local-cli-safetylisted
Install: claude install-skill catpilotai/catpilot-ai-guardrails
## Baseline
**Applies when:** Running `rm`/`find ... -delete`/`shred`/`dd` on paths outside the project or from a variable, `chmod`/`chown` with `-R` near credential directories, history-rewriting `git` commands, commands that start a network service, or anything piping credentials or `env` into a network request.
**Always:**
- Verify a destructive-command path is non-empty and not `/` or `$HOME` before running; never interpolate a bare, unguarded variable.
- Keep `chmod`/`chown` scoped, never recursive (`-R`) on `$HOME` or a credential directory (`~/.ssh`, `~/.aws`, etc.); tighten permissions, never loosen them.
- Treat `main`, `master`, `release/*`, `production`, `staging`, `develop`, `prod*` as protected: no history-rewriting `git` command against them; use `--force-with-lease` elsewhere.
- Bind development network services to `127.0.0.1`, never `0.0.0.0`, unless the user explicitly names external exposure.
- Keep credential paths and `env`/`printenv` output out of any network call, even to what looks like an internal URL.
- Scope `sudo` to the specific named command; run the minimum privileged step and return to the unprivileged shell.
**Never:**
- `rm -rf`/`find ... -delete` against an unset or unguarded variable, or any path outside the project directory.
- Recursive `chmod`/`chown` on `$HOME` or a credential directory, or world-readable/writable modes on credential files.
- `git push --force`/`push -f`, `reset --hard`, `clean -fd`, `filter-branch`, or `filter-repo`