A high-performance Rust-based safety layer that blocks dangerous shell commands before they execute.

Install

mkdir -p .claude/skills/dcg && curl -L -o skill.zip "https://agentskills.codes/api/skills/download/6119" && unzip -o skill.zip -d .claude/skills/dcg && rm skill.zip

Installs to .claude/skills/dcg

Activation

This is the description your AI agent reads to decide when to run this skill — the better it matches your request, the more reliably it fires.

Destructive Command Guard - High-performance Rust hook for Claude Code that blocks dangerous commands before execution. SIMD-accelerated, modular pack system, whitelist-first architecture. Essential safety layer for agent workflows.
232 charsno explicit “when” trigger
Intermediate

Key capabilities

  • Intercepts and blocks destructive shell commands
  • Uses a whitelist-first architecture for safety
  • Provides SIMD-accelerated filtering for performance
  • Organizes patterns into modular packs by category
  • Blocks dangerous git, filesystem, and database commands

How it works

The tool acts as a pre-tool hook that evaluates commands against a whitelist of safe patterns and a blacklist of destructive patterns before execution.

Inputs & outputs

You give it
Shell command execution attempt
You get back
Blocked command notification or allowed execution

When to use dcg

  • Protect files from accidental deletion
  • Prevent destructive git resets
  • Guard against dangerous shell scripts
  • Ensure safe environment cleanup

About this skill

DCG — Destructive Command Guard

A high-performance Claude Code hook that intercepts and blocks destructive commands before they execute. Written in Rust with SIMD-accelerated filtering for sub-millisecond latency.

Why This Exists

AI coding agents are powerful but fallible. They can accidentally run destructive commands:

  • "Let me clean up the build artifacts"rm -rf ./src (typo)
  • "I'll reset to the last commit"git reset --hard (destroys uncommitted changes)
  • "Let me fix the merge conflict"git checkout -- . (discards all modifications)
  • "I'll clean up untracked files"git clean -fd (permanently deletes untracked files)

DCG intercepts dangerous commands before execution and blocks them with a clear explanation, giving you a chance to stash your changes first.

Critical Design Principles

1. Whitelist-First Architecture

Safe patterns are checked before destructive patterns. This ensures explicitly safe commands are never accidentally blocked:

git checkout -b feature    →  Matches SAFE "checkout-new-branch"  →  ALLOW
git checkout -- file.txt   →  No safe match, matches DESTRUCTIVE  →  DENY

2. Fail-Safe Defaults (Default-Allow)

Unrecognized commands are allowed by default. This ensures:

  • The hook never breaks legitimate workflows
  • Only known dangerous patterns are blocked
  • New git commands work until explicitly categorized

3. Zero False Negatives Philosophy

The pattern set prioritizes never allowing dangerous commands over avoiding false positives. A few extra prompts for manual confirmation are acceptable; lost work is not.

What It Blocks

Git Commands That Destroy Uncommitted Work

CommandReason
git reset --hardDestroys uncommitted changes
git reset --mergeDestroys uncommitted changes
git checkout -- <file>Discards file modifications
git restore <file> (without --staged)Discards uncommitted changes
git clean -fPermanently deletes untracked files

Git Commands That Destroy Remote History

CommandReason
git push --force / -fOverwrites remote commits
git branch -d, --delete, -D, -f, -M, -CDeletes or force-overwrites a user-owned branch ref

Git Commands That Destroy Stashed Work

CommandReason
git stash dropPermanently deletes a stash
git stash clearPermanently deletes all stashes

Filesystem Commands

CommandReason
rm -rf (outside /tmp, /var/tmp, $TMPDIR)Recursive deletion is dangerous

What It ALLOWS

Safe operations pass through silently:

Always Safe Git Operations

git status, git log, git diff, git add, git commit, git push, git pull, git fetch, read-only branch listings, git stash, git stash pop, git stash list

Explicitly Safe Patterns

PatternWhy Safe
git checkout -b <branch>Creating new branches
git checkout --orphan <branch>Creating orphan branches
git restore --staged <file>Unstaging only, doesn't touch working tree
git restore -S <file>Short flag for staged
git clean -n / --dry-runPreview mode, no actual deletion
rm -rf /tmp/*Temp directories are ephemeral
rm -rf $TMPDIR/*Shell variable forms

Safe Alternative: --force-with-lease

git push --force-with-lease   # ALLOWED - refuses if remote has unseen commits
git push --force              # BLOCKED - can overwrite others' work

Modular Pack System

DCG uses a modular "pack" system to organize patterns by category:

Core Packs (Always Enabled)

PackDescription
core.gitDestructive git commands
core.filesystemDangerous rm -rf outside temp

Database Packs

PackDescription
database.postgresqlDROP/TRUNCATE in PostgreSQL
database.mysqlDROP/TRUNCATE in MySQL/MariaDB
database.mongodbdropDatabase, drop()
database.redisFLUSHALL/FLUSHDB
database.sqliteDROP in SQLite

Container Packs

PackDescription
containers.dockerdocker system prune, docker rm -f
containers.composedocker-compose down --volumes
containers.podmanpodman system prune

Kubernetes Packs

PackDescription
kubernetes.kubectlkubectl delete namespace
kubernetes.helmhelm uninstall
kubernetes.kustomizekustomize delete patterns

Cloud Provider Packs

PackDescription
cloud.awsDestructive AWS CLI commands
cloud.gcpDestructive gcloud commands
cloud.azureDestructive az commands

Infrastructure Packs

PackDescription
infrastructure.terraformterraform destroy
infrastructure.ansibleDangerous ansible patterns
infrastructure.pulumipulumi destroy

System Packs

PackDescription
system.diskdd, mkfs, fdisk operations
system.permissionsDangerous chmod/chown patterns
system.servicessystemctl stop/disable patterns

Other Packs

PackDescription
strict_gitExtra paranoid git protections
package_managersnpm unpublish, cargo yank

Configuring Packs

# ~/.config/dcg/config.toml
[packs]
enabled = [
    "database.postgresql",
    "containers.docker",
    "kubernetes",  # Enables all kubernetes sub-packs
]

Environment Variables

VariableDescription
DCG_PACKS="containers.docker,kubernetes"Enable packs (comma-separated)
DCG_DISABLE="kubernetes.helm"Disable packs/sub-packs
DCG_VERBOSE=1Verbose output
DCG_COLOR=auto|always|neverColor mode
DCG_BYPASS=1Bypass DCG entirely (escape hatch)

Installation

Quick Install (Recommended)

curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.sh?$(date +%s)" | bash

# Easy mode: auto-update PATH
curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.sh?$(date +%s)" | bash -s -- --easy-mode

# System-wide (requires sudo)
curl -fsSL "https://raw.githubusercontent.com/Dicklesworthstone/destructive_command_guard/main/install.sh?$(date +%s)" | sudo bash -s -- --system

From Source (Requires Rust Nightly)

cargo +nightly install --git https://github.com/Dicklesworthstone/destructive_command_guard

Prebuilt Binaries

Available for: Linux x86_64, Linux ARM64, macOS Intel, macOS Apple Silicon, Windows

Claude Code Configuration

Add to ~/.claude/settings.json:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash|PowerShell",
        "hooks": [
          {
            "type": "command",
            "command": "/absolute/path/to/dcg"
          }
        ]
      }
    ]
  }
}

Replace /absolute/path/to/dcg with the exact resolved binary path. Do not use bare dcg: non-interactive hook shells may not inherit the interactive PATH. On native Windows, use install.ps1 so the hook receives the PowerShell-safe absolute command and explicit shell selection.

Important: Restart Claude Code after adding the hook.

How It Works

Processing Pipeline

┌─────────────────────────────────────────────────────────────────┐
│                        Claude Code                               │
│  Agent executes `rm -rf ./build`                                │
└─────────────────────┬───────────────────────────────────────────┘
                      │
                      ▼ PreToolUse hook (stdin: JSON)
┌─────────────────────────────────────────────────────────────────┐
│                          dcg                                     │
│  ┌──────────────┐    ┌──────────────┐    ┌──────────────┐       │
│  │    Parse     │───▶│  Normalize   │───▶│ Quick Reject │       │
│  │    JSON      │    │   Command    │    │   Filter     │       │
│  └──────────────┘    └──────────────┘    └──────┬───────┘       │
│                                                  │               │
│                      ┌───────────────────────────┘               │
│                      ▼                                           │
│  ┌──────────────────────────────────────────────────────────┐   │
│  │                   Pattern Matching                        │   │
│  │   1. Check SAFE_PATTERNS (whitelist) ──▶ Allow if match  │   │
│  │   2. Check DESTRUCTIVE_PATTERNS ──────▶ Deny if match    │   │
│  │   3. No match ────────────────────────▶ Allow (default)  │   │
│  └──────────────────────────────────────────────────────────┘   │
└─────────────────────┬───────────────────────────────────────────┘
                      │
                      ▼ stdout: JSON (deny) or empty (allow)

Stage 1: JSON Parsing

  • Reads hook input from stdin
  • Validates Claude Code's PreToolUse format
  • Non-Bash tools immediately allowed

Stage 2: Command Normalization

  • Strips absolute paths: /usr/bin/git statusgit status
  • Preserves argument paths

Stage 3: Quick Rejection Filter

  • SIMD-accelerated substring search for "git" or "rm"
  • Commands without these bypass regex entirely (99%+ of commands)

Stage 4: Pattern Matching

  • Safe patterns checked first (short-circuit on match → allow)
  • Destructive patterns checked second (match → deny)
  • No match → default allow

Exit Codes

CodeMeaning
0Command is safe, proceed
2Command is blocked, do not execute

CLI Usage

Test commands manually:

# Show version with build metadata
dcg --version

# Test a command
echo '{"tool_name":"Bash","tool_input":{"command":"git reset --hard"}}' | dcg

Example Block Mes


Content truncated.

When not to use it

  • Against adversarial attacks or malicious actors
  • To inspect contents of non-Bash scripts
  • For protecting committed but unpushed work

Prerequisites

Claude Code environmentRust runtime for hook execution

Limitations

  • Does not inspect contents of scripts like ./deploy.sh
  • Assumes the AI agent is well-intentioned but fallible
  • Does not protect against non-Bash commands

How it compares

Unlike manual review, this tool provides real-time, automated interception of specific dangerous commands using a high-performance Rust hook.

Compared to similar skills

dcg side by side with the closest alternatives in the catalog.

SkillInstallsUpdatedSafetyDifficulty
dcg (this skill)127dReviewIntermediate
ecc-safety-guard02moNo flagsIntermediate
linux-production-shell-scripts76moReviewIntermediate
audit-prep-assistant12moReviewIntermediate

Try saying

Example prompts that trigger this skill in your AI assistant.

You might also like

Search skills

Search the agent skills registry