Writing Rules
athola/claude-night-market
Creates behavioral rules in markdown to block dangerous commands or restrict AI behavior.
Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patterns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .claude/skills/guardrail-patterns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "guardrail-patterns" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patterns into .claude/skills/guardrail-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guardrail-patterns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patternsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patterns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .agents/skills/guardrail-patterns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "guardrail-patterns" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patterns into .agents/skills/guardrail-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guardrail-patterns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patterns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .cursor/skills/guardrail-patterns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "guardrail-patterns" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patterns into .cursor/skills/guardrail-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guardrail-patterns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ZaxbyHub/opencode-swarm.git --path .opencode/skills/generated/guardrail-patterns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patterns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .gemini/skills/guardrail-patterns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "guardrail-patterns" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patterns into .gemini/skills/guardrail-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guardrail-patterns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patternsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .github/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .github/skills/guardrail-patterns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "guardrail-patterns" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patterns into .github/skills/guardrail-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guardrail-patterns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ZaxbyHub/opencode-swarm guardrail-patterns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ZaxbyHub/opencode-swarm.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.opencode/skills/generated/guardrail-patterns .opencode/skills/guardrail-patterns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "guardrail-patterns" agent skill from https://github.com/ZaxbyHub/opencode-swarm/tree/main/.opencode/skills/generated/guardrail-patterns into .opencode/skills/guardrail-patterns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "guardrail-patterns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
guardrail-patternsGuardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()
Guardrail Patterns is an agent skill from ZaxbyHub/opencode-swarm. Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand()
Its SKILL.md is about 3.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in AI & LLM Engineering, covering LLM guardrails. It works with Bash. The repository describes itself as: Architect-centric agentic swarm plugin for OpenCode. Hub-and-spoke orchestration with SME consultation, code generation, and QA review. The licence is MIT.
5 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit b63a4bd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
shrsyncgitbashkubectldockerbunbunxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use rsync, git, kubectl, docker and bunx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Guardrail Patterns loads about 3.5k tokens when it runs. Until then it costs about 42 tokens; SKILL.md has 1,007 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from ZaxbyHub/opencode-swarm at commit b63a4bd, republished under its MIT licence (© ZaxbyHub). 1,007 words, ~3,528 tokens.
.claude/skills/guardrail-patterns/SKILL.md (or your agent's skills folder).Source knowledge: 098926ef, 2c1e4689, 54c33fa4, 4f51d11a
Load this skill before modifying src/hooks/guardrails.ts — adding, removing, or changing guardrail blocks in checkDestructiveCommand(). It documents the pattern structure, known bypass surfaces, regex anti-patterns, and test conventions used across 41 guardrail test files and the ~3900-line guardrails.ts file.
Load before any change to:
src/hooks/guardrails.ts — especially checkDestructiveCommand() or dcNormalizeCommand()tests/unit/hooks/guardrails*.test.ts — any guardrail test filecheckDestructiveCommand()checkDestructiveCommand() — the shell command guardLocated at src/hooks/guardrails.ts (line 1304). This is the only function that blocks destructive shell commands. It is invoked by the toolBefore hook in guardrails.ts before every bash or shell tool call.
Pipeline (in order):
dcNormalizeCommand() (line ~627) — NFKC normalization + evasion collapse: collapses "" (doubled double-quotes) and '' (doubled single-quotes). Single-quote splice like m'v' remains OPEN.dcStripOneWrapper() (line ~664) — detects and strips individual shell wrappers: bash, sh, zsh, dash, fish, pwsh, powershell, cmd (with -c/-Command), sudo, nohup, time, nice, env VAR=val, call (batch), Invoke-Command -ScriptBlock, & { } script blocks, wsl, iexdcUnwrapWrappers() (line ~737) — loops dcStripOneWrapper until no more wrappers remain (max depth 10)dcSplitSegments() (line ~753) — splits compound commands on &&, ;, |, newlinesdcValidateTargets() — runtime lstat-ancestor walk on destructive targets| Function | Line | What it normalizes |
|---|---|---|
dcNormalizeCommand | ~627 | NFKC, caret escapes (^), backtick escapes, collapsed "" and '' |
dcStripOneWrapper | ~664 | Detects/strips a single shell wrapper (bash/sh/zsh/pwsh/cmd/powershell/wsl etc) |
dcUnwrapWrappers | ~737 | Loops dcStripOneWrapper until no more wrappers (max depth 10) |
dcSplitSegments | ~753 | Splits on &&, ;, ` |
Known wrapper unwrapping limitation: sh -c and bash -c with single-quoted inner commands (sh -c 'mv ...') are NOT unwrapped because dcStripOneWrapper uses "? (optional double-quote). Only double-quoted inner commands are properly stripped.
Inside checkDestructiveCommand(), the per-segment for loop evaluates each segment against sections 1–22. A new section should be added after the last existing section and before the closing } of the for loop (currently after Section 22 at approximately line 1733).
There are three patterns used in the codebase:
Pattern A — Simple inline regex (single condition):
// Good for: single-command blocking with no complex extraction
if (/^blockedcommand\b.*\.swarm[\x5c/\s]?/i.test(seg)) {
throw new Error(`BLOCKED: "blockedcommand" targeting .swarm/ detected — ...`);
}Pattern B — Multi-condition (flag check + path check):
// Good for: archive tools with flags + .swarm/ path (prevents argument-order bypass)
if (
/^toolname\b.*--dangerous-flag\b/i.test(seg) &&
/\.swarm(?:[\x5c/\s]|$)/i.test(seg)
) {This is recommended because it handles both tool --flag .swarm/path and tool .swarm/path --flag argument orders.
Pattern C — Argument extraction + stripped check:
// Good for: commands where you need argument isolation (e.g., `mv` with arg capture)
if (/^\\?command\s/i.test(seg)) {
const match = seg.match(/^\\?command\s+(.+)$/i);
if (match) {
const argsStr = match[1].replace(/["']/g, '');
if (/\.swarm(?:[\x5c/\s]|$)/.test(argsStr)) {
throw new Error(`BLOCKED: ...`);
}
}
}POSIX, Windows cmd.exe, and PowerShell often use different commands for the same operation. All three must be covered:
// POSIX section
if (/^\\?posix-cmd\s/i.test(seg) && /\.swarm/i.test(strippedArgs)) { ... }
// Windows cmd section (case-insensitive, optional .exe)
if (/^\\?(?:cmd-cmd|cmd-cmd-alias)(?:\.exe)?\s/i.test(seg) && /\.swarm/i.test(argsStr)) { ... }
// PowerShell section (case-insensitive, all aliases)
if (/^\\?(?:PowerShell-Cmdlet|alias1|alias2)\b.*\.swarm/i.test(seg)) { ... }.swarm path separatorAlways use \x5c (backslash) for cross-platform path matching — \ alone is the regex escape character.
// Correct: matches both / and \
/\.swarm[\x5c/]/
// More complete: also matches .swarm followed by whitespace or end-of-string
// (catches whole-directory targeting like `mv .swarm /tmp/`)
/\.swarm(?:[\x5c/\s]|$)/Commands prefixed with \ (e.g., \mv) bypass simple ^command\s anchors. Always add \\?:
// Correct: catches both mv and \mv
if (/^\\?mv\s/i.test(seg)) { ... }
// Correct for rm (uses \b instead of \s)
if (/^\\?rm\b/i.test(seg)) { ... }These are documented bypass vectors that the current regex-based approach cannot fully close. Every new guardrail section should include adversarial tests for these patterns:
| Evasion | Example | Status | Mitigation |
|---|---|---|---|
| Backslash prefix | \mv .swarm/file | CLOSED | Add ^\\? to command anchor |
| Quote splicing | m'v' .swarm/file | OPEN | Requires NFKC normalization change |
| Quoted command name | "mv" .swarm/file | OPEN | Requires NFKC normalization change |
| Shell wrapper (double-quoted) | sh -c "mv .swarm/file" | CLOSED | dcUnwrapWrappers handles " |
| Shell wrapper (single-quoted) | sh -c 'mv .swarm/file' | OPEN | dcUnwrapWrappers regex uses "? |
| Relative path prefix | mv ./swarm/file | OPEN | Requires path normalization |
| Env var expansion | mv $SWARM_DIR/file | OPEN | Requires variable resolution |
| Unicode fullwidth | mv .swarm/file | OPEN | Requires NFKC normalization |
[^-] consuming path characters// WRONG — [^-] consumes the first character of the path
if (/^rm\s+(?!\s*-)(?!-)[^-].*\.swarm/i.test(seg)) {
// "rm .swarm/file" → [^-] consumes '.' → "swarm/file" doesn't match "\.swarm"
}
// CORRECT — use negative lookahead for flag exclusion
if (
/^rm\b/i.test(seg) &&
!/^rm\s+(?:-[a-zA-Z]*[rR][a-zA-Z]*|--recursive)\b/i.test(seg) &&
/\.swarm(?:[\x5c/\s]|$)/i.test(seg)
) {
// "rm .swarm/file" → BLOCKED ✓
// "rm -rf .swarm/" → Section 3 handles ✓
// "rm -v .swarm/file" → BLOCKED ✓
}(?!-\S))// WRONG — (?!-\S) excludes ALL flag-prefixed rm commands,
// but Section 3 only catches recursive/force flags
if (/^rm\s+(?!-\S).*\.swarm/i.test(seg)) {
// "rm -v .swarm/file" → NOT blocked by S19 (excluded by lookahead)
// "rm -v .swarm/file" → NOT blocked by S3 (no -r/-f flags)
}
// CORRECT — use three-part condition.exec() confused by SAST// WRONG — SAST confuses RegExp.prototype.exec() with child_process.exec()
const match = /^command\s+(.+)$/i.exec(seg); // SAST false positive
// CORRECT — use String.prototype.match()
const match = seg.match(/^command\s+(.+)$/i); // No SAST false positive// WRONG — .swarm/ must appear AFTER the flag in the command string
if (/^tool\b.*--flag\b.*\.swarm/i.test(seg)) {
// "tool --flag .swarm/" → BLOCKED ✓
// "tool .swarm/ --flag" → NOT BLOCKED ✗
}
// CORRECT — split flag check and path check
if (/^tool\b.*--flag\b/i.test(seg) && /\.swarm(?:[\x5c/\s]|$)/i.test(seg)) {
// Both argument orders BLOCKED ✓
}// Positive tests: "command → BLOCKED"
test('mv .swarm/evidence/file.json /tmp/ → BLOCKED', async () => { ... });
// Negative tests: "command → ALLOWED (reason)"
test('ls .swarm/evidence/ → ALLOWED (read-only)', async () => { ... });
// Bypass when feature is disabled
test('mv .swarm/file /tmp/ → ALLOWED when block_destructive_commands=false', async () => { ... });import { mkdtempSync, realpathSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { createGuardrailsHooks } from '../../../src/hooks/guardrails';
import { resetSwarmState, startAgentSession } from '../../../src/state';
const TEST_DIR = realpathSync(mkdtempSync(join(tmpdir(), 'guardrail-pattern-')));
function defaultConfig(overrides?: Partial<GuardrailsConfig>): GuardrailsConfig {
return {
enabled: true,
max_tool_calls: 200,
max_duration_minutes: 30,
idle_timeout_minutes: 60,
max_repetitions: 10,
max_consecutive_errors: 5,
warning_threshold: 0.75,
profiles: undefined,
block_destructive_commands: true,
...overrides,
};
}
function makeBashInput(sessionID = 'test-session', command: string) {
// Note: command is accepted but passed to makeBashOutput, not makeBashInput
return { tool: 'bash', sessionID, callID: 'call-1' };
}
function makeBashOutput(command: string) {
return { args: { command } };
}Every new guardrail section MUST have tests for:
.swarm/ is blocked.swarm/ path is allowedblock_destructive_commands: falsebun:test only (no Jest/Vitest)rejects.toThrow(/BLOCKED/) for positive assertionsresolves.toBeUndefined() for negative assertions/tmp — use os.tmpdir() + mkdtempSyncC:\ stringsmkdtempSync in realpathSync for macOS compatibility| Section | Line | Commands blocked | Notes |
|---|---|---|---|---|
| 2 | ~1347 | Junction/symlink CREATION out-of-cwd | dcCheckJunctionCreation — creation of junctions/symlinks targeting outside cwd |
| 3 | ~1353 | rm -r[Ff]*, rm -f -r, etc | Recursive + force only ([rRfF]+ flag set) |
| 4 | ~1378 | rmdir /s, rd /s | Windows cmd, recursive |
| 5 | ~1400 | del /s | Windows cmd |
| 6–7 | ~1418 | Remove-Item -Recurse + pipeline form | PowerShell |
| 8 | ~1457 | Ransomware-grade | vssadmin, wbadmin, diskpart, bcdedit, sdelete, fsutil, takeown, cipher, format, robocopy /MIR |
| 9 | ~1510 | chmod -R 000, chattr +i, icacls /deny | Permission denial-of-service |
| 10 | ~1529 | dd with /dev/zero/null/urandom | Data wipe |
| 11 | ~1538 | Git destructive | push --force, reset --hard, reset --mixed, clean -fd, worktree remove --force |
| 12 | ~1567 | rsync --delete(-before/-after/-during/-delay) | Mirror/sync with delete |
| 13 | ~1576 | kubectl delete, docker system prune | Cluster/container |
| 14 | ~1590 | DROP TABLE/DATABASE/SCHEMA, TRUNCATE TABLE | SQL DDL |
| 15 | ~1604 | mkfs | Disk format |
| 16 | ~1615 | mv | POSIX — blocked on .swarm/ |
| 17 | ~1635 | move, ren | Windows cmd — blocked on .swarm\ |
| 18 | ~1652 | Move-Item, Rename-Item, aliases | PowerShell — blocked on .swarm/ |
| 19 | ~1667 | rm (non-recursive) | Blocked on .swarm/ (recursive → Section 3) |
| 20 | ~1682 | cp + rm chain | Secondary defense (rm guard is primary) |
| 21 | ~1697 | rsync --remove-source-files, tar --remove-files, zip -m, 7z -sdel | Archive tools with delete-source flags |
| 22 | ~1728 | git clean -fd, git worktree remove --force | Verified existing patterns cover .swarm/ |
^\\? (backslash prefix).swarm path check uses (?:[\x5c/\s]|$) (whole-root + subpath).exec() → .match() to avoid SAST false positives.swarm/ path blocked.swarm/ path allowedblock_destructive_commands: falsebun run build succeedsbunx biome ci . clean© ZaxbyHub, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .opencode/skills/generated/guardrail-patterns of ZaxbyHub/opencode-swarm.
Open the folder on GitHubat commit b63a4bd
Guardrail Patterns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Guardrail Patterns this skillZaxbyHub/opencode-swarm | 494 | — | ~3.5k | Automated safety check: Pass | MIT | |
| Writing Rulesathola/claude-night-market | 341 | — | ~1.4k | Automated safety check: Notes | MIT | |
| GuardHouseofmvps/ultraship | 123 | — | ~790 | Automated safety check: Notes | MIT | |
| Aisafetyhotwuyoscar/AISafetyHot-Hub | 827 | — | ~1.4k | Automated safety check: Pass | Custom licence | |
| ObliteratusRedWoodOG/Hermes-Desktop | 177 | 5 repos | ~3.8k | Automated safety check: Pass | MIT | |
| Lemonade Router Builderamd/skills | 408 | — | ~4k | Automated safety check: Pass | MIT |
athola/claude-night-market
Creates behavioral rules in markdown to block dangerous commands or restrict AI behavior.
Houseofmvps/ultraship
Safety guardrails — blocks destructive commands (rm -rf, DROP TABLE, force-push, git reset --hard) and optionally restricts file edits to a specific directory.
wuyoscar/AISafetyHot-Hub
Query AI Safety HOT news, research papers, incidents, hot topics, and daily/weekly/monthly reports through its public read-only MCP service.
RedWoodOG/Hermes-Desktop
Remove refusal behaviors from open-weight LLMs using OBLITERATUS — mechanistic interpretability techniques (diff-in-means, SVD, whitened SVD, LEACE, SAE decomposition, etc.) to excise guardrails…
amd/skills
Turns a natural-language description of routing intent into a valid Lemonade collection.router policy JSON.
huggingface/skills
Builds reusable command line scripts that fetch, enrich or process data from the Hugging Face API, aimed at chained, repeated or automated tasks.
ZaxbyHub/opencode-swarm
Runs an evidence-gated, quote-grounded audit of a codebase for security, QA, accessibility, performance and more, and writes a verified report without changing source files.
ZaxbyHub/opencode-swarm
Drives a bug report from validation and root-cause tracing through a critic-reviewed plan, an approved minimal fix and a PR-ready closure, never merging without recorded human approval.
ZaxbyHub/opencode-swarm
Codex adapter for opencode-swarm that governs commits, pushes, draft PRs, PR body updates and CI closeout, deferring to the repo's canonical commit-pr protocol.
ZaxbyHub/opencode-swarm
Keeps plans, decisions, evidence and reviewer verdicts in small files so long multi-phase tasks survive context compaction and session resumes.
ZaxbyHub/opencode-swarm
Ingests existing pull request feedback such as review comments and CI failures, verifies each claim, fixes confirmed issues and reports closure status for every item.
ZaxbyHub/opencode-swarm
Monitor a pull request after creation and act autonomously on pushed PR activity.
Works with
Categories
Guardrail patterns for opencode-swarm — pattern structure, bypass surfaces, regex anti-patterns, and test conventions for checkDestructiveCommand(). Guardrail Patterns is an agent skill from ZaxbyHub/opencode-swarm.
Guardrail Patterns fits situations like: tasks that involve LLM guardrails.
Run `npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a claude-code`. Or copy the skill folder (.opencode/skills/generated/guardrail-patterns in ZaxbyHub/opencode-swarm) into .claude/skills/guardrail-patterns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a codex`. Or copy the skill folder (.opencode/skills/generated/guardrail-patterns in ZaxbyHub/opencode-swarm) into .agents/skills/guardrail-patterns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ZaxbyHub/opencode-swarm --skill guardrail-patterns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/guardrail-patterns, .gemini/skills/guardrail-patterns, .github/skills/guardrail-patterns and .opencode/skills/guardrail-patterns in your project.
Going by SKILL.md and its folder, Guardrail Patterns needs the command-line tools its instructions call (sh, rsync, git, bash, kubectl and docker).
SKILL.md contains no URLs. Its commands use git and docker, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Guardrail Patterns is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.5k tokens (SKILL.md is roughly 14k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Guardrail Patterns: Writing Rules (athola/claude-night-market, 341 stars), Guard (Houseofmvps/ultraship, 123 stars), Aisafetyhot (wuyoscar/AISafetyHot-Hub, 827 stars) and Obliteratus (RedWoodOG/Hermes-Desktop, 177 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ZaxbyHub (a GitHub organization) maintains it in ZaxbyHub/opencode-swarm, which has 494 GitHub stars. The repository holds 91 skills in this directory. The repository was last updated on October 10, 2026.
Source: ZaxbyHub/opencode-swarm on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.