Git Guardrails for Claude Code
Set up Claude Code hooks to block dangerous git commands (push, reset --hard, clean, branch -D, etc.) before they execute.
Setup Git Guardrails
Sets up a PreToolUse hook that intercepts and blocks dangerous git commands before Claude executes them.
What Gets Blocked
git push(all variants including--force)git reset --hardgit clean -f/git clean -fdgit branch -Dgit checkout ./git restore .
When blocked, Claude sees a message telling it that it does not have authority to access these commands.
Steps
1. Ask scope
Ask the user: install for this project only (.claude/settings.json) or all projects (~/.claude/settings.json)?
2. Copy the hook script
Copy the bundled script to the target location based on scope and make it executable with chmod +x.
3. Add hook to settings
Add the hook to the appropriate settings file, merging into existing hooks.PreToolUse array if needed.
4. Ask about customization
Ask if user wants to add or remove any patterns from the blocked list.
5. Verify
Run a quick test:
echo '{"tool_input":{"command":"git push origin main"}}' | /path/to/script
Should exit with code 2 and print a BLOCKED message to stderr.