选项

gateguard

affaan-m/ECC affaan-m/ECC

强制 AI 代理在编辑或执行破坏性命令之前进行调查,通过要求提供具体事实(如导入器、数据模式和用户说明)来提高代码质量。

...展开全部
0
更新时间 2026-10-01

GateGuard — 强制求证的行动前门槛

一个 PreToolUse 钩子,用于强制克劳德在编辑前进行调查。它不再依赖自我评估(“你确定吗?”),而是要求提供具体事实。调查这一行为所产生的觉察,是自我评估所无法达到的。

何时启用

  • 在任何文件编辑会影响多个模块的代码库中工作时
  • 包含具有特定模式或日期格式的数据文件的项目
  • AI 生成的代码必须符合现有模式的团队
  • 任何 Claude 倾向于凭猜测而非调查的工作流程

核心概念

LLM的自我评估行不通。若询问“你是否违反了任何政策?”,答案总是“没有”。这一点已通过实验验证。

但若询问“列出所有导入该模块的文件”,则会迫使LLM运行Grep和Read命令。这种调查行为本身会生成新的上下文,从而改变输出结果。

三阶段门控:

1. DENY  — block the first Edit/Write/Bash attempt
2. FORCE — tell the model exactly which facts to gather
3. ALLOW — permit retry after facts are presented

没有竞争对手能做到这三点。大多数止步于“否认”阶段。

证据

两项独立的A/B测试,使用相同的智能体,执行相同的任务:

任务 分阶段 无门控 差距
分析模块 8.0/10 6.5/10 +1.5
Webhook 验证器 10.0/10 7.0/10 +3.0
平均 9.0 6.75 +2.25

这两种代理生成的代码都能运行并通过测试。区别在于设计深度。

门类型

编辑/多文件编辑门(每个文件首次编辑)

多文件编辑的处理方式完全相同——批处理中的每个文件都会单独进行门控。

Before editing {file_path}, present these facts:

1. List ALL files that import/require this file (use Grep)
2. List the public functions/classes affected by this change
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim

写入门(首次创建新文件)

Before creating {file_path}, present these facts:

1. Name the file(s) and line(s) that will call this new file
2. Confirm no existing file serves the same purpose (use Glob)
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim

破坏性Bash门(每个破坏性命令)

触发条件: rm -rf, git reset --hard, git push --force, drop table等

1. List all files/data this command will modify or delete
2. Write a one-line rollback procedure
3. Quote the user's current instruction verbatim

常规 Bash 门控(每个会话一次)

1. The current user request in one sentence
2. What this specific command verifies or produces

快速入门

方案 A:使用 ECC 挂钩(零安装)

位于 scripts/hooks/gateguard-fact-force.js 已包含在此插件中。请通过 hooks.json 启用它。

如果GateGuard阻止了设置或修复操作,请使用 ECC_GATEGUARD=off。如需在钩子级别进行控制,请继续使用 ECC_DISABLED_HOOKS 并配合GateGuard挂钩ID。

在长时间会话中,仅前 GATEGUARD_FACT_FORCE_FULL_DENIALS 强制事实拒绝(默认 3 次)会触发完整的四事实阻塞;后续 拒绝将被压缩为一行,仅包含拒绝序号,因此 几乎相同的阻塞不会在上下文窗口中累积并 加剧模型重复循环(#2142)。 在呈现事实后重试同一文件或 命令,绝不会再次触发该门控机制。

选项 B:带配置的完整包

pip install gateguard-ai
gateguard init

此选项添加 .gateguard.yml 用于项目级配置(自定义消息、忽略路径、门控开关)。

反模式

  • 不要改用自评估。“你确定吗?”总是会得到“是”的回答。这一点已经通过实验得到验证。
  • 不要跳过数据模式检查。两个 A/B 测试代理都假设实际数据使用的是 ISO-8601 日期格式 %Y/%m/%d %H:%M时,两个 A/B 测试代理均默认使用 ISO-8601 日期格式。检查数据结构(使用遮蔽值)可完全避免此类缺陷。
  • 不要对每一条 Bash 命令都设置门控。常规 Bash 命令每会话仅需门控一次,而具有破坏性的 Bash 命令则需每次都进行门控。这种平衡既能避免系统变慢,又能有效防范真实风险。

最佳实践

  • 让门控机制自然触发。不要试图预先回答门控问题——调查过程本身才是提升质量的关键。
  • 根据您的领域自定义门控提示信息。如果您的项目有特定的约定,请将其添加到门控提示中。
  • 使用 .gateguard.yml 来忽略类似 .venv/, node_modules/, .git/.

相关技能

  • safety-guard ——运行时安全检查(互补而非重叠)
  • code-reviewer — 编辑后审查(GateGuard 属于编辑前审查)
在 GitHub 上查看
---
name: gateguard
description: Forces AI agents to investigate before editing or running destructive commands, improving code quality by requiring concrete facts like importers, data schemas, and user instructions.
---

# GateGuard — Fact-Forcing Pre-Action Gate

A PreToolUse hook that forces Claude to investigate before editing. Instead of self-evaluation ("are you sure?"), it demands concrete facts. The act of investigation creates awareness that self-evaluation never did.

## When to Activate

- Working on any codebase where file edits affect multiple modules
- Projects with data files that have specific schemas or date formats
- Teams where AI-generated code must match existing patterns
- Any workflow where Claude tends to guess instead of investigating

## Core Concept

LLM self-evaluation doesn't work. Ask "did you violate any policies?" and the answer is always "no." This is verified experimentally.

But asking "list every file that imports this module" forces the LLM to run Grep and Read. The investigation itself creates context that changes the output.

**Three-stage gate:**

```
1. DENY  — block the first Edit/Write/Bash attempt
2. FORCE — tell the model exactly which facts to gather
3. ALLOW — permit retry after facts are presented
```

No competitor does all three. Most stop at deny.

## Evidence

Two independent A/B tests, identical agents, same task:

| Task | Gated | Ungated | Gap |
| --- | --- | --- | --- |
| Analytics module | 8.0/10 | 6.5/10 | +1.5 |
| Webhook validator | 10.0/10 | 7.0/10 | +3.0 |
| **Average** | **9.0** | **6.75** | **+2.25** |

Both agents produce code that runs and passes tests. The difference is design depth.

## Gate Types

### Edit / MultiEdit Gate (first edit per file)

MultiEdit is handled identically — each file in the batch is gated individually.

```
Before editing {file_path}, present these facts:

1. List ALL files that import/require this file (use Grep)
2. List the public functions/classes affected by this change
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
```

### Write Gate (first new file creation)

```
Before creating {file_path}, present these facts:

1. Name the file(s) and line(s) that will call this new file
2. Confirm no existing file serves the same purpose (use Glob)
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
```

### Destructive Bash Gate (every destructive command)

Triggers on: `rm -rf`, `git reset --hard`, `git push --force`, `drop table`, etc.

```
1. List all files/data this command will modify or delete
2. Write a one-line rollback procedure
3. Quote the user's current instruction verbatim
```

### Routine Bash Gate (once per session)

```
1. The current user request in one sentence
2. What this specific command verifies or produces
```

## Quick Start

### Option A: Use the ECC hook (zero install)

The hook at `scripts/hooks/gateguard-fact-force.js` is included in this plugin. Enable it via hooks.json.

If GateGuard blocks setup or repair work, start the session with
`ECC_GATEGUARD=off`. For hook-level control, keep using
`ECC_DISABLED_HOOKS` with the GateGuard hook ID.

In long sessions, only the first `GATEGUARD_FACT_FORCE_FULL_DENIALS`
fact-force denials (default 3) emit the full four-fact block; later
denials are condensed to a single line carrying the denial ordinal, so
near-identical blocks cannot accumulate in the context window and
amplify model repetition loops (#2142). Retrying the same file or
command after presenting facts never re-triggers the gate.

### Option B: Full package with config

```bash
pip install gateguard-ai
gateguard init
```

This adds `.gateguard.yml` for per-project configuration (custom messages, ignore paths, gate toggles).

## Anti-Patterns

- **Don't use self-evaluation instead.** "Are you sure?" always gets "yes." This is experimentally verified.
- **Don't skip the data schema check.** Both A/B test agents assumed ISO-8601 dates when real data used `%Y/%m/%d %H:%M`. Checking data structure (with redacted values) prevents this entire class of bugs.
- **Don't gate every single Bash command.** Routine bash gates once per session. Destructive bash gates every time. This balance avoids slowdown while catching real risks.

## Best Practices

- Let the gate fire naturally. Don't try to pre-answer the gate questions — the investigation itself is what improves quality.
- Customize gate messages for your domain. If your project has specific conventions, add them to the gate prompts.
- Use `.gateguard.yml` to ignore paths like `.venv/`, `node_modules/`, `.git/`.

## Related Skills

- `safety-guard` — Runtime safety checks (complementary, not overlapping)
- `code-reviewer` — Post-edit review (GateGuard is pre-edit investigation)

所有文件

1 个文件

安装 gateguard

下载技能文件并将其解压到 .claude/skills/ 目录中。

下载ZIP

克隆仓库并复制技能文件到您的项目中。

git clone https://github.com/affaan-m/ECC/tree/main/skills/gateguard # Copy SKILL.md to your .claude/skills/ directory

复制 复制
快速设置: 将技能文件夹复制到 .claude/skills/ Claude 会自动检测并使用该技能
仓库 affaan-m/ECC

相关技能

algorithmic-art
更新时间 2026-08-27
systematic-debugging
更新时间 2026-09-03
tech-debt-tracker
更新时间 2026-08-29
continual-learning
更新时间 2026-09-10
OR