autoplan
無料Auto-review pipeline — reads the full CEO, design, eng, and DX review skills from disk and runs them sequentially with auto-decisions using 6 decision principles. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。
Safety guardrails for destructive commands. (gstack)
インストール方法を見るインストールする前に、エージェントに与えられる指示の中身を確認できます。
Warns before rm -rf, DROP TABLE, force-push, git reset --hard, kubectl delete, and similar destructive operations. User can override each warning. Use when touching prod, debugging live systems, or working in a shared environment. Use when asked to "be careful", "safety mode", "prod mode", or "careful mode".
Safety mode is now active. Every Bash and PowerShell command will be checked for destructive patterns before running. If a destructive command is detected, you'll be warned and can choose to proceed or cancel.
GSTACK_STATE_ROOT=$(~/.claude/skills/gstack/bin/gstack-paths --get GSTACK_STATE_ROOT); : "${GSTACK_STATE_ROOT:?gstack-paths failed; reinstall with ./setup or /gstack-upgrade}"
mkdir -p "$GSTACK_STATE_ROOT"/analytics
echo '{"skill":"careful","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}' >> "$GSTACK_STATE_ROOT"/analytics/skill-usage.jsonl 2>/dev/null || true
| Pattern | Example | Risk |
|---|---|---|
rm -rf / rm -r / rm --recursive | rm -rf /var/data | Recursive delete |
DROP TABLE / DROP DATABASE | DROP TABLE users; | Data loss |
TRUNCATE | TRUNCATE orders; | Data loss |
git push --force / -f | git push -f origin main | History rewrite |
git reset --hard | git reset --hard HEAD~3 | Uncommitted work loss |
git checkout . / git restore . | git checkout . | Uncommitted work loss |
kubectl delete | kubectl delete pod | Production impact |
docker rm -f / docker system prune | docker system prune -a | Container/image loss |
The hook also checks the PowerShell tool (Claude Code's main Windows shell)
and any pwsh/powershell/cmd launched from Bash. Matching ignores case,
covers aliases in command position, accepts parameter prefixes (-r, -fo)
and strips cmd ^ escapes. All rows above apply there too.
| Pattern | Example |
|---|---|
Remove-Item/rm/ri/del/erase/rd/rmdir + -Recurse or -Force | gci | ri -r -fo |
cmd rd /s, rmdir /s, del /s, erase /s | cmd /c rd /s /q C:\proj |
Format-Volume, Clear-Disk, Clear-Content, [IO.Directory]::Delete, [IO.File]::Delete | Clear-Disk -Number 1 |
-EncodedCommand, iex, Start-Process of a shell, & $cmd (can't be inspected) | irm $url | iex |
Best-effort on PowerShell. String matching can't see a command built at
runtime. For a hard stop, add Claude Code permission deny rules, which parse
PowerShell and its aliases: "deny": ["PowerShell(Remove-Item *)"] in
.claude/settings.json. The hook runs through bash, so Windows needs Git Bash.
These patterns are allowed without warning:
rm -rf node_modules / .next / dist / __pycache__ / .cache / build / .turbo / coverageThe hook reads tool_name and the command from the tool input JSON, checks it against the
patterns above, and returns a hookSpecificOutput payload with
permissionDecision: "ask" and a warning reason if a match is found (the
decision must be nested under hookSpecificOutput — Claude Code ignores a
top-level permissionDecision). You can always override a MEDIUM warning and
proceed.
Two catastrophic shapes are denied, not asked: rm -r/-R of exactly
/, ~, or $HOME, and force-push to the repo's default branch. SIMPLE
commands only (no ;, &&, ||, |, newline) — compound shapes fall
through to the MEDIUM ask; --force-with-lease is never HIGH. A best-effort
advisory hard-stop, not a policy boundary: the escape hatch is ending the
opt-in, session-scoped /careful session.
Add warn rules — one POSIX ERE per line, # comments OK — in
~/.gstack/careful-patterns.txt (global) or
~/.gstack/projects/<slug>/careful-patterns.txt (per-project). Consulted
after the built-in families, so config can only ADD rules, never suppress a
baseline warning. Invalid regex lines are skipped.
To deactivate, end the conversation or start a new one. Hooks are session-scoped.
まだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Auto-review pipeline — reads the full CEO, design, eng, and DX review skills from disk and runs them sequentially with auto-decisions using 6 decision principles. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。
Web performance regression detection. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。
Cross-model benchmark for gstack skills. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。
Drive a real browser through Aside: open a page, read it, click through a flow, take screenshots, check console errors. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。
Post-deploy canary monitoring. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。
OpenAI Codex CLI wrapper — three modes. (gstack)
日本語の概要は準備中です。原文の説明を表示しています。