Auth & SécuritéAttention6666/100
safety-guard
Use this skill to prevent destructive operations when working on production systems or running agents autonomously.
ou envoie-le directement à ton agent.
Installer dans ton projet
Ce skill a un score de sûreté moyen. Vérifie le rapport avant de l’installer.
$ npx arboris-cli install safety-guardContenu à copier
--- name: safety-guard description: Use this skill to prevent destructive operations when working on production systems or running agents autonomously. metadata: origin: ECC --- # Safety Guard — Prevent Destructive Operations ## When to Use - When working on production systems - When agents are running autonomously (full-auto mode) - When you want to restrict edits to a specific directory - During sensitive operations (migrations, deploys, data changes) ## How It Works Three modes of protection: ### Mode 1: Careful Mode Intercepts destructive commands before execution and warns: ``` Watched patterns: - rm -rf (especially /, ~, or project root) - git push --force - git reset --hard - git checkout . (discard all changes) - DROP TABLE / DROP DATABASE - docker system prune - kubectl delete - chmod 777 - sudo rm - npm publish (accidental publishes) - Any command with --no-verify ``` When detected: shows what the command does, asks for confirmation, suggests safer alternative. ### Mode 2: Freeze Mode Locks file edits to a specific directory tree: ``` /safety-guard freeze src/components/ ``` Any Write/Edit outside `src/components/` is blocked with an explanation. Useful when you want an agent to focus on one area without touching unrelated code. ### Mode 3: Guard Mode (Careful + Freeze combined) Both protections active. Maximum safety for autonomous agents. ``` /safety-guard guard --dir src/api/ --allow-read-all ``` Agents can read anything but only write to `src/api/`. Destructive commands are blocked everywhere. ### Unlock ``` /safety-guard off ``` ## Implementation Uses PreToolUse hooks to intercept Bash, Write, Edit, and MultiEdit tool calls. Checks the command/path against the active rules before allowing execution. ## Integration - Enable by default for `codex -a never` sessions - Pair with observability risk scoring in ECC 2.0 - Logs all blocked actions to `~/.claude/safety-guard.log`
Colle ce Markdown dans ton agent ou utilise les boutons ci-dessus pour l’écrire dans ton projet.
Ce que fait safety-guard
When working on production systems
When agents are running autonomously (full-auto mode)
When you want to restrict edits to a specific directory
During sensitive operations (migrations, deploys, data changes)
Comment utiliser safety-guard
1
Copie le prompt
Un clic copie le prompt packagé (ou l'envoie à ton agent).
2
L'agent installe le skill
Il ajoute le SKILL.md et ses ressources à ton projet.
3
Activation automatique
Le skill s'active dès que le contexte correspond.
Déclencheurs pour safety-guard
Dis simplement à ton agent quelque chose comme :
Applique le skill safety-guard à cette tâche
Utilise safety-guard pour améliorer cette implémentation
Passe en revue ce sujet avec safety-guard
Skills liés à safety-guard
1password__nousresearch-hermes-agent__optional-skills-security-8c6b9c4182d0
Set up op CLI, sign in, and read or inject secrets.aibast_approval-routing_03__microsoft-aibast-agents-library__solutions-procurement-agent-manual-skills-e0f04224c5d0
Use when a department approver asks which authorization threshold applies to a request.aibast_certification-tracker_rc05__microsoft-aibast-agents-library__solutions-fs-regulatory-compliance-manual-skills-298b575c90bd
Use for who may trade, lapsed or upcoming certifications, supervisor escalation, and training-session planning.