# Mk Careful

> Session-scoped guardrails warning before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, etc; user can override. NOT for scoping edits to a directory (mk:freeze).

- Skill: `ngocsangyem/mk-careful-2` (Agent Skill, multi-file: 3 files)
- Install (CLI): `npx skillmds@latest add ngocsangyem/mk-careful-2`
- Raw SKILL.md: https://api.skillmd.com/api/skills/ngocsangyem/mk-careful-2/raw
- Safety review: pending
- Works with: Claude Code, Claude.ai, OpenAI Codex
- Category: Coding & Dev Tools
- Author: ngocsangyem (https://skillmd.com/u/ngocsangyem)
- Updated: 2026-09-17
- Page: https://skillmd.com/skills/ngocsangyem/mk-careful-2

---


# /careful — Destructive Command Guardrails

Safety mode is now **active**. Every bash command will be checked for destructive
patterns before running. If a destructive command is detected, you'll be warned
and can choose to proceed or cancel.

```bash
mkdir -p .meowkit/telemetry
echo '{"skill":"careful","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}'  >> .meowkit/telemetry/skill-usage.jsonl 2>/dev/null || true
```

## What's protected

See [references/destructive-patterns.md](references/destructive-patterns.md) for full pattern list.

## How it works

The guard script reads the command from the tool input, checks it against the
patterns above, and (enforced by this project's configured hooks when present)
surfaces an "ask" warning if a match is found. You can always override the warning and proceed.

To deactivate, end the conversation or start a new one. Guardrails are session-scoped.

## Guardrails

- **Bash command guard**: Warns before destructive commands (rm -rf, DROP TABLE, force-push, reset --hard, kubectl delete) — enforced by this project's configured hooks when present
- Session-scoped — only active when `mk:careful` is invoked
- User can override each warning individually
- **Interaction with mk:investigate**: When careful is active during an investigation, destructive-Bash warnings still fire. Debugging commands that touch state require explicit user confirmation per warning — do not bypass.

## Gotchas

- **False positives on legitimate operations**: Pattern matching `rm` or `drop` in file content, not commands → Check command context, not just string presence
- **Overly broad regex blocking development**: Guard triggers on test fixtures or documentation mentioning destructive commands → Scope guards to actual Bash tool invocations only
