Wip File Guard
Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Skill: Wip File Guard Owner: parkertoddbrooks Summary: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Tags: latest:1.9.72 Version history: v1.9.72 | 2026-04-21T21:24:57.219Z | user AI DevOps Toolbox v1.9.72 Promote v1.9.71-alpha series to stable Closes #256. Consolidates 21 alpha prereleases (v1.9.71-alpha.1 through v1.9.71-alpha.21) into a stable v1.9.72 release. No
Rank
62
Safety
84
Downloads
2.3k
Updated
Oct 9, 2026
Version
1.9.72
Source
CLAWHUB
About
What it does, and when to use it.
Capability contract not published. No trust telemetry is available yet. 2.3K downloads reported by the source. Last updated 10/9/2026.
Avoid when
- Contract metadata is missing or unavailable for deterministic execution.
Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing
Public facts
Every fact links back to the source it came from.
- Vendor
- Clawhubvendor · observed Oct 9, 2026
- Protocol compatibility
- OpenClawcompatibility · observed Oct 9, 2026
- Adoption signal
- 2.3K downloadsadoption · observed Oct 9, 2026
- Latest release
- 1.9.72release · observed Apr 21, 2026
- Handshake status
- UNKNOWNsecurity
Install and run
Setup complexity: low.
clawhub skill install s17620xzyc7kfan8m36at57m6n83h8he:wip-file-guard- Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.
- Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data.
Contract: missing
curl -s "https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/snapshot"
Documentation
CLAWHUB
160,000 characters of source documentation, loaded on request.
Extracted files
5 files captured from the source.
SKILL.md
---
name: wip-file-guard
description: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.
license: MIT
interface: [cli, module, hook, plugin, skill]
metadata:
display-name: "Identity File Protection"
version: "1.0.1"
homepage: "https://github.com/wipcomputer/wip-file-guard"
author: "Parker Todd Brooks"
category: dev-tools
capabilities:
- file-protection
- edit-blocking
- identity-guard
requires:
bins: [node]
openclaw:
requires:
bins: [node]
install:
- id: node
kind: node
package: "@wipcomputer/wip-file-guard"
bins: [wip-file-guard]
label: "Install via npm"
emoji: "🛡️"
compatibility: Requires node. Node.js 18+.
---
# wip-file-guard
Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.
## When to Use This Skill
**Use wip-file-guard for:**
- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten
- Blocking AI agents from replacing file content instead of extending it
- Surviving context compaction (behavioral rules get erased, but hooks don't)
**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.
### Do NOT Use For
- Protecting binary files or images
- Blocking all edits (it allows small edits, only blocks destructive ones)
- Repos without identity files
## How It Works
Two rules:
1. **Write is blocked** on protected files. Always. Use Edit instead.
2. **Edit is blocked** when it removes more than 2 net lines from a protected file.
### Protected Files
CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md
### Protected Patterns
Any file matching: memory, memories, journal, diary, daily log
## API Reference
### CLI
```bash
node guard.mjs --list # list protected files
bash test.sh # run test suite
```
### Claude Code Hook
Add to `~/.claude/settings.json`:
```json
{
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write",
"hooks": [
{
"type": "command",
"command": "node \"/path/to/wip-file-guard/guard.mjs\"",
"timeout": 5
}
]
}
]
}
}
```
## Troubleshooting
### Agent keeps trying to Write
The deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.
### Edit blocked unexpectedly
Check the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.README.md
###### WIP Computer [](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md) # File Guard PreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong. ## The Problem AI agents replace content instead of extending it. After context compaction, behavioral rules like "don't delete things" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time. File Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens. ## How It Works Two rules: 1. **Write is blocked** on protected files outside shared state paths. Use Edit instead. 2. **Edit is blocked** when it removes more than 2 net lines from a protected file (20 for shared state). 3. **Shared state paths** (e.g. `~/.openclaw/workspace/`) are always writable. These are live agent workspace files, not code. The agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it. ### Protected Files | File | What it protects | |------|-----------------| | `CLAUDE.md` | Project instructions, boot sequence, system docs | | `SHARED-CONTEXT.md` | Cross-agent shared state | | `SOUL.md` | Agent identity | | `IDENTITY.md` | Agent identity (alternate format) | | `CONTEXT.md` | Current state snapshot | | `TOOLS.md` | Tool and workflow rules | | `MEMORY.md` | Persistent memory and preferences | ## Install Open your AI coding tool and say: ``` Read the README at github.com/wipcomputer/wip-file-guard. Then explain to me: 1. What is this tool? 2. What does it do? 3. What would it change or fix in our current system? Then ask me: - Do you have more questions? - Do you want to integrate it into our system? - Do you want to clone it (use as-is) or fork i
_meta.json
{
"ownerId": "kn7b4mj57xb02gqhvjzgzkxq557zz95h",
"slug": "wip-file-guard",
"version": "1.9.72",
"publishedAt": 1776806697219
}CHANGELOG.md
# Changelog ## 1.0.2 (2026-04-08) Add `~/.openclaw/workspace/` to shared state paths. OpenClaw agent workspace files are live shared state, not code. The guard now checks shared state BEFORE exact-match protection, so workspace TOOLS.md, MEMORY.md, etc. can be written freely by the agent that owns them. Fixes Lēsa being unable to write her own workspace files after the guard was deployed to OpenClaw on Apr 4. ## 1.0.1 (2026-02-21) Align description, add SKILL.md, add badges, agent-driven install, REFERENCE.md
REFERENCE.md
###### WIP Computer
# wip-file-guard ... Reference
Manual install instructions, CLI usage, and customization.
## Install
Install to your LDM OS home:
```bash
mkdir -p ~/.ldm/extensions/wip-file-guard
cp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/
```
All config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.
## Claude Code
Add to `~/.claude/settings.json`:
```json
{
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write",
"hooks": [
{
"type": "command",
"command": "node ~/.ldm/extensions/wip-file-guard/guard.mjs",
"timeout": 5
}
]
}
]
}
}
```
## OpenClaw
```bash
cp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard
```
The `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.
## CLI
```bash
# List protected files
node guard.mjs --list
# Test the guard with a simulated input
echo '{"tool_name":"Write","tool_input":{"file_path":"/foo/CLAUDE.md"}}' | node guard.mjs
# Run the test suite
bash test.sh
```
## Customization
### Adding Protected Files
Edit the `PROTECTED` set in `guard.mjs`:
```javascript
const PROTECTED = new Set([
'CLAUDE.md',
'SHARED-CONTEXT.md',
'SOUL.md',
'IDENTITY.md',
'CONTEXT.md',
'TOOLS.md',
'MEMORY.md',
'YOUR-FILE-HERE.md', // add yours
]);
```
### Changing the Line Threshold
The default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:
```javascript
if (removed > 2) { // change 2 to your threshold
```AionUi
Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!
activepieces
AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents
cherry-studio
AI productivity studio with smart chat, autonomous agents, and 300+ assistants.
CopilotKit
The Frontend for Agents & Generative UI. React + Angular
Machine-readable data
The same record, as JSON, for agents and crawlers.
{
"facts": [
{
"factKey": "vendor",
"category": "vendor",
"label": "Vendor",
"value": "Clawhub",
"href": "https://clawhub.ai/parkertoddbrooks/skills/wip-file-guard",
"sourceUrl": "https://clawhub.ai/parkertoddbrooks/skills/wip-file-guard",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T16:38:13.640Z",
"isPublic": true
},
{
"factKey": "protocols",
"category": "compatibility",
"label": "Protocol compatibility",
"value": "OpenClaw",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/contract",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/contract",
"sourceType": "contract",
"confidence": "medium",
"observedAt": "2026-10-09T16:38:13.640Z",
"isPublic": true
},
{
"factKey": "traction",
"category": "adoption",
"label": "Adoption signal",
"value": "2.3K downloads",
"href": "https://clawhub.ai/parkertoddbrooks/wip-file-guard",
"sourceUrl": "https://clawhub.ai/parkertoddbrooks/wip-file-guard",
"sourceType": "profile",
"confidence": "medium",
"observedAt": "2026-10-09T16:38:13.640Z",
"isPublic": true
},
{
"factKey": "latest_release",
"category": "release",
"label": "Latest release",
"value": "1.9.72",
"href": "https://clawhub.ai/parkertoddbrooks/wip-file-guard",
"sourceUrl": "https://clawhub.ai/parkertoddbrooks/wip-file-guard",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-21T21:24:57.219Z",
"isPublic": true
},
{
"factKey": "handshake_status",
"category": "security",
"label": "Handshake status",
"value": "UNKNOWN",
"href": "https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/trust",
"sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/trust",
"sourceType": "trust",
"confidence": "medium",
"observedAt": null,
"isPublic": true
}
],
"events": [
{
"eventType": "release",
"title": "Release 1.9.72",
"description": "# AI DevOps Toolbox v1.9.72 ## Promote v1.9.71-alpha series to stable Closes #256. Consolidates 21 alpha prereleases (`v1.9.71-alpha.1` through `v1.9.71-alpha.21`) into a stable v1.9.72 release. No code changes beyond the version bump in the toolbox root `package.json`; the sub-tool code has been stable and dogfooded across the alpha iterations. ## Why The root `package.json` had been sitting at `1.9.71-alpha.21` without a stable promotion. That blocked `deploy-public.sh` from syncing the private repo to the public mirror ... the script gates public release on stable root versions. Symptom during 2026-04-21: wip-branch-guard sub-tool shipped stable (v1.9.82 → v1.9.83 → v1.9.84) to npm successfully, but the public `wipcomputer/wip-ai-devops-toolbox` GitHub releases page did not show any of them because `deploy-public.sh` refused to run with an alpha root. ## What's in the diff - `package.json` - Version bump `1.9.71-alpha.21` → `1.9.72` Everything else flows from `wip-release`: - CHANGELOG.md updated - Git tag `v1.9.72` - GitHub release on private repo - npm publish to `@latest` - `deploy-public.sh` runs, syncs private code (minus `ai/`) to `wipcomputer/wip-ai-devops-toolbox` - Public GitHub release created ## Sub-tool versions at this release | Sub-tool | npm version | |---|---| | `@wipcomputer/wip-branch-guard` | 1.9.84 | | Other sub-tools | See their individual `package.json` | The sub-tool releases have their own cadence; this release is purely the toolbox root bump. ## Co-authors Parker Todd Brooks, Lēsa (oc-lesa-mini, Opus 4.7), Claude Code (cc-mini, Opus 4.7).",
"href": "https://clawhub.ai/parkertoddbrooks/wip-file-guard",
"sourceUrl": "https://clawhub.ai/parkertoddbrooks/wip-file-guard",
"sourceType": "release",
"confidence": "medium",
"observedAt": "2026-04-21T21:24:57.219Z",
"isPublic": true
}
]
}Record generated Oct 9, 2026.
