Git Guardrails Claude Code
Set up Claude Code hooks that block dangerous git commands (push, reset --hard, clean, branch -D) before they execute.
What gets blocked
git push(all variants including --force)git reset --hardgit clean -f/git clean -fdgit branch -Dgit checkout ./git restore .
Setup steps
- Ask scope: project-only (.claude/settings.json) or all projects (~/.claude/settings.json)
- Copy the hook script to the appropriate location
- Make it executable (chmod +x)
- Add PreToolUse hook to settings.json
- Verify by triggering a blocked command
Note: This skill is designed for Claude Code's hook system. For Hermes Agent, adapt to use git config aliases or pre-commit hooks instead.
Common Pitfalls
- Missing execute permission on the hook script: The block-dangerous-git.sh script must be chmod +x or it silently won't run.
- Installing globally when project-only is appropriate: Global hooks affect all Claude Code sessions. Only install globally if the user explicitly wants that.
- Not testing the guardrails after installation: Verify by triggering one of the blocked commands and confirming it is intercepted.
Verification Checklist
- Scope confirmed (project or global)
- Hook script copied to correct location
- chmod +x applied to hook script
- Hook added to settings.json (PreToolUse)
- Guardrails verified with a test command