# How to Set Up Claude Code Git Guardrails to Block Dangerous Commands

> Learn how to set up Claude Code git guardrails to block dangerous Git commands. Prevent accidental repository changes with this PreToolUse hook.

- Repository: [Matt Pocock/skills](https://github.com/mattpocock/skills)
- Tags: how-to-guide
- Published: 2026-04-04

---

**The git-guardrails-claude-code skill implements a PreToolUse hook that intercepts Claude Code's Bash tool invocations and returns exit code 2 when dangerous Git commands are detected, preventing accidental repository modifications before they execute.**

Claude Code git guardrails protect your repositories from destructive operations like force pushes and hard resets. This safety mechanism from the mattpocock/skills repository works by registering a bash filter script that validates every Git command against a list of dangerous patterns before execution. By implementing these guardrails, you create a safety net that prevents Claude from executing commands that could damage your codebase.

## How the Git Guardrails Work

The guardrails operate through a **PreToolUse** hook architecture that intercepts tool invocations before they reach the operating system.

### The PreToolUse Hook Architecture

When Claude Code attempts to execute any Bash command, the PreToolUse matcher triggers the guardrail script. According to the implementation in [`git-guardrails-claude-code/scripts/block-dangerous-git.sh`](https://github.com/mattpocock/skills/blob/main/git-guardrails-claude-code/scripts/block-dangerous-git.sh), the script reads JSON input from stdin containing the `tool_input.command` field, then validates it against a whitelist of dangerous patterns.

### Pattern Matching and Blocking Logic

The script defines a `DANGEROUS_PATTERNS` array containing destructive Git operations including `git push`, `git reset --hard`, `git clean -fd`, `git branch -D`, and `git checkout .`. When the input command matches any pattern, the script outputs a BLOCKED message to stderr and returns **exit code 2**, signaling to Claude Code that it "does not have authority to access these commands."

## Installing the Git Guardrails

You can install the guardrails either project-scoped or globally using the configuration files from the repository.

### Copy the Guardrail Script

First, clone the repository and copy the hook script to your Claude configuration directory:

```bash

# Project-scoped installation

cp $(git rev-parse --show-toplevel)/git-guardrails-claude-code/scripts/block-dangerous-git.sh .claude/hooks/block-dangerous-git.sh

# Global installation

cp $(git rev-parse --show-toplevel)/git-guardrails-claude-code/scripts/block-dangerous-git.sh ~/.claude/hooks/block-dangerous-git.sh

chmod +x .claude/hooks/block-dangerous-git.sh

```

### Configure Project-Level Settings

Add the PreToolUse hook to your project configuration in [`.claude/settings.json`](https://github.com/mattpocock/skills/blob/main/.claude/settings.json):

```json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

```

### Configure Global Settings

For system-wide protection, update `~/.claude/settings.json`:

```json
{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

```

## Testing Your Guardrails

Verify the installation by simulating a blocked command:

```bash
echo '{"tool_input":{"command":"git push origin main"}}' \
  | .claude/hooks/block-dangerous-git.sh

```

The script should output:

```

BLOCKED: 'git push origin main' matches dangerous pattern 'git push'. The user has prevented you from doing this.

```

And return **exit code 2**.

## Customizing Dangerous Patterns

Edit [`block-dangerous-git.sh`](https://github.com/mattpocock/skills/blob/main/block-dangerous-git.sh) to modify the `DANGEROUS_PATTERNS` array. Add new patterns to block additional commands, or remove existing ones if certain operations are safe for your workflow. Each pattern supports partial matching, so `git push` blocks all push operations including `git push origin main` and `git push --force`.

## Summary

- **PreToolUse hooks** intercept Bash commands before execution in Claude Code.
- The [`block-dangerous-git.sh`](https://github.com/mattpocock/skills/blob/main/block-dangerous-git.sh) script matches commands against a `DANGEROUS_PATTERNS` array.
- **Exit code 2** aborts the tool invocation and displays a BLOCKED message.
- Install project-scoped via [`.claude/settings.json`](https://github.com/mattpocock/skills/blob/main/.claude/settings.json) or globally via `~/.claude/settings.json`.
- Default blocks include `git push`, `git reset --hard`, `git clean -fd`, `git branch -D`, and `git checkout .`.

## Frequently Asked Questions

### What Git commands are blocked by default?

The guardrails block `git push`, `git reset --hard`, `git clean -fd`, `git branch -D`, and `git checkout .` by default. These patterns are defined in the `DANGEROUS_PATTERNS` array within [`git-guardrails-claude-code/scripts/block-dangerous-git.sh`](https://github.com/mattpocock/skills/blob/main/git-guardrails-claude-code/scripts/block-dangerous-git.sh).

### Can I allow specific Git commands while blocking others?

Yes. Edit the `DANGEROUS_PATTERNS` array in [`block-dangerous-git.sh`](https://github.com/mattpocock/skills/blob/main/block-dangerous-git.sh) to remove patterns you want to allow, or add new patterns for additional restrictions. The script uses simple string matching, so you can specify exact commands or partial matches.

### Why does the script return exit code 2 specifically?

Exit code 2 indicates a policy violation to Claude Code's tool execution system. When the PreToolUse hook returns non-zero, Claude aborts the operation and displays the stderr output, preventing any repository changes from occurring.

### Will these guardrails work with global Claude Code configurations?

Yes. Configure the hook in `~/.claude/settings.json` to apply the guardrails across all projects. Alternatively, use project-scoped configuration in [`.claude/settings.json`](https://github.com/mattpocock/skills/blob/main/.claude/settings.json) for repository-specific rules.