Skip to content
Back to skills

Git Guardrails Claude Code

ASecurity

设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。

  • 429 stars
  • 0 votes
  • 0 copies
  • 2 views
  • Added September 29, 2026
ai-agentsbashrailsgit

Works with

  • claude code

Security analysis

A100/100

Pro scans all 3 files and shows the line behind each finding

Scanned September 29, 2026

npx -y skills add devcxl/mattpocock-skills-zh --skill git-guardrails-claude-code --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Git Guardrails Claude Code?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Git Guardrails Claude Code
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/devcxl-git-guardrails-claude-code/badge)](https://www.skillsdirectory.com/skills/devcxl-git-guardrails-claude-code)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: git-guardrails-claude-code
description: 设置 Claude Code 钩子,在危险 Git 命令(push、reset --hard、clean、branch -D 等)执行前将其拦截。当用户想要防止破坏性 Git 操作、添加 Git 安全钩子或在 Claude Code 中阻止 git push/reset 时使用。
---

# 设置 Git 护栏

设置一个 PreToolUse 钩子,在 Claude 执行危险 Git 命令之前拦截并阻止它们。

## 会被阻止的命令

- `git push`(包括 `--force` 在内的所有变体)
- `git reset --hard`
- `git clean -f` / `git clean -fd`
- `git branch -D`
- `git checkout .` / `git restore .`

当命令被阻止时,Claude 会看到一条消息,告知它没有权限访问这些命令。

## 步骤

### 1. 询问安装范围

询问用户:是**仅针对当前项目**安装(`.claude/settings.json`),还是**所有项目**安装(`~/.claude/settings.json`)?

### 2. 复制钩子脚本

打包的脚本位于:[scripts/block-dangerous-git.sh](scripts/block-dangerous-git.sh)

根据安装范围将其复制到目标位置:

- **项目级**:`.claude/hooks/block-dangerous-git.sh`
- **全局**:`~/.claude/hooks/block-dangerous-git.sh`

使用 `chmod +x` 使其可执行。

### 3. 将钩子添加到设置文件

添加到相应的设置文件中:

**项目级**(`.claude/settings.json`):

```json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "\"$CLAUDE_PROJECT_DIR\"/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}
```

**全局**(`~/.claude/settings.json`):

```json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}
```

如果设置文件已存在,将钩子合并到现有的 `hooks.PreToolUse` 数组中:不要覆盖其他设置。

### 4. 询问自定义

询问用户是否需要从阻止列表中添加或移除任何模式。根据需求编辑已复制的脚本。

### 5. 验证

运行一个快速测试:

```bash
echo '{"tool_input":{"command":"git push origin main"}}' | <path-to-script>
```

应退出并返回代码 2,并向 stderr 打印一条 BLOCKED 消息。

Files in this skill

  • SKILL.md2.3 KB
  • agents/openai.yaml112 B
  • scripts/block-dangerous-git.sh507 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…