Git Guardrails for Claude Code
Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.
Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.
Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.
git push (all variants including --force)git reset --hardgit clean -f / git clean -fdgit branch -Dgit checkout . / git restore .When blocked, Claude sees a message telling it that it does not have authority to access these commands.
Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?
Copy the bundled script to the target location based on scope and make it executable with chmod +x.
Add the hook to the appropriate settings file, merging into existing hooks.PreToolUse array if needed.
Ask if user wants to add or remove any patterns from the blocked list.
Run a quick test:
echo '{"tool_input":{"command":"git push origin main"}}' | /path/to/script
Should exit with code 2 and print a BLOCKED message to stderr.