docs+config: never-delete policy — CLAUDE.md hard rule + .claude/settings.json deny list
Claude must never execute destructive/irreversible commands (rm, git branch -d/-D, git push --delete, reset --hard, force-push, DROP, etc.) — it proposes them for the user to run. Enforced behaviorally in CLAUDE.md (authoritative) and as permissions.deny rules in .claude/settings.json (defense-in-depth). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
This commit is contained in:
@@ -0,0 +1,35 @@
|
|||||||
|
{
|
||||||
|
"$comment": "Team-shared restricted options. Destructive/irreversible commands are DENIED so Claude proposes them for the user to run instead of executing them. Authoritative policy: see the 'Destructive operations — NEVER delete' section of CLAUDE.md.",
|
||||||
|
"permissions": {
|
||||||
|
"deny": [
|
||||||
|
"Bash(rm:*)",
|
||||||
|
"Bash(rmdir:*)",
|
||||||
|
"Bash(git branch -d:*)",
|
||||||
|
"Bash(git branch -D:*)",
|
||||||
|
"Bash(git branch --delete:*)",
|
||||||
|
"Bash(git push --delete:*)",
|
||||||
|
"Bash(git push -d:*)",
|
||||||
|
"Bash(git push origin --delete:*)",
|
||||||
|
"Bash(git push github --delete:*)",
|
||||||
|
"Bash(git push origin -d:*)",
|
||||||
|
"Bash(git push github -d:*)",
|
||||||
|
"Bash(git tag -d:*)",
|
||||||
|
"Bash(git tag --delete:*)",
|
||||||
|
"Bash(git remote remove:*)",
|
||||||
|
"Bash(git remote rm:*)",
|
||||||
|
"Bash(git reset --hard:*)",
|
||||||
|
"Bash(git clean -f:*)",
|
||||||
|
"Bash(git clean -d:*)",
|
||||||
|
"Bash(git clean -x:*)",
|
||||||
|
"Bash(git push --force:*)",
|
||||||
|
"Bash(git push -f:*)",
|
||||||
|
"Bash(git push --force-with-lease:*)",
|
||||||
|
"Bash(git checkout --:*)",
|
||||||
|
"PowerShell(Remove-Item:*)",
|
||||||
|
"PowerShell(rm:*)",
|
||||||
|
"PowerShell(del:*)",
|
||||||
|
"PowerShell(rmdir:*)",
|
||||||
|
"PowerShell(Clear-Content:*)"
|
||||||
|
]
|
||||||
|
}
|
||||||
|
}
|
||||||
@@ -2,6 +2,24 @@
|
|||||||
|
|
||||||
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
|
This file provides guidance to Claude Code (claude.ai/code) when working with code in this repository.
|
||||||
|
|
||||||
|
## Destructive operations — NEVER delete (hard rule)
|
||||||
|
|
||||||
|
**Claude must never EXECUTE a destructive or irreversible command. Always ask, and hand the user the exact command(s) to run themselves.**
|
||||||
|
|
||||||
|
This covers (non-exhaustively):
|
||||||
|
- Deleting files/directories: `rm`, `rm -rf`, `rmdir`, `del`, `Remove-Item`.
|
||||||
|
- Deleting branches: `git branch -d` / `-D`, `git push --delete`, `git push <remote> :branch`.
|
||||||
|
- Deleting tags/remotes: `git tag -d`, `git remote remove` / `rm`.
|
||||||
|
- Discarding work: `git reset --hard`, `git checkout -- <path>`, `git clean -f`.
|
||||||
|
- Force-pushing: `git push -f` / `--force` / `--force-with-lease`.
|
||||||
|
- Dropping data: `DROP`, `TRUNCATE`, destructive migrations.
|
||||||
|
|
||||||
|
Instead: print the command(s) in a fenced block with a one-line note on what each does and what it affects, and let the **user run them**. Never run them yourself, even when the desired outcome is clear — `rm` and `-d` are **prompted, never executed**.
|
||||||
|
|
||||||
|
Leave regular branches alone (`main`, the active sprint branch) unless the user explicitly names them. Before calling any branch "stale", prove containment (`git branch --merged`, 0 unique commits) and report that evidence — do not act on it.
|
||||||
|
|
||||||
|
These are also enforced as `permissions.deny` rules in `.claude/settings.json` (defense-in-depth), but this behavioral rule is authoritative and covers cases the patterns can't.
|
||||||
|
|
||||||
## Commands
|
## Commands
|
||||||
|
|
||||||
```bash
|
```bash
|
||||||
|
|||||||
Reference in New Issue
Block a user