safe-mode
Prevent destructive operations using Claude Code hooks. Three modes — cautious (warn on dangerous commands), lockdown (restrict edits to one directory), and clear (remove restrictions). Uses PreToolUse matchers for Bash, Edit, and Write.
Install / Use
npx skills add rohitg00/pro-workflow --skill safe-modeInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
Development & EngineeringSupported Platforms
Our assessment of safe-mode
safe-mode scores 90/100 on our quality scale, 917th of 3,554 Development & Engineering skills we index (top 26%).
Its SKILL.md is 5.5 KB long, well organised into 13 sections with 8 code examples: a solid amount of guidance for an agent.
With 2,876 GitHub stars, it is one of the more widely adopted skills in the catalogue.
Maintenance, license and trust
- The repository was last updated 5 days ago, so safe-mode is actively maintained.
- No license is declared. By default that means all rights are reserved: you can read it, but reusing or redistributing it is not clearly permitted. Ask the author before building on it commercially.
- Its trust signals score 88/100, with 1 caution from licensing, adoption, age or documentation. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
safe-mode compared with similar skills
All 4 of these similar skills score higher than safe-mode; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| safe-mode (this skill)by rohitg00 | 90 | 2.9k | 5d ago | SKILL.md |
| ai-job-searchby MadsLorentzen | 100 | 44.4k | 1d ago | CLAUDE.md |
| claude-howtoby luongnv89 | 100 | 41.7k | 3d ago | CLAUDE.md |
| algorithmic-artby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 7d ago | SKILL.md |
Frequently asked questions
- How do I install safe-mode?
- Run
npx skills add rohitg00/pro-workflow --skill safe-mode. The install tabs above show the steps for each supported agent. - Which AI agents does safe-mode work with?
- It is written for Claude Code, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is safe-mode safe to use?
- It declares no license and scores 88/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is safe-mode still maintained?
- The repository was last updated 5 days ago, so safe-mode is actively maintained.
Skill content
View source on GitHubname: safe-mode description: Prevent destructive operations using Claude Code hooks. Three modes — cautious (warn on dangerous commands), lockdown (restrict edits to one directory), and clear (remove restrictions). Uses PreToolUse matchers for Bash, Edit, and Write. user-invocable: true hooks: PreToolUse: - matcher: "Bash|Edit|Write" hooks: - type: command command: "node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js""
Safe Mode
Three levels of protection against destructive operations during AI coding sessions.
Note: These hooks are skill-scoped — they only activate when you invoke
/safe-mode. The globalpermission-request.jshook in hooks.json provides always-on alerting for dangerous commands. Safe-mode adds opt-in blocking and directory restrictions on top of that.
Modes
Cautious Mode
/safe-mode cautious
Intercepts Bash commands before execution. Warns on dangerous patterns but does not block — the user decides.
Flagged patterns:
| Pattern | Risk |
|---------|------|
| rm -rf / rm -r | Recursive deletion |
| DROP TABLE / DROP DATABASE | SQL data loss |
| TRUNCATE | SQL data destruction |
| git push --force / git push -f | Remote history rewrite |
| git reset --hard | Local history loss |
| git clean -f | Untracked file deletion |
| git checkout . / git restore . | Discard all changes |
| chmod 777 | World-writable permissions |
| curl or wget piped to a shell | Piped remote execution |
| > /dev/sda / dd if= | Disk-level operations |
| :(){ :\|:& };: | Fork bombs |
| sudo rm | Elevated deletion |
What happens: the hook returns a permission ask, so Claude Code shows you a prompt that names the pattern, for example Safe mode: rm with -r or -f. You approve or reject the command. This prompt appears even in auto mode.
Lockdown Mode
/safe-mode lockdown <path>
Restricts Edit and Write operations to a single directory tree. Prevents accidental changes to unrelated code.
How it works:
- Set the allowed path (absolute or relative to repo root)
- Every Edit/Write call checks if the target file is inside the allowed path
- Operations outside the path are blocked with an explanation
LOCKDOWN ACTIVE: Edits restricted to src/api/
Blocked: Edit to src/utils/helpers.ts
Reason: File is outside the lockdown path (src/api/)
To edit files outside the lockdown, run: /safe-mode clear
Use cases:
- Focused refactoring of one module without touching others
- Bug fix in a specific directory while tests run elsewhere
- Junior developer guardrail — scope the blast radius
- Code review session — only edit the files under review
Scope: Keyed to the project root. It stays set until /safe-mode clear, and only enforces in sessions where /safe-mode was invoked.
Clear
/safe-mode clear
Removes all restrictions for the current session. Both cautious warnings and lockdown restrictions are disabled.
SAFE MODE: All restrictions cleared for this session.
Implementation
Invoking this skill registers one PreToolUse hook for Bash|Edit|Write that runs scripts/safe-mode-guard.js. Skill hooks stay registered for the rest of the session. The guard does nothing until a mode is set.
Set the mode
When the user runs /safe-mode <mode>, run the guard's setter from the project root:
node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js" set cautious
node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js" set lockdown src/api/
node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js" set clear
Then report the line the setter prints.
Cautious (Bash)
The guard checks tool_input.command against a fixed list of destructive patterns: recursive or forced rm, DROP and TRUNCATE, force-push, hard reset, git clean -f, discarding all changes, chmod 777, piping curl or wget to a shell, disk-level writes, fork bombs, and sudo rm. A match returns permissionDecision: "ask" with the pattern as the reason. No match passes through.
Lockdown (Edit and Write)
The guard resolves tool_input.file_path against the project root, follows symlinks, and checks that it sits inside the lockdown path. Inside passes through. Outside exits 2, which blocks the edit and tells Claude why.
State
The mode lives in $TMPDIR/pro-workflow/safe-mode-<hash>.json, keyed by the project root, so two projects never share it:
{ "cautious": true, "lockdownPath": "/Users/dev/project/src/api", "root": "/Users/dev/project" }
set clear deletes the file. The file outlives the session, so clear it when you are done; a new session only enforces it again after /safe-mode is invoked, because the hook is skill-scoped.
Combining Modes
Cautious and lockdown can run simultaneously:
/safe-mode cautious
/safe-mode lockdown src/api/
Now you get:
- Bash command warnings for destructive operations
- Edit/Write restrictions to
src/api/only
Clear removes both.
When to Use
| Situation | Mode | |-----------|------| | Working on production-adjacent code | Cautious | | Focused refactoring of one module | Lockdown | | Unfamiliar codebase, feeling cautious | Cautious | | Pair programming, limiting AI scope | Lockdown | | Done with restrictions | Clear |
Anti-Patterns
- Leaving lockdown on when you need to edit tests (update the path or clear it)
- Using safe-mode as a substitute for git branches (branches protect history, safe-mode protects the session)
- Ignoring cautious warnings repeatedly (if you always proceed, turn it off — false confidence is worse)
Related Skills
ai-job-search
44.4kThe job search that runs on your machine. AI job application framework built on Claude Code: evaluate postings, tailor CVs, write cover letters, prep interviews. Fork it and own it.
claude-howto
41.7kA visual, example-driven guide to Claude Code — from basic concepts to advanced agents, with copy-paste templates that bring immediate value.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
