Skip to content

Safety Rules

Hard prohibitions for all sessions. Extracted from ~/CLAUDE.md and .cursorrules.

Destructive command bans

  • No rm -rf (use safe-rm alias / explicit per-file removal)
  • No /bin/rm, /usr/bin/rm, sudo rm (bypass attempts)
  • No chmod 777, dd if=, mkfs.*, fork bombs

Git safety

  • No git push --force or git push -f (force push)
  • No git reset --hard on shared branches
  • No git checkout . or git clean -f (discards uncommitted work)
  • No git branch -D without confirmation
  • No direct commits to main, master, development, release/*
  • MR creation is authorized via the GitLab API, glab, or the issue page (operator ruling, 2026-09-21). Formula-driven creation is the preferred path where a formula exists — delivery/gitlab currently registers gitlab-mr-deliver and gitlab-push-mr. Do not cite a formula name that is not registered; verify it loads before depending on it. However created, every MR must require a governing Bead, target release/v0.1.x, link the Bead, link the GitLab issue WHEN ONE EXISTS — for bead-only work, state in the description that no GitLab issue exists rather than fabricating or opening one to satisfy the rule — record the source SHA and MR URL, enable source branch deletion after merge, emit gitlab.merge_request.opened, and route to WITNESS. Ad-hoc glab mr create outside a registered formula is still discouraged — it loses the Bead link and the receipt, which is what the old issue-page-only rule existed to protect. Do not create a per-MR exception.

Hook bypass bans

  • No --no-verify (bypass git hooks)
  • No HUSKY=0, LEFTHOOK=0 (bypass pre-commit)
  • No git commit -n (no-verify shorthand)
  • Pre-push hooks must pass before push

Secret hygiene

  • No tokens or secrets ever committed
  • 1Password is the sole secrets authority (op run / Service Accounts / Connect); never read or use ~/.tokens/*
  • 1Password env via op run --env-file=.op-env --account blueflyiollc -- <cmd>; env files hold op:// references only
  • Never echo, print, export, or inspect secret values (no op read into shell vars, no --no-masking)

File creation bans

  • No new local .md files at workspace root (use GitLab Wiki or update existing)
  • No .sh scripts (use BuildKit CLI or TypeScript tooling)
  • No services in platform-agents/ (use common_npm/ packages)
  • No edits inside llm-platform/web/ (use all_drupal_custom)

Branch / push protection

  • Branch from release/v*.x or feature branch — never main
  • Authoritative repos are rigs on Oracle at /home/ubuntu/gt/<rig>/ (no __BARE_REPOS/); never create .claude/worktrees/ inside a product rig
  • Pre-push: tests must pass; lefthook gates must succeed