Marketplaces / vanillagreencom/kendex / commit-guards
commit-guards
Hooks and skills that guard what gets committed
11 packages
| Package | Kind |
|---|---|
| commit-guards Load to add, tune, or debug a commit guard lane, its git hooks, or COMMIT_GUARDS_* settings. | skill |
| doc-limits Load to add, tune, or debug document byte ceilings and DOC_LIMITS_* settings. | skill |
| preflight Load to run, tune, or debug preflight. | skill |
| block-bare-cd Refuse a command with a line that is only a `cd`. Where the shell persists across tool calls (Claude Code) a bare cd re-roots every later command and every hook that judges the working directory, while instruction files and hook paths stay with the launch directory; a cd into a worktree inside the repository, Claude Code's default `.claude/worktrees/<name>/`, also loads that tree's instruction fil | hook |
| block-repo-copy Block a copy (cp, rsync, tar, git clone) whose source names a `.git` or `target` path component and whose destination is under /tmp, /var/tmp or $TMPDIR. Suggests reading the source in place or building a minimal fixture. | hook |
| block-unsafe-rm Block rm on shared directory roots, globs directly under them, child paths with . or .. segments, and paths that start with a variable that may expand empty. Keep a private mktemp directory and remove it in the same shell call. Not run on antigravity: its required command-safety companion does not name antigravity, whose payload is toolCall.args. | hook |
| block-argv-kill Refuse a command that kills processes by name or by argv pattern (`pkill`, `killall`), whatever flags follow. On a machine where several agents share one checkout and its worktrees, a pattern that matches a tool's name matches every lane running that tool, the caller's own shell included when its command line holds the pattern. Names the accepted forms: `kill <pid>` on a PID the caller recorded wh | hook |
| block-worktree-refresh Refuse a `kendex` command that writes the project scope (`refresh`, `apply`, `add`, `remove`, `update-pi`, `updates --apply`, `pin`, `fork`, `adopt`, `drift-hook`, `source add|remove|enable|disable`, `marketplace subscribe|unsubscribe`) when the working directory is a linked git worktree, the command does not name the global scope, and the project the write lands in is not the worktree's own; and | hook |
| pre-commit-check On a git commit, defer to the working directory's armed git hooks — both pre-commit and commit-msg, marked and executable (the tracked commit-guards installer or kendex guard install arms them). Otherwise the commit is refused naming the tracked installer first, then kendex guard install: arming is the local act that says a person wants this repository's committed scripts run on their commits, and | hook |
| session-drift-check On a fresh session start (not resume or compact), runs `kendex check --quiet --report-only` and surfaces kendex drift to the agent — outdated items (`kendex refresh`), items removed upstream (`kendex remove --kind <kind> <name>`, `--global` in a global section), unreachable sources, and packages not yet evaluated against their sources (a background refresh settles them). Outside a lane, prints not | hook |
| task-completed-check Before a task is marked complete, runs `cargo clippy --workspace --all-targets -- -D warnings` against the repository's Cargo.toml, or the nearest one above a changed file when the root has none, whenever a Rust file changed in the working tree, the index or as an untracked file, and refuses the completion naming the first error lines, or the output tail when there are none. Rust only. Not run on | hook |