dangerous-action-guard

SkillDev tools

Intercepts irreversible or destructive actions and requires explicit user confirmation before proceeding

Instructions available. Your AI can read the instructions. Execution depends on the setup they require.

Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.

Then ask your AI: use the dangerous-action-guard skill

What this skill tells your AI

The instructions your AI receives, as published by archieindian/openclaw-superpowers in skills/openclaw-native/dangerous-action-guard/SKILL.md and read by ahel’s review.

Before executing any irreversible or high-impact action, pause and get explicit user confirmation. Log every confirmed and rejected action to an audit trail.

Dangerous action categories

CategoryExamples
File destructionrm -rf, unlink, delete files, empty trash, wipe directories
Git destructivegit push --force, git reset --hard, git clean -f, git branch -D
External messagingSend email, post to Slack/Teams/Discord, publish social post, reply-all
FinancialConfirm purchase, submit payment, execute trade, cancel subscription
CredentialsRotate/delete API keys, modify OAuth apps, change passwords
InfrastructureDeploy to production, drop database, terminate server instance
Permission changesShare document, change access controls, make resource public

Confirmation protocol

When about to execute a dangerous action:

Step 1 — Pause before the action Do not execute the action yet. Write it to pending_action in state with a 5-minute expiry.

Step 2 — Describe to user Tell the user:

  • What you're about to do (exact command or operation)
  • What it will affect (files, people, systems)
  • Whether it's reversible and how (if at all)

Step 3 — Wait for explicit confirmation Accept only unambiguous affirmatives: "yes", "go ahead", "confirmed", "do it", "proceed". Do NOT proceed on: "maybe", "I think so", "sure I guess", or any other hedged response.

Step 4 — Execute within expiry window If confirmed, execute within 5 minutes. If the session lapsed or the user is no longer active, re-confirm.

Step 5 — Log to audit trail Write to state: action, timestamp, user confirmation phrase, outcome (executed / rejected / expired).

Approval expiry

Approvals expire after 5 minutes. If you execute a dangerous action more than 5 minutes after receiving confirmation, re-confirm with the user. Stale approvals from prior sessions never carry over.

Batch operations

For bulk operations (e.g. "delete all temp files"), list the specific items and the count before confirming — never confirm a batch without showing scope. If scope exceeds 10 items, show first 5 and the total count.

Audit trail

Every action — confirmed or rejected — is logged to state. Use python3 audit.py --history to review the full trail. The audit trail is the user's safety net for disputed actions.

Signals

GitHub stars
72
Forks
14
Last commit
May 2026

ahel review

  • K4info
    destructive
  • K4binfo
    destructive-scoped
  • K4info
    destructive (in example-state.yaml)

Automated review, not a security audit. Ruleset v1+k2.

Advanced
Item type
skill
Key
dangerous-action-guard
Source
github.com/archieindian/openclaw-superpowers
dangerous-action-guard: Skill · ahel