/guard — Full safety mode
Skill mới trong bộ claudekit —
/guard = safety first: /careful (warn destructive actions) + /freeze (lock scope, prevent accidental edits outside). Ideal cho debugging production incident hoặc refactoring shared infrastructure.Tổng quan
/guard là combination của 2 safety mechanisms:
1. /careful — Warn destructive actions
- Confirm before:
rm, git reset, database migration - Log all commands
- Ask “Are you sure?” cho high-risk ops
/freeze <dir> — Lock scope
- Only allow edits inside frozen dir
- Prevent accidental changes to other modules
- Block: git reset outside scope, cross-module imports
/unfreezeto unlock
/guard:
- Debug production incident (minimize blast radius)
- Refactor one critical module (protect others)
- Work in shared infrastructure (prevent side effects)
- New dev on legacy code (guardrail learning)
Prefix & flags
Workflow
1
Bước 1: Activate guard
- Careful mode ON: destructive actions warn
- Freeze ON: only
src/apieditable - Log: all commands tracked
2
Bước 2: Debug inside scope
- Read logs, understand issue
- Locate bug in
src/api/ - Make minimal fix
- Try edit
src/ui/→ ERROR: “Outside frozen scope” - Try
git reset --hard→ WARN: “Destructive, confirm?”
3
Bước 3: Verify fix
/verify(test frozen scope only)/runand test narrowly- Confirm bug gone
4
Bước 4: Unfreeze & ship
- Ship PR
- Deploy fix
- Monitor
Ví dụ thực tế
Case 1: Production bug in payment API
- Prod alert: “Payment endpoint 500 error”
/guard src/api/payment→ scope locked- Debug:
- Check logs in
src/api/payment/handlers.ts - Find bug: missing null check
- Try edit
src/types/Payment.ts→ BLOCKED - Edit only
handlers.ts
- Check logs in
/verify --coverage→ test pass/unfreeze→ ship hotfix
Case 2: Refactor shared auth module (complex)
- Big refactor: OAuth2 → OIDC migration
/guard src/auth→ protects everything else- Refactor inside
src/auth/:oauth2.ts→oidc.ts- Update exports
- Try modify consumer (
src/api/) → BLOCKED
/verify --coveragein locked scope- Audit: make sure didn’t accidentally touch other modules
/unfreeze→ ship
Case 3: New dev learning codebase
- Junior dev: “Let me understand Button component”
/guard src/components/Button→ can’t break other components- Edit, test, iterate → /run to see changes
- When confident:
/unfreeze+ work broader - Reduces fear of “I might break something”
So sánh với skill khác
Common pitfalls
Sai lầm phổ biến:
- Freeze scope quá rộng:
/guard src/→ too broad, legitimate work blocked. Freeze smallest risky module - Forget
/unfreeze: Guard persist across sessions. Check/guard statusregularly - Try bypass freeze: Don’t comment it out or use shell tricks. Use
/unfreezeexplicitly (auditable) - Guard on dirty worktree: Freeze + uncommitted changes = confusion. Commit or stash first
- Scope too narrow:
/guard src/api/payment/handler.ts(single file) → might freeze too much. Consider/guard src/api/payment/ - Disable careful warnings: “Warnings annoying” → don’t disable. Warnings exist for reason (protect prod)
FAQ
Q: Có thể bypass frozen scope không?
Q: Có thể bypass frozen scope không?
A: Technically yes, strategically no:
/unfreeze→ explicit, auditable- Shell workarounds → bad, hidden
/unfreeze nếu truly need to edit outside. Better: re-evaluate scope scope.Q: Careful warnings quá nhiều, skip không?
Q: Careful warnings quá nhiều, skip không?
A: Không nên. Warnings catch:
rm -rftypos- Accidental
git reset --hard - Direct DB deletes
Q: Guard config persist?
Q: Guard config persist?
A: Yes, session-scoped:
- Open new terminal → new guard state
- Same terminal → guard persist
/guard status
Clear: /unfreeze + close terminalQ: Multiple frozen scopes?
Q: Multiple frozen scopes?
A: No. Only one To unfreeze first scope:
/guard at a time:/unfreezeQ: Can /guard integrate with IDE?
Q: Can /guard integrate with IDE?
A: Depends IDE:
- VSCode: Guard config →
.vscode/settings.json(future) - CLI: Guard works at shell level (current)
Best practices
Guard protocol:
- Identify risky work (prod bug, critical refactor)
- Determine minimal safe scope
/guard <scope>+ document (issue comment)- Work, verify, unfreeze
- Review: did guard catch anything? (feedback loop)