How to Set Up Claude Code Git Guardrails to Block Dangerous Commands

The git-guardrails-claude-code skill implements a PreToolUse hook that intercepts Claude Code's Bash tool invocations and returns exit code 2 when dangerous Git commands are detected, preventing accidental repository modifications before they execute.

Claude Code git guardrails protect your repositories from destructive operations like force pushes and hard resets. This safety mechanism from the mattpocock/skills repository works by registering a bash filter script that validates every Git command against a list of dangerous patterns before execution. By implementing these guardrails, you create a safety net that prevents Claude from executing commands that could damage your codebase.

How the Git Guardrails Work

The guardrails operate through a PreToolUse hook architecture that intercepts tool invocations before they reach the operating system.

The PreToolUse Hook Architecture

When Claude Code attempts to execute any Bash command, the PreToolUse matcher triggers the guardrail script. According to the implementation in git-guardrails-claude-code/scripts/block-dangerous-git.sh, the script reads JSON input from stdin containing the tool_input.command field, then validates it against a whitelist of dangerous patterns.

Pattern Matching and Blocking Logic

The script defines a DANGEROUS_PATTERNS array containing destructive Git operations including git push, git reset --hard, git clean -fd, git branch -D, and git checkout .. When the input command matches any pattern, the script outputs a BLOCKED message to stderr and returns exit code 2, signaling to Claude Code that it "does not have authority to access these commands."

Installing the Git Guardrails

You can install the guardrails either project-scoped or globally using the configuration files from the repository.

Copy the Guardrail Script

First, clone the repository and copy the hook script to your Claude configuration directory:


# Project-scoped installation

cp $(git rev-parse --show-toplevel)/git-guardrails-claude-code/scripts/block-dangerous-git.sh .claude/hooks/block-dangerous-git.sh

# Global installation

cp $(git rev-parse --show-toplevel)/git-guardrails-claude-code/scripts/block-dangerous-git.sh ~/.claude/hooks/block-dangerous-git.sh

chmod +x .claude/hooks/block-dangerous-git.sh

Configure Project-Level Settings

Add the PreToolUse hook to your project configuration in .claude/settings.json:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "$CLAUDE_PROJECT_DIR/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Configure Global Settings

For system-wide protection, update ~/.claude/settings.json:

{
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "~/.claude/hooks/block-dangerous-git.sh"
          }
        ]
      }
    ]
  }
}

Testing Your Guardrails

Verify the installation by simulating a blocked command:

echo '{"tool_input":{"command":"git push origin main"}}' \
  | .claude/hooks/block-dangerous-git.sh

The script should output:


BLOCKED: 'git push origin main' matches dangerous pattern 'git push'. The user has prevented you from doing this.

And return exit code 2.

Customizing Dangerous Patterns

Edit block-dangerous-git.sh to modify the DANGEROUS_PATTERNS array. Add new patterns to block additional commands, or remove existing ones if certain operations are safe for your workflow. Each pattern supports partial matching, so git push blocks all push operations including git push origin main and git push --force.

Summary

  • PreToolUse hooks intercept Bash commands before execution in Claude Code.
  • The block-dangerous-git.sh script matches commands against a DANGEROUS_PATTERNS array.
  • Exit code 2 aborts the tool invocation and displays a BLOCKED message.
  • Install project-scoped via .claude/settings.json or globally via ~/.claude/settings.json.
  • Default blocks include git push, git reset --hard, git clean -fd, git branch -D, and git checkout ..

Frequently Asked Questions

What Git commands are blocked by default?

The guardrails block git push, git reset --hard, git clean -fd, git branch -D, and git checkout . by default. These patterns are defined in the DANGEROUS_PATTERNS array within git-guardrails-claude-code/scripts/block-dangerous-git.sh.

Can I allow specific Git commands while blocking others?

Yes. Edit the DANGEROUS_PATTERNS array in block-dangerous-git.sh to remove patterns you want to allow, or add new patterns for additional restrictions. The script uses simple string matching, so you can specify exact commands or partial matches.

Why does the script return exit code 2 specifically?

Exit code 2 indicates a policy violation to Claude Code's tool execution system. When the PreToolUse hook returns non-zero, Claude aborts the operation and displays the stderr output, preventing any repository changes from occurring.

Will these guardrails work with global Claude Code configurations?

Yes. Configure the hook in ~/.claude/settings.json to apply the guardrails across all projects. Alternatively, use project-scoped configuration in .claude/settings.json for repository-specific rules.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →