# $debug --mode Diagnose-only --module careful — Destructive Command Guardrails Safety mode is now **active**. Every bash command will be checked for destructive patterns before running. If a destructive command is detected, you'll be warned and can choose to proceed or cancel. Canonical execution does not write engagement analytics or telemetry. ## What's protected | Pattern | Example | Risk | |---------|---------|------| | `rm -rf` / `rm -r` / `rm --recursive` | `rm -rf /var/data` | Recursive delete | | `DROP TABLE` / `DROP DATABASE` | `DROP TABLE users;` | Data loss | | `TRUNCATE` | `TRUNCATE orders;` | Data loss | | `git push --force` / `-f` | `git push -f origin main` | History rewrite | | `git reset --hard` | `git reset --hard HEAD~3` | Uncommitted work loss | | `git checkout .` / `git restore .` | `git checkout .` | Uncommitted work loss | | `kubectl delete` | `kubectl delete pod` | Production impact | | `docker rm -f` / `docker system prune` | `docker system prune -a` | Container/image loss | ## Safe exceptions These patterns are allowed without warning: - `rm -rf node_modules` / `.next` / `dist` / `__pycache__` / `.cache` / `build` / `.turbo` / `coverage` ## How it works The hook reads the command from the tool input JSON, checks it against the patterns above, and returns `permissionDecision: "ask"` with a warning message if a match is found. You can always override the warning and proceed. To deactivate, end the conversation or start a new one. Hooks are session-scoped. ## Upstream judgment port: PR #679 [Match the user language](https://github.com/garrytan/gstack/pull/679) ### User-language rule Write questions, progress updates, reports, and artifacts in the language used by the user. Source material, code identifiers, commands, and quotations may remain in their original language when translating them would reduce accuracy.