    AI & LLM EngineeringAuto-check passed
  • Official

    Builds reusable command line scripts that fetch, enrich or process data from the Hugging Face API, aimed at chained, repeated or automated tasks.

    11k GitHub starsUsed in 2 repos~1.5k tokens
    AI & LLM EngineeringAuto-check passed

More from ZaxbyHub/opencode-swarm

All 91 skills in this repo
  • Codebase Review Swarm

    ZaxbyHub/opencode-swarm

    Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.

    494 GitHub stars~2.8k tokensUpdated today
    Auto-check passed
  • Issue Tracer

    ZaxbyHub/opencode-swarm

    Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.

    494 GitHub stars~4.4k tokensUpdated today
    Auto-check passed
  • Commit and PR Publishing for Codex

    ZaxbyHub/opencode-swarm

    Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.

    494 GitHub stars~1.6k tokensUpdated today
    Auto-check passed
  • Durable Session State

    ZaxbyHub/opencode-swarm

    Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.

    494 GitHub stars~896 tokensUpdated today
    Auto-check passed
  • Swarm PR Feedback Closer

    ZaxbyHub/opencode-swarm

    Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.

    494 GitHub stars~14k tokensUpdated today
    Auto-check passed
  • Swarm PR Subscribe

    ZaxbyHub/opencode-swarm

    Monitor a pull request after creation and act autonomously on pushed PR activity.

    494 GitHub stars~2.2k tokensUpdated today
    Auto-check passed

Works with

Questions about Guardrail Patterns

What does Guardrail Patterns do?

Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand(). Guardrail Patterns is an agent skill from ZaxbyHub/opencode-swarm.

When should I use Guardrail Patterns?

Guardrail Patterns fits situations like: tasks that involve LLM guardrails.

How do I install Guardrail Patterns in Claude Code?

Run `npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a claude-code`. Or copy the skill folder (.opencode/skills/generated/guardrail-patterns in ZaxbyHub/opencode-swarm) into .claude/skills/guardrail-patterns in your project. Claude Code loads it when a task matches its description.

How do I install Guardrail Patterns in Codex?

Run `npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a codex`. Or copy the skill folder (.opencode/skills/generated/guardrail-patterns in ZaxbyHub/opencode-swarm) into .agents/skills/guardrail-patterns in your project. Codex loads it when a task matches its description.

Can I use Guardrail Patterns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guardrail-patterns, .gemini/skills/guardrail-patterns, .github/skills/guardrail-patterns and .opencode/skills/guardrail-patterns in your project.

What does Guardrail Patterns need to run?

Going by SKILL.md and its folder, Guardrail Patterns needs the command-line tools its instructions call (sh, rsync, git, bash, kubectl and docker).

Does Guardrail Patterns access the network?

SKILL.md contains no URLs. Its commands use git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Guardrail Patterns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Guardrail Patterns use?

Guardrail Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Guardrail Patterns use?

About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Guardrail Patterns?

Skills that share tags, products or a category with Guardrail Patterns: Writing Rules (athola/claude-night-market, 341 stars), Guard (Houseofmvps/ultraship, 123 stars), Aisafetyhot (wuyoscar/AISafetyHot-Hub, 708 stars) and Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Guardrail Patterns?

ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 494 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 10, 2026.

Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.