Never let an agent run `rm -rf`, a force-drop, or a disk-level command without a human approval on the tool call.
For: Engineers running Claude Code with write access to a real repo or machine
Blocks any Bash tool call whose command matches a recursive or forced delete before the host executes it.
Blocks disk-level commands (format, dd to a device, filesystem wipe) outright — there is no approving path.
Escalates writes that resolve outside the repository root to a named approver instead of denying silently.
# Claude Code Destructive-Shell Gate
# Fork: adjust the command patterns and the workspace root for your setup.
# Wire it at PreToolUse in .claude/settings.json so the agent cannot choose
# whether to consult the gate.
apiVersion: decionis.dev/v1
kind: PolicyPack
metadata:
name: claude-code-destructive-shell-gate
surface: claude_code
standards: [SOC2-CC8.1, ISO27001-A.8.32]
defaults:
mode: shadow # shadow | enforce
emit_dossier: true
fail_closed: true # parse/eval failure denies the tool call
rules:
- name: recursive_delete_block
when: "tool == 'Bash'"
decision: |
BLOCK IF command matches '(^|\s)rm\s+(-[a-zA-Z]*r[a-zA-Z]*f|-[a-zA-Z]*f[a-zA-Z]*r)'
ALLOW OTHERWISE
reason_code: destructive_delete_blocked
- name: disk_and_device_guard
when: "tool == 'Bash'"
decision: |
BLOCK IF command matches '(mkfs|diskutil eraseDisk|dd\s+.*of=/dev/)'
ALLOW OTHERWISE
reason_code: disk_level_command_blocked
- name: out_of_workspace_write
when: "tool in ['Write', 'Edit', 'NotebookEdit']"
decision: |
ESCALATE IF not path.startswith(workspace.root)
ALLOW OTHERWISE
reason_code: write_outside_workspace
Fork it, change the thresholds to match your environment, and deploy in shadow mode first — it defaults to listen-only so nothing in your live pipeline changes.
Follow the install path for this surface, then paste the forked YAML as your policy config.