跳到正文
FunCoding

搜索

搜索文档、Skill 和 MCP

safe-mode

Prevent destructive operations using Claude Code hooks. Three modes — cautious (warn on dangerous commands), lockdown (restrict edits to one directory), and clear (remove restrictions). Uses PreToolUse matchers for Bash, Edit, and Write.

AI 与智能体2.9kskills/safe-mode/SKILL.md

安装

把这段话发给 Claude Code、Codex 或 Cursor。智能体会先检查安全性,你确认后才安装。

读取 https://funcoding.ai/skills/rohitg00/pro-workflow/safe-mode/install.md ,按里面的步骤帮我安装这个 Skill。

SKILL.md

Safe Mode

Three levels of protection against destructive operations during AI coding sessions.

Note: These hooks are skill-scoped — they only activate when you invoke /safe-mode. The global permission-request.js hook in hooks.json provides always-on alerting for dangerous commands. Safe-mode adds opt-in blocking and directory restrictions on top of that.

Modes

Cautious Mode

/safe-mode cautious

Intercepts Bash commands before execution. Warns on dangerous patterns but does not block — the user decides.

Flagged patterns:

PatternRisk
rm -rf / rm -rRecursive deletion
DROP TABLE / DROP DATABASESQL data loss
TRUNCATESQL data destruction
git push --force / git push -fRemote history rewrite
git reset --hardLocal history loss
git clean -fUntracked file deletion
git checkout . / git restore .Discard all changes
chmod 777World-writable permissions
curl or wget piped to a shellPiped remote execution
> /dev/sda / dd if=Disk-level operations
:(){ :|:& };:Fork bombs
sudo rmElevated deletion

What happens: the hook returns a permission ask, so Claude Code shows you a prompt that names the pattern, for example Safe mode: rm with -r or -f. You approve or reject the command. This prompt appears even in auto mode.

Lockdown Mode

/safe-mode lockdown <path>

Restricts Edit and Write operations to a single directory tree. Prevents accidental changes to unrelated code.

How it works:

  1. Set the allowed path (absolute or relative to repo root)
  2. Every Edit/Write call checks if the target file is inside the allowed path
  3. Operations outside the path are blocked with an explanation
LOCKDOWN ACTIVE: Edits restricted to src/api/

  Blocked: Edit to src/utils/helpers.ts
  Reason: File is outside the lockdown path (src/api/)

  To edit files outside the lockdown, run: /safe-mode clear

Use cases:

  • Focused refactoring of one module without touching others
  • Bug fix in a specific directory while tests run elsewhere
  • Junior developer guardrail — scope the blast radius
  • Code review session — only edit the files under review

Scope: Keyed to the project root. It stays set until /safe-mode clear, and only enforces in sessions where /safe-mode was invoked.

Clear

/safe-mode clear

Removes all restrictions for the current session. Both cautious warnings and lockdown restrictions are disabled.

SAFE MODE: All restrictions cleared for this session.

Implementation

Invoking this skill registers one PreToolUse hook for Bash|Edit|Write that runs scripts/safe-mode-guard.js. Skill hooks stay registered for the rest of the session. The guard does nothing until a mode is set.

Set the mode

When the user runs /safe-mode <mode>, run the guard's setter from the project root:

node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js" set cautious
node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js" set lockdown src/api/
node "${CLAUDE_PLUGIN_ROOT}/scripts/safe-mode-guard.js" set clear

Then report the line the setter prints.

Cautious (Bash)

The guard checks tool_input.command against a fixed list of destructive patterns: recursive or forced rm, DROP and TRUNCATE, force-push, hard reset, git clean -f, discarding all changes, chmod 777, piping curl or wget to a shell, disk-level writes, fork bombs, and sudo rm. A match returns permissionDecision: "ask" with the pattern as the reason. No match passes through.

Lockdown (Edit and Write)

The guard resolves tool_input.file_path against the project root, follows symlinks, and checks that it sits inside the lockdown path. Inside passes through. Outside exits 2, which blocks the edit and tells Claude why.

State

The mode lives in $TMPDIR/pro-workflow/safe-mode-<hash>.json, keyed by the project root, so two projects never share it:

{ "cautious": true, "lockdownPath": "/Users/dev/project/src/api", "root": "/Users/dev/project" }

set clear deletes the file. The file outlives the session, so clear it when you are done; a new session only enforces it again after /safe-mode is invoked, because the hook is skill-scoped.

Combining Modes

Cautious and lockdown can run simultaneously:

/safe-mode cautious
/safe-mode lockdown src/api/

Now you get:

  • Bash command warnings for destructive operations
  • Edit/Write restrictions to src/api/ only

Clear removes both.

When to Use

SituationMode
Working on production-adjacent codeCautious
Focused refactoring of one moduleLockdown
Unfamiliar codebase, feeling cautiousCautious
Pair programming, limiting AI scopeLockdown
Done with restrictionsClear

Anti-Patterns

  • Leaving lockdown on when you need to edit tests (update the path or clear it)
  • Using safe-mode as a substitute for git branches (branches protect history, safe-mode protects the session)
  • Ignoring cautious warnings repeatedly (if you always proceed, turn it off — false confidence is worse)

相似的 Skill

brand-guidelines
anthropics/skills180k

brand-guidelines

Applies Anthropic's official brand colors and typography to any sort of artifact that may benefit from having Anthropic's look-and-feel. Use it when brand colors or style guidelines, visual formatting, or company design standards apply.

AI 与智能体

internal-comms
anthropics/skills180k

internal-comms

A set of resources to help me write all kinds of internal communications, using the formats that my company likes to use. Claude should use this skill whenever asked to write some sort of internal communications (status reports, leadership updates, 3P updates, company newsletters, FAQs, incident reports, project updates, etc.).

AI 与智能体

template-skill
anthropics/skills180k

template-skill

Replace with description of the skill and when Claude should use it.

AI 与智能体

mcp-builder
anthropics/skills180k

mcp-builder

Guide for creating high-quality MCP (Model Context Protocol) servers that enable LLMs to interact with external services through well-designed tools. Use when building MCP servers to integrate external APIs or services, whether in Python (FastMCP) or Node/TypeScript (MCP SDK).

AI 与智能体

algorithmic-art
anthropics/skills180k

algorithmic-art

Creating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems. Create original algorithmic art rather than copying existing artists' work to avoid copyright violations.

AI 与智能体

academy-guide
anthropics/skills180k

academy-guide

Stop and check this skill before finishing any reply to a question about how to use Claude or a Claude product — it recommends matching courses, tutorials, and use cases from Claude Academy (academy.claude.com), Anthropic's learning hub. Trigger on: "how do I", "how can I", "getting started with", "what can Claude do", "teach me", "learn to use"; questions about artifacts, projects, skills, plugins, connectors, MCP; requests about rolling Claude out to a team, class, or organization; and any ask for training materials, onboarding content, or learning resources. Use it when the user is learning how to use a feature or product — not when they are mid-task and just want the task done. This skill composes with other skills: after consulting product documentation to answer how a Claude feature works, also check here for a matching course or tutorial — a docs-grounded answer and an Academy recommendation belong together. Only recommend on a strong match; never invent Academy content.

AI 与智能体