Skip to content
Back to skills

Careful

BSecurity

Session-scoped safety guardrails for destructive commands. Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Active for the current session only. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode". NOT for scoping edits to a specific directory (see mk:freeze).

  • 14 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added May 29, 2026
ai-agentsgobashrailsdebugginggitdocumentation

Security analysis

B85/100
  • highPerforms destructive filesystem operations

Pro scans all 3 files and shows the line behind each finding

Scanned May 29, 2026

npx -y skills add ngocsangyem/MeowKit --skill careful --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Careful?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Careful
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/ngocsangyem-careful/badge)](https://www.skillsdirectory.com/skills/ngocsangyem-careful)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: mk:careful
version: 0.1.0
description: |
  Session-scoped safety guardrails for destructive commands. Warns before rm -rf,
  DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive
  operations. User can override each warning. Active for the current session only.
  Use when touching prod, debugging live systems, or working in a shared environment.
  Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".
  NOT for scoping edits to a specific directory (see mk:freeze).
allowed-tools:
  - Bash
  - Read
hooks:
  PreToolUse:
    - matcher: "Bash"
      hooks:
        - type: command
          command: "bash ${CLAUDE_SKILL_DIR}/bin/check-careful.sh"
          statusMessage: "Checking for destructive commands..."
source: gstack
keywords: [careful, safety-mode, destructive-commands, prod-mode, guardrails]
when_to_use: "Use when working in prod or with destructive commands — warns before rm -rf, DROP TABLE, force-push. NOT for scoping edits to a directory (see mk:freeze)."
user-invocable: true
---

# /careful — Destructive Command Guardrails

Safety mode is now **active**. Every bash command will be checked for destructive
patterns before running. If a destructive command is detected, you'll be warned
and can choose to proceed or cancel.

```bash
mkdir -p .claude/memory
echo '{"skill":"careful","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}'  >> .claude/memory/skill-usage.jsonl 2>/dev/null || true
```

## What's protected

See [references/destructive-patterns.md](references/destructive-patterns.md) for full pattern list.

## How it works

The hook reads the command from the tool input JSON, checks it against the
patterns above, and returns `permissionDecision: "ask"` with a warning message
if a match is found. You can always override the warning and proceed.

To deactivate, end the conversation or start a new one. Hooks are session-scoped.

## Hooks

- **PreToolUse on Bash**: Warns before destructive commands (rm -rf, DROP TABLE, force-push, reset --hard, kubectl delete)
- Session-scoped — only active when `mk:careful` is invoked
- User can override each warning individually
- **Interaction with mk:investigate**: When careful is active during an investigation, destructive-Bash warnings still fire. Debugging commands that touch state require explicit user confirmation per warning — do not bypass.

## Gotchas

- **False positives on legitimate operations**: Pattern matching `rm` or `drop` in file content, not commands → Check command context, not just string presence
- **Overly broad regex blocking development**: Guard triggers on test fixtures or documentation mentioning destructive commands → Scope guards to actual Bash tool invocations only

Files in this skill

  • SKILL.md2.8 KB
  • bin/check-careful.sh10.3 KB
  • references/destructive-patterns.md11.7 KB

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…