/vibeflow-freeze — Restrict Edits to a Directory
Lock file edits to a specific directory. Any Edit or Write operation targeting a file outside the allowed path will be blocked (not just warned).
Note: This skill requires hook script support. Ensure the hook script
bin/check-freeze.sh is executable and properly installed. The freeze boundary
is stored in ~/.vibeflow/freeze-dir.txt.
Setup
Ask the user which directory to restrict edits to. Use AskUserQuestion:
- Question: "Which directory should I restrict edits to? Files outside this path will be blocked from editing."
- Text input (not multiple choice) — the user types a path.
Once the user provides a directory path:
- Resolve it to an absolute path:
FREEZE_DIR=$(cd "<user-provided-path>" 2>/dev/null && pwd)
echo "$FREEZE_DIR"
- Ensure trailing slash and save to the freeze state file:
FREEZE_DIR="${FREEZE_DIR%/}/"
STATE_DIR="${VIBEFLOW_STATE_DIR:-${HOME}/.vibeflow}"
mkdir -p "$STATE_DIR"
echo "$FREEZE_DIR" > "$STATE_DIR/freeze-dir.txt"
echo "Freeze boundary set: $FREEZE_DIR"
Tell the user: "Edits are now restricted to <path>/. Any Edit or Write
outside this directory will be blocked. To change the boundary, run /vibeflow-freeze
again. To remove it, run /vibeflow-unfreeze or end the session."
How it works
The hook reads file_path from the Edit/Write tool input JSON, then checks
whether the path starts with the freeze directory. If not, it returns
permissionDecision: "deny" to block the operation.
The freeze boundary persists for the session via the state file. The hook script reads it on every Edit/Write invocation.
Notes
- The trailing
/on the freeze directory prevents/srcfrom matching/src-old - Freeze applies to Edit and Write tools only — Read, Bash, Glob, Grep are unaffected
- This prevents accidental edits, not a security boundary — Bash commands like
sedcan still modify files outside the boundary - To deactivate, run
/vibeflow-unfreezeor end the conversation
Activation
To activate this skill, run:
Skill: vibeflow-freeze
集成
调用者: 用户在 review 阶段或其他需要文件边界保护的场景主动调用
依赖: bin/check-freeze.sh hook 脚本存在且可执行;~/.vibeflow/freeze-dir.txt 状态文件
状态: 默认关闭,需要用户显式激活
链接到: vibeflow-guard(组合模式)/ vibeflow-unfreeze(解除)