careful
Installation
SKILL.md
Contains Hooks
This skill uses Claude hooks which can execute code automatically in response to events. Review carefully before installing.
careful, block destructive commands for this session
Invoking this skill registers a PreToolUse hook on Bash (the hooks: block above).
Claude Code keeps a skill's hooks registered for the rest of the session, on every
later turn, so careful stays on until the session ends. There is no off switch:
start a new session to work without it.
What it blocks
| Rule | Blocks | Still allowed |
|---|---|---|
rm-rf |
rm with recursive and force flags (-rf, -fr, -r -f, --recursive --force), xargs rm -rf, and any target the shell expands: $TMPDIR/x, $TMP, $TEMP, $X, $( ), globs, braces, ~ |
the same command when every target is a LITERAL absolute path that lands, after following existing symlinks, strictly inside /tmp, /private/tmp or the configured TMPDIR (trusted only when it is two or more levels deep); write /tmp/build, not $TMPDIR/build, because a command can reassign TMPDIR first (TMPDIR=/ ; rm -rf $TMPDIR/usr); rm -r; rm -f file |
git-push-force |
git push --force, -f (also inside -uf), --force-with-lease[=...], a +branch refspec, to any branch |
git push, git push -u origin <branch> |
git-push-delete |
git push origin --delete <b>, -d <b>, :<b> |
git push origin <b>:<b> |
git-reset-hard |
git reset --hard |
git reset --soft, git reset HEAD <file> |
sql-drop |
DROP TABLE, DROP DATABASE, DROP SCHEMA anywhere in the command, heredocs included |
a SELECT that mentions drop |
sql-truncate |
TRUNCATE TABLE, or a TRUNCATE <name> statement sent to a SQL client |
truncate -s 0 file.log |
kubectl-delete |
kubectl ... delete |
kubectl get, kubectl logs |
terraform-destroy |
terraform destroy, terraform apply -destroy, the same with tofu |
terraform plan, terraform apply |