Atlas / Skills / affaan-m / Safety Guard

Safety GuardSAFE

skills/affaan-m/safety-guard

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
1 documented
License
MIT
Stars
264,831
01

Overview

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

Read from source at commit fb3fb10d9622OBSERVED · 2026-09-22
02

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
codexmentioned
03

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

---
name: safety-guard
description: 本番システムでの作業時や、エージェントを自律的に実行する際に破壊的な操作を防ぐためにこのスキルを使用してください。
origin: ECC
---

# Safety Guard — 破壊的な操作の防止

## 使用するタイミング

- 本番システムでの作業時
- エージェントが自律的に動作している場合(フルオートモード)
- 特定のディレクトリへの編集を制限したい場合
- センシティブな操作時(マイグレーション、デプロイ、データ変更)

## 動作の仕組み

3つの保護モードがあります:

### モード1: Careful モード

実行前に破壊的なコマンドを検知して警告します:

```
監視するパターン:
- rm -rf(特に /、~、またはプロジェクトルート)
- git push --force
- git reset --hard
- git checkout .(全変更を破棄)
- DROP TABLE / DROP DATABASE
- docker system prune
- kubectl delete
- chmod 777
- sudo rm
- npm publish(誤公開)
- --no-verify を含む全コマンド
```

検知した場合: コマンドの内容を示し、確認を求め、より安全な代替手段を提示します。

### モード2: Freeze モード

特定のディレクトリツリーへのファイル編集をロックします:

```
/safety-guard freeze src/components/
```

`src/components/` 外への Write/Edit は説明付きでブロックされます。エージェントを特定の領域に集中させ、無関係なコードに触れないようにしたい場合に便利です。

### モード3: Guard モード(Careful + Freeze の組み合わせ)

両方の保護が有効になります。自律エージェントのための最大安全モードです。

```
/safety-guard guard --dir src/api/ --allow-read-all
```

エージェントはすべてを読み取れますが、`src/api/` にのみ書き込めます。破壊的なコマンドはどこでもブロックされます。

### ロック解除

```
/safety-guard off
```

## 実装

PreToolUse フックを使用して Bash、Write、Edit、MultiEdit ツールの呼び出しを検知します。実行前に、アクティブなルールに対してコマンド/パスを確認します。

## 統合

- `codex -a never` セッションでデフォルトで有効化する
- ECC 2.0 の可観測性リスクスコアリングと組み合わせる
- ブロックされた全アクションを `~/.claude/safety-guard.log` に記録する
04

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (0)

No findings outside the package's declared scope.

Gates applied: no_behavioural_pass.

Audited 2026-09-22 · audit v0.4.1 · source sha fb3fb10d9622full audit observations/trust-audit/skill/affaan-m__safety-guard.json · Report an issue / request a re-scan
05

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-09-22fb3fb10d9622SAFEB89first audit
06

Questions

What does the Safety Guard skill do?

The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.

Is Safety Guard safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Safety Guard access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Safety Guard work with?

Its documentation mentions codex. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (fb3fb10d9622), read on 2026-09-22. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement