072920ff0e
Claude must never execute destructive/irreversible commands (rm, git branch -d/-D, git push --delete, reset --hard, force-push, DROP, etc.) — it proposes them for the user to run. Enforced behaviorally in CLAUDE.md (authoritative) and as permissions.deny rules in .claude/settings.json (defense-in-depth). Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>