kendex.ai

Marketplaces / vanillagreencom/kendex / commit-guards

commit-guards

Hooks and skills that guard what gets committed

11 packages

PackageKind
commit-guards

Load to add, tune, or debug a commit guard lane, its git hooks, or COMMIT_GUARDS_* settings.

skill
doc-limits

Load to add, tune, or debug document byte ceilings and DOC_LIMITS_* settings.

skill
preflight

Load to run, tune, or debug preflight.

skill
block-bare-cd

Refuse a command with a line that is only a `cd`. Where the shell persists across tool calls (Claude Code) a bare cd re-roots every later command and every hook that judges the working directory, while instruction files and hook paths stay with the launch directory; a cd into a worktree inside the repository, Claude Code's default `.claude/worktrees/<name>/`, also loads that tree's instruction fil

hook
block-repo-copy

Block a copy (cp, rsync, tar, git clone) whose source names a `.git` or `target` path component and whose destination is under /tmp, /var/tmp or $TMPDIR. Suggests reading the source in place or building a minimal fixture.

hook
block-unsafe-rm

Block rm on shared directory roots, globs directly under them, child paths with . or .. segments, and paths that start with a variable that may expand empty. Keep a private mktemp directory and remove it in the same shell call. Not run on antigravity: its required command-safety companion does not name antigravity, whose payload is toolCall.args.

hook
block-argv-kill

Refuse a command that kills processes by name or by argv pattern (`pkill`, `killall`), whatever flags follow. On a machine where several agents share one checkout and its worktrees, a pattern that matches a tool's name matches every lane running that tool, the caller's own shell included when its command line holds the pattern. Names the accepted forms: `kill <pid>` on a PID the caller recorded wh

hook
block-worktree-refresh

Refuse a `kendex` command that writes the project scope (`refresh`, `apply`, `add`, `remove`, `update-pi`, `updates --apply`, `pin`, `fork`, `adopt`, `drift-hook`, `source add|remove|enable|disable`, `marketplace subscribe|unsubscribe`) when the working directory is a linked git worktree, the command does not name the global scope, and the project the write lands in is not the worktree's own; and

hook
pre-commit-check

On a git commit, defer to the working directory's armed git hooks — both pre-commit and commit-msg, marked and executable (the tracked commit-guards installer or kendex guard install arms them). Otherwise the commit is refused naming the tracked installer first, then kendex guard install: arming is the local act that says a person wants this repository's committed scripts run on their commits, and

hook
session-drift-check

On a fresh session start (not resume or compact), runs `kendex check --quiet --report-only` and surfaces kendex drift to the agent — outdated items (`kendex refresh`), items removed upstream (`kendex remove --kind <kind> <name>`, `--global` in a global section), unreachable sources, and packages not yet evaluated against their sources (a background refresh settles them). Outside a lane, prints not

hook
task-completed-check

Before a task is marked complete, runs `cargo clippy --workspace --all-targets -- -D warnings` against the repository's Cargo.toml, or the nearest one above a changed file when the root has none, whenever a Rust file changed in the working tree, the index or as an untracked file, and refuses the completion naming the first error lines, or the output tail when there are none. Rust only. Not run on

hook