{"version":"1.0","workflow_uuid":"9894f476-bf15-511f-bac9-37c1724d040d","workflow_title":"Claude Code Safety Net — Block Destructive Commands","recommended_install":{"schema_version":1,"status":"confirm","policy":"confirm","install_mode":"single","target":"codex","command":"npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d --target codex","dry_run_command":"npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d --target codex --dry-run --json","runtime_commands":{"codex":"npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d --target codex","gemini":"npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d --target gemini","project":"npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d"},"prompt":"Install and make this TokRepo asset usable: \"Claude Code Safety Net — Block Destructive Commands\".\n\nPage: \nUUID: 9894f476-bf15-511f-bac9-37c1724d040d\nTarget adapter: codex\nPolicy/mode: confirm / single\n\nRead these machine-facing entry points first:\n- metadata: https://tokrepo.com/metadata/9894f476-bf15-511f-bac9-37c1724d040d.json\n- install contract: https://tokrepo.com/install-contract/9894f476-bf15-511f-bac9-37c1724d040d.json\n- install plan: https://api.tokrepo.com/api/v1/tokenboard/workflows/install-plan?uuid=9894f476-bf15-511f-bac9-37c1724d040d&target=codex\n- raw content: https://tokrepo.com/raw/9894f476-bf15-511f-bac9-37c1724d040d\n\nCommands:\n- choose the current runtime; do not use unsupported CLI targets.\n- Codex: npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d --target codex\n- Gemini CLI: npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d --target gemini\n- Claude Code / project agent: run npx -y tokrepo@latest install 9894f476-bf15-511f-bac9-37c1724d040d from the project root; add `--dry-run --json` first to inspect the plan.\n- add `--dry-run --json` to the chosen command first; after the plan allows it, run the chosen command.\n\nExecution rules:\n1. Run the dry-run command first to inspect writes, risks, and rollback.\n2. Confirm with the user which files or global config will change.\n3. After confirmation, run the install command and verify post_verify.\n\nReport back with changed files, verification result, and how to use the asset next.","next_steps":["Run the dry-run command first to inspect writes, risks, and rollback.","Confirm with the user which files or global config will change.","After confirmation, run the install command and verify post_verify."],"success_check":["The user confirmed the risk envelope.","The asset is installed or staged with rollback evidence."]},"install_contract":{"version":"1.0","installReady":false,"title":"Claude Code Safety Net — Block Destructive Commands","summary":"cc-safety-net adds a safety gate for Claude Code tool calls: explain/score risky commands (rm -rf, git resets) and validate custom rules (1,330★).","assetType":"Skills","pageUrl":"","sourceUrl":"https://github.com/kenryu42/claude-code-safety-net","intendedFor":[],"firstActions":[],"agentFirstSteps":[],"targetPaths":[],"verification":[],"startingPoints":[],"example":"","successOutcome":"","boundaries":[],"askUserIf":["the current workspace stack cannot be matched to a safe upstream template","the target path is not the project root, or an existing file should be merged instead of overwritten"]}}