AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL unreviewed MIT Self-run

Guard

skill-houseofmvps-ultraship-guard · by Houseofmvps

Safety guardrails — blocks destructive commands (rm -rf, DROP TABLE, force-push, git reset --hard) and optionally restricts file edits to a specific directory. Use when working on critical systems or when you want extra protection.

No reviews yet
0 installs
33 views
0.0% view→install

Install

$ agentstack add skill-houseofmvps-ultraship-guard

Open-source listing, not yet scanned by AgentStack. Follow the source repository for install instructions.

Security review

⚠ Flagged

1 finding(s); flagged for manual review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures
  • high Destructive filesystem operation.

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Reliability & compatibility

Not yet reviewed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Guard? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Guard — Safety Guardrails

Guard protects you from accidental destructive actions by intercepting dangerous commands before they execute. It uses Claude Code's PreToolUse hooks to catch risky patterns in real-time.

Announce at start: "I'm activating Guard — destructive commands will be blocked until you explicitly approve them."

What Guard Blocks

Destructive Bash Commands

  • rm -rf / rm -r on important directories
  • DROP TABLE / DROP DATABASE / TRUNCATE
  • git push --force / git push -f (to main/master)
  • git reset --hard
  • git checkout . / git restore . (discard all changes)
  • git clean -f / git clean -fd
  • git branch -D (force delete branch)
  • kubectl delete (Kubernetes resource deletion)
  • docker system prune / docker volume rm
  • :> file / > file (truncate files)

File Edit Restrictions (Optional)

When the user specifies a directory to freeze to, Guard blocks edits outside that directory:

User: "Only edit files in src/api/"
→ Guard blocks Edit/Write calls to any path not under src/api/

How It Works

Guard installs PreToolUse hooks that run BEFORE Claude executes Bash, Edit, or Write tools:

  1. Bash hook — Scans the command string for destructive patterns. If matched, outputs a warning and blocks execution.
  2. Edit/Write hook — If a freeze directory is set, checks that the target file is within the allowed path.

The hooks are defined in this skill's configuration and activate when the skill is loaded.

Usage

Activate full protection

Just invoke /guard — destructive command blocking is immediate.

Set a directory freeze

Tell Claude which directory to restrict edits to:

"Only edit files in packages/api/"
"Freeze edits to src/components/"

Guard will write the freeze path to .ultraship/guard-freeze.txt and enforce it on all Edit/Write operations.

Remove freeze

"Unfreeze" or "Remove edit restrictions"

Override a blocked command

If Guard blocks something you actually need to run, explicitly confirm:

"Yes, I want to force-push to main"
"Confirmed: drop the users table"

Guard will allow explicitly confirmed destructive actions.

Integration with Other Skills

  • /investigate — Guard pairs well with investigation. No accidental fixes while diagnosing.
  • /deploy — Guard prevents accidental force-pushes during deployment.
  • /rescue — During incidents, Guard ensures rollback commands are deliberate.

Key Principles

  1. Block by default, allow on confirmation. Better to stop and ask than to destroy.
  2. No silent failures. Always explain what was blocked and why.
  3. The user is sovereign. Explicit confirmation overrides any guard.
  4. Minimal friction for safe operations. Guard only triggers on genuinely dangerous patterns.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.