Skip to content

toolkit: add a MERGE RULE PreToolUse guard (block gh pr merge, git tag, push to main) #751

Description

@genwave-radio

🎯 Problem

The MERGE RULE (never merge, tag, or push main without Dean's explicit per-action consent) lives only in prompt text and assistant memory. Every builder/reviewer subagent has Bash; nothing mechanical stops gh pr merge or git tag.

✅ Fix

Add a PreToolUse hook on Bash to .claude/settings.example.json and the active settings.local.json:

{ "matcher": "Bash", "hooks": [{ "type": "command",
  "command": "c=$(jq -r '.tool_input.command // empty'); case \"$c\" in *'gh pr merge'*|*'git push'*origin*main*|*'git tag'*) echo 'refuse: merge/tag/push-main needs Dean per-action consent (MERGE RULE)' >&2; exit 2;; esac; exit 0" }] }

Exit 2 blocks the call and feeds the message back to the model. Dean lifts it per action by running the command himself or temporarily editing the hook.

Depends on the hooks fix (stdin JSON, not $CLAUDE_FILE_PATHS).

📎 Source

docs/AI_TOOLKIT_AUDIT_CLAUDE.md F2b.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    P1High priorityenhancementNew feature or request

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions