/guard — Full safety mode

Skill mới trong bộ claudekit — /guard = safety first: /careful (warn destructive actions) + /freeze (lock scope, prevent accidental edits outside). Ideal cho debugging production incident hoặc refactoring shared infrastructure.

Tổng quan

/guard là combination của 2 safety mechanisms: 1. /careful — Warn destructive actions
  • Confirm before: rm, git reset, database migration
  • Log all commands
  • Ask “Are you sure?” cho high-risk ops
2. /freeze <dir> — Lock scope
  • Only allow edits inside frozen dir
  • Prevent accidental changes to other modules
  • Block: git reset outside scope, cross-module imports
  • /unfreeze to unlock
When to use /guard:
  • Debug production incident (minimize blast radius)
  • Refactor one critical module (protect others)
  • Work in shared infrastructure (prevent side effects)
  • New dev on legacy code (guardrail learning)

Prefix & flags


Workflow

1

Bước 1: Activate guard

  • Careful mode ON: destructive actions warn
  • Freeze ON: only src/api editable
  • Log: all commands tracked
2

Bước 2: Debug inside scope

  • Read logs, understand issue
  • Locate bug in src/api/
  • Make minimal fix
Blocked attempts:
  • Try edit src/ui/ → ERROR: “Outside frozen scope”
  • Try git reset --hard → WARN: “Destructive, confirm?”
3

Bước 3: Verify fix

  • /verify (test frozen scope only)
  • /run and test narrowly
  • Confirm bug gone
4

Bước 4: Unfreeze & ship

  • Ship PR
  • Deploy fix
  • Monitor

Ví dụ thực tế

Case 1: Production bug in payment API

Workflow:
  1. Prod alert: “Payment endpoint 500 error”
  2. /guard src/api/payment → scope locked
  3. Debug:
    • Check logs in src/api/payment/handlers.ts
    • Find bug: missing null check
    • Try edit src/types/Payment.ts → BLOCKED
    • Edit only handlers.ts
  4. /verify --coverage → test pass
  5. /unfreeze → ship hotfix

Case 2: Refactor shared auth module (complex)

Workflow:
  1. Big refactor: OAuth2 → OIDC migration
  2. /guard src/auth → protects everything else
  3. Refactor inside src/auth/:
    • oauth2.ts → oidc.ts
    • Update exports
    • Try modify consumer (src/api/) → BLOCKED
  4. /verify --coverage in locked scope
  5. Audit: make sure didn’t accidentally touch other modules
  6. /unfreeze → ship

Case 3: New dev learning codebase

Workflow:
  1. Junior dev: “Let me understand Button component”
  2. /guard src/components/Button → can’t break other components
  3. Edit, test, iterate → /run to see changes
  4. When confident: /unfreeze + work broader
  5. Reduces fear of “I might break something”

So sánh với skill khác


Common pitfalls

Sai lầm phổ biến:
  • Freeze scope quá rộng: /guard src/ → too broad, legitimate work blocked. Freeze smallest risky module
  • Forget /unfreeze: Guard persist across sessions. Check /guard status regularly
  • Try bypass freeze: Don’t comment it out or use shell tricks. Use /unfreeze explicitly (auditable)
  • Guard on dirty worktree: Freeze + uncommitted changes = confusion. Commit or stash first
  • Scope too narrow: /guard src/api/payment/handler.ts (single file) → might freeze too much. Consider /guard src/api/payment/
  • Disable careful warnings: “Warnings annoying” → don’t disable. Warnings exist for reason (protect prod)

FAQ

A: Technically yes, strategically no:
  • /unfreeze → explicit, auditable
  • Shell workarounds → bad, hidden
Use /unfreeze nếu truly need to edit outside. Better: re-evaluate scope scope.
A: Không nên. Warnings catch:
  • rm -rf typos
  • Accidental git reset --hard
  • Direct DB deletes
Ignore warnings = risk. If busy:
A: Yes, session-scoped:
  • Open new terminal → new guard state
  • Same terminal → guard persist
Check status: /guard status Clear: /unfreeze + close terminal
A: No. Only one /guard at a time:
To unfreeze first scope: /unfreeze
A: Depends IDE:
  • VSCode: Guard config → .vscode/settings.json (future)
  • CLI: Guard works at shell level (current)
For now: CLI only, works with any editor

Best practices

Guard protocol:
  1. Identify risky work (prod bug, critical refactor)
  2. Determine minimal safe scope
  3. /guard <scope> + document (issue comment)
  4. Work, verify, unfreeze
  5. Review: did guard catch anything? (feedback loop)

Xem thêm