Browse
129kNavegador headless rápido para QA testing y dogfooding de sitios (gstack).
- Costo de contexto al activarse
- 14.8k tok
- Tamaño del paquete
- 237 archivos
- Última actualización
- hace 7 horas
- Permisos
Barreras de seguridad para comandos destructivos (gstack).
bashreaden todo el repo
0–100, la ruta de este skill
último commit aquí
últimos 90 días
13 tok en reposo
25 KB
Funciona con cualquier agente que lea SKILL.md
npx -y skills add garrytan/gstack --skill careful --agent claude-codeSe instala solo en este repositorio.
Este skill runs shell commands.
Di cualquiera de estas frases y el agente debería cargar este skill.
Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".
Safety mode is now active. Every bash command will be checked for destructive patterns before running. If a destructive command is detected, you'll be warned and can choose to proceed or cancel.
mkdir -p ~/.gstack/analytics
echo '{"skill":"careful","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}' >> ~/.gstack/analytics/skill-usage.jsonl 2>/dev/null || true
| Pattern | Example | Risk |
|---|---|---|
rm -rf / rm -r / rm --recursive |
rm -rf /var/data |
Recursive delete |
DROP TABLE / DROP DATABASE |
DROP TABLE users; |
Data loss |
TRUNCATE |
TRUNCATE orders; |
Data loss |
git push --force / -f |
git push -f origin main |
History rewrite |
git reset --hard |
git reset --hard HEAD~3 |
Uncommitted work loss |
git checkout . / git restore . |
git checkout . |
Uncommitted work loss |
kubectl delete |
kubectl delete pod |
Production impact |
docker rm -f / docker system prune |
docker system prune -a |
Container/image loss |
These patterns are allowed without warning:
rm -rf node_modules / .next / dist / __pycache__ / .cache / build / .turbo / coverageThe hook reads the command from the tool input JSON, checks it against the
patterns above, and returns a hookSpecificOutput payload with
permissionDecision: "ask" and a warning reason if a match is found (the
decision must be nested under hookSpecificOutput — Claude Code ignores a
top-level permissionDecision). You can always override a MEDIUM warning and
proceed.
Two catastrophic shapes are denied, not asked: rm -r/-R of exactly
/, ~, or $HOME, and force-push to the repo's default branch. SIMPLE
commands only (no ;, &&, ||, |, newline) — compound shapes fall
through to the MEDIUM ask; --force-with-lease is never HIGH. A best-effort
advisory hard-stop, not a policy boundary: the escape hatch is ending the
opt-in, session-scoped /careful session.
Add warn rules — one POSIX ERE per line, # comments OK — in
~/.gstack/careful-patterns.txt (global) or
~/.gstack/projects/<slug>/careful-patterns.txt (per-project). Consulted
after the built-in families, so config can only ADD rules, never suppress a
baseline warning. Invalid regex lines are skipped.
To deactivate, end the conversation or start a new one. Hooks are session-scoped.
Reproducido de garrytan/gstack bajo licencia MIT. Leer esta página en markdown.
4 archivos en el paquete. Solo se lee SKILL.md al activarse — las referencias se cargan si el skill decide que las necesita.
Requiere el hook check-careful.sh en $HOME/.claude/skills/gstack/careful/bin/ y es válido solo durante la sesión actual.
Necesita en el PATH:git
Este repo incluye 59 skills. Si instalas uno, normalmente ya tienes los demás.
Navegador headless rápido para QA testing y dogfooding de sitios (gstack).
Flujo de ship: detecta y fusiona la rama base, corre tests, revisa el diff, sube VERSION, actualiza CHANGELOG, hace commit, push y crea el PR (gstack).
QA en dispositivo iOS real para apps SwiftUI, con bucle de agente guiado por visión sobre USB (gstack).
Revisión de planes con ojo de diseñador — interactiva, al estilo de las revisiones de CEO e Ingeniería. (gstack)
Revisión de plan en modo gerente de ingeniería: arquitectura, flujo de datos, diagramas, casos límite, cobertura de pruebas y rendimiento. (gstack)
Actualización de documentación posterior al ship (gstack).
Modo Chief Security Officer: auditoría de seguridad centrada en infraestructura, con OWASP Top 10, modelado de amenazas STRIDE y verificación activa.
Modo de máxima seguridad: avisos ante comandos destructivos más restricción de ediciones a un directorio concreto (gstack).
Endurece el código contra vulnerabilidades. Úsalo al manejar entrada de usuario, autenticación, almacenamiento de datos, integraciones externas o datos personales (GDPR, CCPA).