freeze
- 作者仓库星标 0
- 作者更新于 2026年8月24日 23:55
- 作者仓库 gstack
When to invoke this skill
Blocks Edit and Write outside the allowed path. Use when debugging to prevent accidentally "fixing" unrelated code, or when you want to scope changes to one module. Use when asked to "freeze", "restrict edits", "only edit this folder", or "lock down edits".
/freeze — Restrict Edits to a Directory
Lock file edits to a specific directory. Any Edit or Write operation targeting a file outside the allowed path will be blocked (not just warned).
mkdir -p ~/.gstack/analytics
echo '{"skill":"freeze","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}' >> ~/.gstack/analytics/skill-usage.jsonl 2>/dev/null || true
Setup
Ask the user which directory to restrict edits to. Use AskUserQuestion:
- Question: "Which directory should I restrict edits to? Files outside this path will be blocked from editing."
- Text input (not multiple choice) — the user types a path.
Once the user provides a directory path:
- Resolve it to an absolute path:
FREEZE_DIR=$(cd "<user-provided-path>" 2>/dev/null && pwd)
echo "$FREEZE_DIR"
- Ensure trailing slash and save to the freeze state file:
FREEZE_DIR="${FREEZE_DIR%/}/"
eval "$(~/.claude/skills/gstack/bin/gstack-paths)"
STATE_DIR="$GSTACK_STATE_ROOT"
mkdir -p "$STATE_DIR"
echo "$FREEZE_DIR" > "$STATE_DIR/freeze-dir.txt"
echo "Freeze boundary set: $FREEZE_DIR"
Tell the user: "Edits are now restricted to <path>/. Any Edit or Write
outside this directory will be blocked. To change the boundary, run /freeze
again. To remove it, run /unfreeze or end the session."
How it works
The hook reads file_path from the Edit/Write tool input JSON (shared
real-JSON extractor with /careful — one copy, sourced by both hooks), then
checks whether the path starts with the freeze directory. If not, it returns a
hookSpecificOutput payload with permissionDecision: "deny" to block the
operation (nested under hookSpecificOutput — Claude Code ignores a top-level
permissionDecision).
Polarity is fail-closed: a tool payload the hook cannot parse is DENIED, not
allowed — a boundary that fails open is not a boundary. A payload that parses
but has no file_path (a non-file tool) is allowed. Symlinks are resolved
through their FINAL component, so an in-boundary symlink pointing outside the
boundary is checked against its target.
The freeze boundary persists for the session via the state file. The hook script reads it on every Edit/Write invocation. Boundaries containing spaces are supported.
Notes
- The trailing
/on the freeze directory prevents/srcfrom matching/src-old - Freeze applies to Edit and Write tools only — Read, Bash, Glob, Grep are unaffected
- This prevents accidental edits, not a security boundary — Bash commands like
sedcan still modify files outside the boundary - To deactivate, run
/unfreezeor end the conversation
- 流狐分类
- 通用
- 作者声明 Agent
- 未找到明确声明;不据此推断已兼容或已测试
- 静态检查
- 92 / 100 · 启发式扫描,不代表运行安全
- 作者 / 版本 / 许可
- @garrytan · v0.1.0 · 未声明 license
- 流狐 Token 估算
- 低消耗
- 流狐接入估算
- 即装即用
- 是否需要外部 API Key
- 未发现要求
- 检测到的系统要求
- macOS · Linux · Windows
- 底层运行要求
- Bun
- 检测到的文件与系统行为
-
- 只读
- 允许写入 / 修改
- 检测到的网络行为
- 仅限本地
- 安装命令数
- 无(仅作为资料)
档案由构建时根据 SKILL.md 与安装命令自动衍生,可能与作者实际意图存在差异。
需要注意: 未限定 allowed-tools,默认拥有全部工具权限。
作者没有在当前 SKILL.md 中定义固定输出样例。 Blocks Edit and Write outside the allowed path. Use when debugging to prevent accidentally "fixing" unrelated code, or when you want to scope changes to one module.
Ask the user which directory to restrict edits to. Use AskUserQuestion: Question: "Which directory should I restrict edits to? Files outside this path will be blocked from editing." Text input (not multiple choice) — the user types a path.
The hook reads filepath from the Edit/Write tool input JSON (shared real-JSON extractor with /careful — one copy, sourced by both hooks), then checks whether the path starts with the freeze directory. If not, it returns a
The trailing / on the freeze directory prevents /src from matching /src-old Freeze applies to Edit and Write tools only — Read, Bash, Glob, Grep are unaffected This prevents accidental edits, not a security boundary — Bash commands like sed can still modify…
<!-- AUTO-GENERATED from SKILL.md.tmpl — do not edit directly -->
<!-- Regenerate: bun run gen:skill-docs -->
## When to invoke this skill
Blocks Edit and
Write outside the allowed path. Use when debugging to prevent accidentally
"fixing" unrelated code, or when you want to scope changes to one module.
Use when asked to "freeze", "restrict edits", "only edit this folder",
or "lock down edits".
# /freeze — Restrict Edits to a Directory
Lock file edits to a specific directory. Any Edit or Write operation targeting
a file outside the allowed path will be **blocked** (not just warned).
```bash
mkdir -p ~/.gstack/analytics
echo '{"skill":"freeze","ts":"'$(date -u +%Y-%m-%dT%H:%M:%SZ)'","repo":"'$(basename "$(git rev-parse --show-toplevel 2>/dev/null)" 2>/dev/null || echo "unknown")'"}' >> ~/.gstack/analytics/skill-usage.jsonl 2>/dev/null || true
```
## Setup
Ask the user which directory to restrict edits to. Use AskUserQuestion:
- Question: "Which directory should I restrict edits to? Files outside this path will be blocked from editing."
- Text input (not multiple choice) — the user types a path.
Once the user provides a directory path:
1. Resolve it to an absolute path:
```bash
FREEZE_DIR=$(cd "<user-provided-path>" 2>/dev/null && pwd)
echo "$FREEZE_DIR"
```
2. Ensure trailing slash and save to the freeze state file:
```bash
FREEZE_DIR="${FREEZE_DIR%/}/"
eval "$(~/.claude/skills/gstack/bin/gstack-paths)"
STATE_DIR="$GSTACK_STATE_ROOT"
mkdir -p "$STATE_DIR"
echo "$FREEZE_DIR" > "$STATE_DIR/freeze-dir.txt"
echo "Freeze boundary set: $FREEZE_DIR"
```
Tell the user: "Edits are now restricted to `<path>/`. Any Edit or Write
outside this directory will be blocked. To change the boundary, run `/freeze`
again. To remove it, run `/unfreeze` or end the session."
… 作者原文负责流程事实;流狐只索引当前章节、要点、文件与命令。
章节 -> When to invoke this skill → Setup → How it works → Notes
要点 -> blocked · Blocks Edit and Write outside the allowed path. · Lock file edits to a specific directory. · Ask the user which directory to restrict edits to. · - Question: "Which directory should I restrict edits to? · Tell the user: "Edits are now restricted to <path>/. · Polarity is fail-closed: a tool payload the hook cannot parse is DENIED, not allowed — a boundary that fails open is not a boundary. · The freeze boundary persists for the session via the state file.
文件/命令 -> <path>/ · /freeze · /unfreeze · filepath · hookSpecificOutput · permissionDecision: "deny" · permissionDecision · on the freeze directory prevents
内容 SHA-256 -> df348a37913c
设计思路
freeze是 gstack 的「编辑边界锁」——告诉 hook:从现在起,Edit / Write 工具只能改某个目录里的文件,超出边界直接 deny(不是 warn)。设计目的是给 agent 一个「围栏」,让它明确知道哪些文件是这个 task 该碰的,避免误改不相关代码。注意作者明确说这不是安全边界——bash sed这种命令仍然能在围栏外动文件,但能挡住 90% 的手滑误改。Setup 流程
设置完后会回执:「Edits are now restricted to
<path>/. Any Edit or Write outside this directory will be blocked. To change the boundary, run/freezeagain. To remove it, run/unfreezeor end the session.」工作机制
hook 读 Edit/Write 工具调用里的
file_path,检查它是否以 freeze directory 开头——不是就返回permissionDecision: "deny"直接拦截。关键边界条件
/src误匹配/src-old。sed/mv仍可绕过。/unfreeze解除。适合谁
不适合
配套
unfreeze(解除)、careful(命令级危险拦截)、git-guardrails-claude-code(git 级 PreToolUse 拦截)一起组成多层防护。