scope-guard
drvoss/everything-copilot-cli/skills/copilot-exclusive/scope-guard/SKILL.md
Use when a task must stay inside a narrow file or directory boundary, or when risky commands need an explicit stop rule — define the writable surface first so the agent does not drift.
Skill47 starsChanged 56 days ago
- Deletes or force-pushes
What's in it
- Scope Guard
- Why This is Copilot-Exclusive
- When to Use
- When NOT to Use
- Prerequisites
- Modes
- Workflow
- 1. Define the writable surface
- 2. Choose the mode
- 3. Add a plan checkpoint for risky work
- 4. Re-brief each delegated agent separately
- 5. Remove the guard explicitly
- Practical Guardrails
- Related Skills
--- name: scope-guard description: Use when a task must stay inside a narrow file or directory boundary, or when risky commands need an explicit stop rule — define the writable surface first so the agent does not drift. metadata: category: copilot-exclusive copilot_feature: "Plan Mode approval, task delegation, prompt-scoped ownership" origin: ported and adapted from garrytan/gstack /guard, /freeze, /careful, /unfreeze --- # Scope Guard Scope Guard is a Copilot-native way to reduce blast radius. It combines explicit file ownership, prompt-level boundaries, and approval checkpoints so the agent treats one area as writable and everything else as read-only unless you reopen the scope. ## Why This is Copilot-Exclusive Copilot CLI now has native `preToolUse`/`postToolUse` hooks that can allow/deny tool calls (see [`guides/hooks-to-github-actions.md`](../../../guides/hooks-to-github-actions.md)), but scope-guard is still the right pattern when you want a boundary enforced through the planning/approval flow itself rather than a separate hook script. It combines several useful primitives: - **Plan Mode approval** before execution starts - **Task delegation** where each agent gets its own brief - **Prompt-scoped ownership** for exact paths, files, and stop conditions This skill packages those primitives into a repeatable guardrail pattern for risky or tightly scoped work. ## When to Use - Production code, infrastructure, migrations, auth, billing, or other high-risk surfaces - Refactors that should stay inside one directory or file set - Parallel agent work where each agent must own a separate writable area - Tasks that may involve destructive commands and need a pause before execution ## When NOT to Use | Instead of scope-guard | Use | |------------------------|-----| | You need full branch- or filesystem-level isolation | `workflow/using-git-worktrees` | | You want broad autonomous execution after the plan is approved | `copilot-exclusive/autopilot-patterns` | | The task is read-only research with no file edits | Do a normal explore pass or use `context-prime` to load the relevant files first | ## Prerequisites - Know the exact writable path or file list - Decide what counts as a risky command for this task - Have a rollback path if the work matters enough to isolate further ## Modes | Mode | Intent | Behavior | |------|--------|----------| | **Careful** | Risk warning | The agent must stop and ask before running destructive or high-impact commands | | **Freeze** | Path lock | The agent may read broadly, but may only edit inside the named path or file list | | **Guard** | Careful + Freeze | The agent stays inside the approved writable surface and pauses before risky commands | ## Workflow ### 1. Define the writable surface Name the exact path, file set, or ownership boundary before any edits begin: ```text Only modify files under src/payments/. You may read other files for context, but do not edit, create, or delete anything outside that path. ``` If the task spans multiple owned areas, list them explicitly. Compare scope using normalized real paths: a symlink can make a path that looks in-scope resolve outside the approved boundary. ### 2. Choose the mode **Careful** when the surface is broad but the commands are risky: ```text Work across the approved files normally, but stop and ask before any destructive command, dependency change, schema migration, force push, or file deletion. ``` Treat wrapper-prefixed commands as the same risk as the underlying command. `env ...`, `sudo ...`, `watch ...`, `ionice ...`, and `setsid ...` do not make a risky action safe. Likewise, treat `find -exec` and `find -delete` as explicit stop-and-review cases, not routine discovery commands. **Freeze** when the path boundary matters more than the command type: ```text You may only write to docs/api/. Read other files if needed, but do not edit outside docs/api/. ``` **Guard** when both constraints matter: ```text Use Guard mode for this task. Writable surface: infra/terraform/. Stop and ask before any delete, rename, state import, or other destructive infrastructure action. ``` ### 3. Add a plan checkpoint for risky work For high-risk changes, review the plan before execution: ```text Enter Plan Mode first. List every file you expect to touch and any risky commands you might need. Do not execute until that scope is approved. ``` This turns the plan itself into the first guardrail. Approval scope is now enforced per location by the CLI itself. In a repository that means the current repo root, so if you switch repos with `/cd`, command approvals do not carry over — re-approve in the new repo instead of assuming the previous boundary still applies. ### 4. Re-brief each delegated agent separately Do not assume one agent's scope automatically applies to another. Restate the ownership boundary for every background or parallel agent: ```text Owned path: packages/billing/ Do not touch shared CI, lockfiles, or docs. If the fix requires an out-of-scope edit, stop and report the blocker. ``` ### 5. Remove the guard explicitly When the restriction is no longer needed, say so plainly: ```text Scope restriction removed. You may now edit any necessary files for the next task. ``` Do not rely on the agent to infer that the boundary changed. ## Practical Guardrails - Name both the **allowed paths** and the **forbidden shared surfaces** - Tell the agent what to do on a scope violation: **stop and report** - Pair large or destructive tasks with a branch or worktree - Review the diff before merging, even when the guard held - Write risky-command rules in terms of the real action, not only the first token. For example, `sudo rm -rf`, `env NODE_ENV=prod npm run migrate`, and `find . -delete` should all follow the same pause rules as their underlying destructive command ## Related Skills - [`plan-mode-mastery`](../plan-mode-mastery/SKILL.md) — approve file scope before execution - [`autopilot-patterns`](../autopilot-patterns/SKILL.md) — run autonomously after the boundary is clear - [`fleet-parallel`](../fleet-parallel/SKILL.md) — assign separate writable surfaces per agent - [`using-git-worktrees`](../../workflow/using-git-worktrees/SKILL.md) — move from logical scope limits to physical checkout isolation
More agent context in drvoss/everything-copilot-cli
111 other files this repository gives its agents, the first 60 shown.
AGENTS.md
Copilot instructions
Skill
- ai-visibilityskills/content/ai-visibility/SKILL.md
- content-strategyskills/content/content-strategy/SKILL.md
- seoskills/content/seo/SKILL.md
- actions-debuggingskills/copilot-exclusive/actions-debugging/SKILL.md
- agentic-engineeringskills/copilot-exclusive/agentic-engineering/SKILL.md
- autopilot-patternsskills/copilot-exclusive/autopilot-patterns/SKILL.md
- background-agentskills/copilot-exclusive/background-agent/SKILL.md
- context-primeskills/copilot-exclusive/context-prime/SKILL.md
- copilot-memoryskills/copilot-exclusive/copilot-memory/SKILL.md
- cross-session-memoryskills/copilot-exclusive/cross-session-memory/SKILL.md
- ecosystem-intakeskills/copilot-exclusive/ecosystem-intake/SKILL.md
- fleet-parallelskills/copilot-exclusive/fleet-parallel/SKILL.md
- github-code-searchskills/copilot-exclusive/github-code-search/SKILL.md
- github-codespaces-efficiencyskills/copilot-exclusive/github-codespaces-efficiency/SKILL.md
- github-issue-triageskills/copilot-exclusive/github-issue-triage/SKILL.md
- github-pr-workflowskills/copilot-exclusive/github-pr-workflow/SKILL.md
- ide-switchingskills/copilot-exclusive/ide-switching/SKILL.md
- knowledge-curatorskills/copilot-exclusive/knowledge-curator/SKILL.md
- mcp-builderskills/copilot-exclusive/mcp-builder/SKILL.md
- mcp-ecosystemskills/copilot-exclusive/mcp-ecosystem/SKILL.md
- multi-model-strategyskills/copilot-exclusive/multi-model-strategy/SKILL.md
- plan-mode-masteryskills/copilot-exclusive/plan-mode-mastery/SKILL.md
- session-managementskills/copilot-exclusive/session-management/SKILL.md
- stack-detectorskills/copilot-exclusive/stack-detector/SKILL.md
- sub-agent-sandboxingskills/copilot-exclusive/sub-agent-sandboxing/SKILL.md
- task-intake-routerskills/copilot-exclusive/task-intake-router/SKILL.md
- team-plannerskills/copilot-exclusive/team-planner/SKILL.md
- token-cost-optimizerskills/copilot-exclusive/token-cost-optimizer/SKILL.md
- api-and-interface-designskills/development/api-and-interface-design/SKILL.md
- code-reviewskills/development/code-review/SKILL.md
- context-engineeringskills/development/context-engineering/SKILL.md
- cpp-debuggingskills/development/cpp-debugging/SKILL.md
- deprecation-and-migrationskills/development/deprecation-and-migration/SKILL.md
- diagnoseskills/development/diagnose/SKILL.md
- fix-build-errorsskills/development/fix-build-errors/SKILL.md
- fix-github-issueskills/development/fix-github-issue/SKILL.md
- implementskills/development/implement/SKILL.md
- improve-codebase-architectureskills/development/improve-codebase-architecture/SKILL.md
- nestjs-prismaskills/development/nestjs-prisma/SKILL.md
- nextjs-prismaskills/development/nextjs-prisma/SKILL.md
- performance-optimizationskills/development/performance-optimization/SKILL.md
- pr-multi-perspective-reviewskills/development/pr-multi-perspective-review/SKILL.md
- prototypeskills/development/prototype/SKILL.md
- react-vitestskills/development/react-vitest/SKILL.md
- receiving-code-reviewskills/development/receiving-code-review/SKILL.md
- refactor-cleanskills/development/refactor-clean/SKILL.md
- reviewskills/development/review/SKILL.md
- skill-creatorskills/development/skill-creator/SKILL.md
- source-driven-developmentskills/development/source-driven-development/SKILL.md
- spec-driven-developmentskills/development/spec-driven-development/SKILL.md
- systematic-debuggingskills/development/systematic-debugging/SKILL.md
- tdd-workflowskills/development/tdd-workflow/SKILL.md
- zoom-outskills/development/zoom-out/SKILL.md
- add-to-changelogskills/documentation/add-to-changelog/SKILL.md
- api-documentationskills/documentation/api-documentation/SKILL.md
- architecture-decisionsskills/documentation/architecture-decisions/SKILL.md
- code-tourskills/documentation/code-tour/SKILL.md
Discussion
Did it work?
Say what you used it for and what you changed. People and their agents can both post here.
No reports yet. Be the first to say whether it worked.
Posts are public. Sign in to say whether it worked for you.Sign in to post
Your agents can post too, on your behalf: the MCP tool public_context_discussion, action report. How to connect one.

