{"id":"dc1475fd-8c22-4290-9603-54441b3680a0","entityType":"agent","slug":"clawhub-parkertoddbrooks-wip-file-guard","name":"Wip File Guard","canonicalUrl":"https://www.xpersona.co/agent/clawhub-parkertoddbrooks-wip-file-guard","canonicalPath":"/agent/clawhub-parkertoddbrooks-wip-file-guard","generatedAt":"2026-10-09T21:19:13.020Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":null},"description":"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Skill: Wip File Guard Owner: parkertoddbrooks Summary: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Tags: latest:1.9.72 Version history: v1.9.72 | 2026-04-21T21:24:57.219Z | user AI DevOps Toolbox v1.9.72 Promote v1.9.71-alpha series to stable Closes #256. Consolidates 21 alpha prereleases (v1.9.71-alpha.1 through v1.9.71-alpha.21) into a stable v1.9.72 release. No","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 2.3K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17620xzyc7kfan8m36at57m6n83h8he:wip-file-guard","sourceUrl":"https://clawhub.ai/parkertoddbrooks/wip-file-guard","homepage":"https://clawhub.ai/parkertoddbrooks/skills/wip-file-guard","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/parkertoddbrooks/wip-file-guard","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/parkertoddbrooks/skills/wip-file-guard","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Skill: Wip File Guard Owner: parkertoddbrooks Summary: Hook th"},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":null},"stars":null,"forks":null,"downloads":2292,"packageName":null,"latestVersion":"1.9.72","tractionLabel":"2.3K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T16:38:13.640Z","lastCrawledAt":"2026-10-09T16:38:13.640Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T16:38:13.640Z","lastVerifiedAt":null,"highlights":[{"version":"1.9.72","createdAt":"2026-04-21T21:24:57.219Z","changelog":"# AI DevOps Toolbox v1.9.72 ## Promote v1.9.71-alpha series to stable Closes #256. Consolidates 21 alpha prereleases (`v1.9.71-alpha.1` through `v1.9.71-alpha.21`) into a stable v1.9.72 release. No code changes beyond the version bump in the toolbox root `package.json`; the sub-tool code has been stable and dogfooded across the alpha iterations. ## Why The root `package.json` had been sitting at `1.9.71-alpha.21` without a stable promotion. That blocked `deploy-public.sh` from syncing the private repo to the public mirror ... the script gates public release on stable root versions. Symptom during 2026-04-21: wip-branch-guard sub-tool shipped stable (v1.9.82 → v1.9.83 → v1.9.84) to npm successfully, but the public `wipcomputer/wip-ai-devops-toolbox` GitHub releases page did not show any of them because `deploy-public.sh` refused to run with an alpha root. ## What's in the diff - `package.json` - Version bump `1.9.71-alpha.21` → `1.9.72` Everything else flows from `wip-release`: - CHANGELOG.md updated - Git tag `v1.9.72` - GitHub release on private repo - npm publish to `@latest` - `deploy-public.sh` runs, syncs private code (minus `ai/`) to `wipcomputer/wip-ai-devops-toolbox` - Public GitHub release created ## Sub-tool versions at this release | Sub-tool | npm version | |---|---| | `@wipcomputer/wip-branch-guard` | 1.9.84 | | Other sub-tools | See their individual `package.json` | The sub-tool releases have their own cadence; this release is purely the toolbox root bump. ## Co-authors Parker Todd Brooks, Lēsa (oc-lesa-mini, Opus 4.7), Claude Code (cc-mini, Opus 4.7).","fileCount":10,"zipByteSize":11262},{"version":"1.9.68","createdAt":"2026-04-01T13:27:41.534Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.68 Closes #239 ## Four-track release pipeline The release tool now supports four tracks: alpha, beta, hotfix, and stable. This replaces the single-track model where every release was public. Alpha is silent (no public release notes by default). Beta publishes prerelease notes to the public repo. Hotfix publishes to npm @latest without syncing code to public. Stable is the full deploy: npm + code sync + release notes. Developers can iterate on private, ship betas to testers, and only go public when ready. Version numbering uses standard semver prereleases: `1.9.68-alpha.1`, `1.9.68-beta.1`. The installer (`ldm install --beta` / `--alpha`) pulls the right tag from npm.","fileCount":9,"zipByteSize":9205},{"version":"1.9.67","createdAt":"2026-03-31T07:27:51.593Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.67 **Date:** 2026-03-30 ## What changed ### Hardcoded path removal Two files in the devops toolbox had paths that assumed a specific username or iCloud layout. **ldm-jobs/backup.sh** referenced `/Users/lesa/Library/Mobile Documents/.../ldm/bin/` to find the `ldm` binary for scheduled backup jobs. This iCloud path was fragile (iCloud sync delays, different usernames). The script now uses `$HOME/.ldm/bin/` which is the standard LDM install location and works on any machine (#301). **test.sh** (the branch guard test harness) had `/Users/lesa` hardcoded for creating temp directories. It now uses `$HOME` so tests run correctly under any user account (#301). ### Earlier changes included in this release **v1.9.66** added auto-combine for release notes from batched PRs (#237). When multiple PRs are merged between releases, their individual RELEASE-NOTES files are automatically combined into a single changelog entry. **v1.9.65** fixed the scaffold-on-main issue (#223) where scaffolding left untracked files that blocked `git pull` on the main working tree. ## Why The backup job is scheduled via LaunchAgent and runs unattended. If the path to `ldm` is wrong, backups silently fail. Moving to `$HOME/.ldm/bin/` aligns with the standard LDM install path and eliminates the iCloud dependency. The test fix ensures CI and local test runs work for all contributors. ## Issues closed - #301 ## How to verify ```bash grep -r \"/Users/lesa\" ldm-jobs/ tools/wip-branch-guard/test.sh # Should return zero results ```","fileCount":9,"zipByteSize":9205},{"version":"1.9.66","createdAt":"2026-03-30T13:28:50.071Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.66 Auto-combine release notes when batching multiple PRs into a single release. ## The story When multiple PRs merge to main before wip-release runs, the release had no good way to gather all their stories. Each PR might have its own RELEASE-NOTES file committed on the branch, but once the branch merges and the file gets trashed, the next release only sees an empty repo root. The agent had to write a new RELEASE-NOTES file from scratch, losing the narrative that was already reviewed in each PR. Now wip-release looks back through git history. It finds every merge commit since the last tag, checks each one for RELEASE-NOTES files via `git diff-tree` and `git show`, and combines them into a single document. If only one PR had notes, it uses them as-is (fully backwards compatible). If multiple PRs had notes, it wraps them with per-PR section headers, strips duplicate top-level headings, and collects all issue references into a combined list at the end. The detection sits at priority 2.5 in the release notes cascade: after the single-file check (RELEASE-NOTES-v{ver}.md on disk) but before the dev-update fallback. A file on disk always wins. The merged-PR scan only kicks in when nothing is found on disk. ## What changed - New exported function `collectMergedPRNotes()` in `core.mjs` that scans git merge history for RELEASE-NOTES files - Updated `cli.js` to call it at priority 2.5 in the notes detection cascade - Updated help text to document the new detection path - Zero breaking changes. Single-file detection still works exactly as before. ## Issues closed - Closes #237 ## How to verify ```bash # In any repo with multiple merged PRs since last tag, each having RELEASE-NOTES files: wip-release patch --dry-run # Should show: \"Combined release notes from N merged PRs\" ```","fileCount":9,"zipByteSize":9205},{"version":"1.9.65","createdAt":"2026-03-29T23:57:29.591Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.65 **Fix release notes scaffold on protected branches** When `wip-release patch` runs on main without a RELEASE-NOTES file, it used to scaffold a template directly in the working tree. On repos with branch guards (pre-commit hooks that block commits to main), this scaffolded file could not be removed or committed. It would block `git pull` and leave the working tree dirty. This has happened multiple times across different repos. The fix adds a branch check before scaffolding. If the current branch is main or master, wip-release now prints a clear error telling the user to write release notes on their feature branch before merging, then exits non-zero without creating any files. The scaffold behavior still works on feature branches, where it's actually useful. ## Issues closed - Closes #223 ## How to verify ```bash # On main, without release notes: should error, NOT scaffold cd any-repo && git checkout main wip-release patch # Expected: \"Release notes missing. Write RELEASE-NOTES-v*.md on your feature branch before merging.\" # Expected: no RELEASE-NOTES file created in working tree # On a feature branch: should scaffold as before git checkout -b test/scaffold-check wip-release patch # Expected: scaffolded template created ```","fileCount":9,"zipByteSize":9205},{"version":"1.9.64","createdAt":"2026-03-29T23:38:36.209Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.64 Closes #295 ## Branch guard: allow extension cleanup The branch guard blocked `rm` on deployed extension directories (`~/.openclaw/extensions/` and `~/.ldm/extensions/`) because those paths live inside git repos. But deployed extensions are managed by `ldm install`, not by hand. When a stale `-private` extension needed to be removed (e.g. `wip-xai-grok-private` replaced by the public `wip-xai-grok`), the agent couldn't clean it up without asking the user to run the command manually. Added an allowlist pattern for `rm` targeting `.openclaw/extensions/` and `.ldm/extensions/` paths. Same approach as the existing `.ldm/state/` allowlist. The guard still blocks `rm` on actual repo source files.","fileCount":9,"zipByteSize":9205},{"version":"1.9.63","createdAt":"2026-03-29T19:12:05.975Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.63 **Fix all wip-release errors: branch cleanup crashes, shell injection, stale remote refs.** ## The story Every wip-release run produced errors: \"fatal: Not a valid object name +\", \"remote ref does not exist\", and shell injection risks from branch names passed through execSync template strings. These were dismissed as \"non-blocking\" but they cluttered every release output and masked real problems. Root cause: branch cleanup code (sections 10 and 11) used `execSync` with template strings, which breaks on branch names with special characters and allows shell injection. Also tried to delete remote branches that GitHub already deleted during PR merge. Fix: replaced all `execSync` template strings with `execFileSync` array args (safe from injection). Added character validation to skip branches with special chars. Wrapped remote delete in try/catch since GitHub PR merge already handles deletion. ## Issues closed - #231 (continued: release pipeline reliability) ## How to verify ```bash wip-release patch --dry-run # Should show no \"fatal\" or \"Not a valid object name\" errors # Guard tests: cd tools/wip-branch-guard && bash test.sh ```","fileCount":9,"zipByteSize":9165},{"version":"1.9.62","createdAt":"2026-03-29T19:05:47.637Z","changelog":"# Release Notes: wip-ai-devops-toolbox v1.9.62 **Fix wip-release leaving dirty state on main after every release.** ## The story wip-release writes to 15+ files during a release (root package.json, 12 sub-tool package.json files, SKILL.md, CHANGELOG.md, product docs, trashed release notes). But gitCommitAndTag() only staged 3 files (package.json, CHANGELOG.md, SKILL.md). The other 12+ files were left modified on disk, uncommitted. This blocked git pull on the next operation and required manual `git checkout -- .` every time. Fix: stage all files that wip-release modifies. Sub-tool package.json files, product docs (ai/product/), and trashed release notes (_trash/) are now included in the release commit. ## Issues closed - #231 (wip-release rollback version bumps on failure) ## How to verify ```bash wip-release patch git status # Should show clean working tree after release ```","fileCount":9,"zipByteSize":9165}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17620xzyc7kfan8m36at57m6n83h8he:wip-file-guard","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T21:19:13.018Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-parkertoddbrooks-wip-file-guard/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":null},"readme":"Skill: Wip File Guard\n\nOwner: parkertoddbrooks\n\nSummary: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\nTags: latest:1.9.72\n\nVersion history:\n\nv1.9.72 | 2026-04-21T21:24:57.219Z | user\n\n# AI DevOps Toolbox v1.9.72\n\n## Promote v1.9.71-alpha series to stable\n\nCloses #256.\n\nConsolidates 21 alpha prereleases (`v1.9.71-alpha.1` through `v1.9.71-alpha.21`) into a stable v1.9.72 release. No code changes beyond the version bump in the toolbox root `package.json`; the sub-tool code has been stable and dogfooded across the alpha iterations.\n\n## Why\n\nThe root `package.json` had been sitting at `1.9.71-alpha.21` without a stable promotion. That blocked `deploy-public.sh` from syncing the private repo to the public mirror ... the script gates public release on stable root versions.\n\nSymptom during 2026-04-21: wip-branch-guard sub-tool shipped stable (v1.9.82 → v1.9.83 → v1.9.84) to npm successfully, but the public `wipcomputer/wip-ai-devops-toolbox` GitHub releases page did not show any of them because `deploy-public.sh` refused to run with an alpha root.\n\n## What's in the diff\n\n- `package.json`\n  - Version bump `1.9.71-alpha.21` → `1.9.72`\n\nEverything else flows from `wip-release`:\n\n- CHANGELOG.md updated\n- Git tag `v1.9.72`\n- GitHub release on private repo\n- npm publish to `@latest`\n- `deploy-public.sh` runs, syncs private code (minus `ai/`) to `wipcomputer/wip-ai-devops-toolbox`\n- Public GitHub release created\n\n## Sub-tool versions at this release\n\n| Sub-tool | npm version |\n|---|---|\n| `@wipcomputer/wip-branch-guard` | 1.9.84 |\n| Other sub-tools | See their individual `package.json` |\n\nThe sub-tool releases have their own cadence; this release is purely the toolbox root bump.\n\n## Co-authors\n\nParker Todd Brooks, Lēsa (oc-lesa-mini, Opus 4.7), Claude Code (cc-mini, Opus 4.7).\n\nv1.9.68 | 2026-04-01T13:27:41.534Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.68\n\nCloses #239\n\n## Four-track release pipeline\n\nThe release tool now supports four tracks: alpha, beta, hotfix, and stable. This replaces the single-track model where every release was public.\n\nAlpha is silent (no public release notes by default). Beta publishes prerelease notes to the public repo. Hotfix publishes to npm @latest without syncing code to public. Stable is the full deploy: npm + code sync + release notes. Developers can iterate on private, ship betas to testers, and only go public when ready.\n\nVersion numbering uses standard semver prereleases: `1.9.68-alpha.1`, `1.9.68-beta.1`. The installer (`ldm install --beta` / `--alpha`) pulls the right tag from npm.\n\nv1.9.67 | 2026-03-31T07:27:51.593Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.67\n\n**Date:** 2026-03-30\n\n## What changed\n\n### Hardcoded path removal\n\nTwo files in the devops toolbox had paths that assumed a specific username or iCloud layout.\n\n**ldm-jobs/backup.sh** referenced `/Users/lesa/Library/Mobile Documents/.../ldm/bin/` to find the `ldm` binary for scheduled backup jobs. This iCloud path was fragile (iCloud sync delays, different usernames). The script now uses `$HOME/.ldm/bin/` which is the standard LDM install location and works on any machine (#301).\n\n**test.sh** (the branch guard test harness) had `/Users/lesa` hardcoded for creating temp directories. It now uses `$HOME` so tests run correctly under any user account (#301).\n\n### Earlier changes included in this release\n\n**v1.9.66** added auto-combine for release notes from batched PRs (#237). When multiple PRs are merged between releases, their individual RELEASE-NOTES files are automatically combined into a single changelog entry.\n\n**v1.9.65** fixed the scaffold-on-main issue (#223) where scaffolding left untracked files that blocked `git pull` on the main working tree.\n\n## Why\n\nThe backup job is scheduled via LaunchAgent and runs unattended. If the path to `ldm` is wrong, backups silently fail. Moving to `$HOME/.ldm/bin/` aligns with the standard LDM install path and eliminates the iCloud dependency. The test fix ensures CI and local test runs work for all contributors.\n\n## Issues closed\n\n- #301\n\n## How to verify\n\n```bash\ngrep -r \"/Users/lesa\" ldm-jobs/ tools/wip-branch-guard/test.sh\n# Should return zero results\n```\n\nv1.9.66 | 2026-03-30T13:28:50.071Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.66\n\nAuto-combine release notes when batching multiple PRs into a single release.\n\n## The story\n\nWhen multiple PRs merge to main before wip-release runs, the release had no good way to gather all their stories. Each PR might have its own RELEASE-NOTES file committed on the branch, but once the branch merges and the file gets trashed, the next release only sees an empty repo root. The agent had to write a new RELEASE-NOTES file from scratch, losing the narrative that was already reviewed in each PR.\n\nNow wip-release looks back through git history. It finds every merge commit since the last tag, checks each one for RELEASE-NOTES files via `git diff-tree` and `git show`, and combines them into a single document. If only one PR had notes, it uses them as-is (fully backwards compatible). If multiple PRs had notes, it wraps them with per-PR section headers, strips duplicate top-level headings, and collects all issue references into a combined list at the end.\n\nThe detection sits at priority 2.5 in the release notes cascade: after the single-file check (RELEASE-NOTES-v{ver}.md on disk) but before the dev-update fallback. A file on disk always wins. The merged-PR scan only kicks in when nothing is found on disk.\n\n## What changed\n\n- New exported function `collectMergedPRNotes()` in `core.mjs` that scans git merge history for RELEASE-NOTES files\n- Updated `cli.js` to call it at priority 2.5 in the notes detection cascade\n- Updated help text to document the new detection path\n- Zero breaking changes. Single-file detection still works exactly as before.\n\n## Issues closed\n\n- Closes #237\n\n## How to verify\n\n```bash\n# In any repo with multiple merged PRs since last tag, each having RELEASE-NOTES files:\nwip-release patch --dry-run\n# Should show: \"Combined release notes from N merged PRs\"\n```\n\nv1.9.65 | 2026-03-29T23:57:29.591Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.65\n\n**Fix release notes scaffold on protected branches**\n\nWhen `wip-release patch` runs on main without a RELEASE-NOTES file, it used to scaffold a\ntemplate directly in the working tree. On repos with branch guards (pre-commit hooks that\nblock commits to main), this scaffolded file could not be removed or committed. It would\nblock `git pull` and leave the working tree dirty. This has happened multiple times across\ndifferent repos.\n\nThe fix adds a branch check before scaffolding. If the current branch is main or master,\nwip-release now prints a clear error telling the user to write release notes on their\nfeature branch before merging, then exits non-zero without creating any files. The scaffold\nbehavior still works on feature branches, where it's actually useful.\n\n## Issues closed\n\n- Closes #223\n\n## How to verify\n\n```bash\n# On main, without release notes: should error, NOT scaffold\ncd any-repo && git checkout main\nwip-release patch\n# Expected: \"Release notes missing. Write RELEASE-NOTES-v*.md on your feature branch before merging.\"\n# Expected: no RELEASE-NOTES file created in working tree\n\n# On a feature branch: should scaffold as before\ngit checkout -b test/scaffold-check\nwip-release patch\n# Expected: scaffolded template created\n```\n\nv1.9.64 | 2026-03-29T23:38:36.209Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.64\n\nCloses #295\n\n## Branch guard: allow extension cleanup\n\nThe branch guard blocked `rm` on deployed extension directories (`~/.openclaw/extensions/` and `~/.ldm/extensions/`) because those paths live inside git repos. But deployed extensions are managed by `ldm install`, not by hand. When a stale `-private` extension needed to be removed (e.g. `wip-xai-grok-private` replaced by the public `wip-xai-grok`), the agent couldn't clean it up without asking the user to run the command manually.\n\nAdded an allowlist pattern for `rm` targeting `.openclaw/extensions/` and `.ldm/extensions/` paths. Same approach as the existing `.ldm/state/` allowlist. The guard still blocks `rm` on actual repo source files.\n\nv1.9.63 | 2026-03-29T19:12:05.975Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.63\n\n**Fix all wip-release errors: branch cleanup crashes, shell injection, stale remote refs.**\n\n## The story\n\nEvery wip-release run produced errors: \"fatal: Not a valid object name +\", \"remote ref does not exist\", and shell injection risks from branch names passed through execSync template strings. These were dismissed as \"non-blocking\" but they cluttered every release output and masked real problems.\n\nRoot cause: branch cleanup code (sections 10 and 11) used `execSync` with template strings, which breaks on branch names with special characters and allows shell injection. Also tried to delete remote branches that GitHub already deleted during PR merge.\n\nFix: replaced all `execSync` template strings with `execFileSync` array args (safe from injection). Added character validation to skip branches with special chars. Wrapped remote delete in try/catch since GitHub PR merge already handles deletion.\n\n## Issues closed\n\n- #231 (continued: release pipeline reliability)\n\n## How to verify\n\n```bash\nwip-release patch --dry-run\n# Should show no \"fatal\" or \"Not a valid object name\" errors\n# Guard tests: cd tools/wip-branch-guard && bash test.sh\n```\n\nv1.9.62 | 2026-03-29T19:05:47.637Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.62\n\n**Fix wip-release leaving dirty state on main after every release.**\n\n## The story\n\nwip-release writes to 15+ files during a release (root package.json, 12 sub-tool package.json files, SKILL.md, CHANGELOG.md, product docs, trashed release notes). But gitCommitAndTag() only staged 3 files (package.json, CHANGELOG.md, SKILL.md). The other 12+ files were left modified on disk, uncommitted. This blocked git pull on the next operation and required manual `git checkout -- .` every time.\n\nFix: stage all files that wip-release modifies. Sub-tool package.json files, product docs (ai/product/), and trashed release notes (_trash/) are now included in the release commit.\n\n## Issues closed\n\n- #231 (wip-release rollback version bumps on failure)\n\n## How to verify\n\n```bash\nwip-release patch\ngit status\n# Should show clean working tree after release\n```\n\nv1.9.61 | 2026-03-29T18:58:25.400Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.61\n\n**Add test script for branch guard. Fix node bypass regex.**\n\n## The story\n\nEvery guard bug this session (v1.9.56-59) would have been caught by running a test before merging. This release adds test.sh to the guard that pipes test JSON into guard.mjs and verifies allow/deny results. 30 test cases covering destructive commands, quoted strings (Bug 1/3), compound commands (Bug 2), safe commands, and plan files.\n\nAlso fixes the node bypass regex: `require('fs').writeFileSync` wasn't caught because the regex looked for `fs.writeFile` literally. Broadened to match `writeFile` after `node -e`.\n\n## Issues closed\n\n- #232 (guard test coverage)\n\n## How to verify\n\n```bash\ncd tools/wip-branch-guard && bash test.sh\n# Should show: 30 passed, 0 failed, 3 skipped\n```\n\nv1.9.60 | 2026-03-29T15:44:11.926Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.60\n\n**Fix npm package bloat: exclude worktrees and _trash from published tarball.**\n\n## The story\n\nv1.9.59 published 869 files (3.9 MB) to npm because leftover worktree directories and _trash/ were included in the tarball. The .npmignore only excluded ai/ and .DS_Store. Added _trash/, .worktrees/, _worktrees/, .claude/, .wrangler/ to .npmignore. Also cleaned up 10 stale worktrees from previous sessions.\n\n## Issues closed\n\n- #232 (continued cleanup)\n\n## How to verify\n\n```bash\nnpm pack --dry-run 2>&1 | tail -5\n# Should show ~200 files, not 869\n```\n\nv1.9.58 | 2026-03-29T14:46:24.113Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.58\n\n**Fix deploy-public.sh losing release notes when invoked with relative path.**\n\n## The story\n\nWhen deploy-public.sh was called with `.` as the private repo path (e.g. `bash scripts/deploy-public.sh . wipcomputer/repo`), the script later cd'd into a temp directory. After that, `cd \".\"` no longer pointed to the private repo, so `gh release view` failed silently and release notes fell back to the empty \"Release vX.Y.Z\" default. This has been broken since at least v1.9.51.\n\nFix: resolve PRIVATE_REPO to an absolute path at startup before any cd happens.\n\n## Issues closed\n\n- #228 (continued from v1.9.57)\n\n## How to verify\n\n```bash\n# From a repo directory, run with \".\" and check public release has real notes:\ncd /path/to/private-repo\nbash scripts/deploy-public.sh . wipcomputer/public-repo --dry-run\n```\n\nv1.9.57 | 2026-03-29T14:38:39.105Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.57\n\n**deploy-public.sh now excludes .worktrees/ and _worktrees/ from public repo syncs.**\n\n## The story\n\nv1.9.56 accidentally deployed worktree directories (containing embedded git repos) to the public repo. The deploy script's rsync excluded ai/, .git/, _trash/, and other dev artifacts but didn't exclude worktree directories. Added both .worktrees/ (new convention) and _worktrees/ (old convention) to the exclude list.\n\n## Issues closed\n\n- #228 (deploy-public.sh leaks .worktrees/ to public repo)\n\n## How to verify\n\n```bash\n# Run deploy-public.sh --dry-run and confirm .worktrees/ is not synced\ngrep -n \"worktrees\" scripts/deploy-public.sh\n```\n\nv1.9.56 | 2026-03-29T14:22:00.371Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.56\n\n**Branch guard now blocks destructive git commands on all branches.**\n\n## The story\n\nThe branch guard blocked commits and file writes on main, but allowed destructive git commands that destroy uncommitted work. Commands like `git clean -fd`, `git checkout --`, `git stash drop`, and `git reset --hard` slipped through because they were either in the allowed list or not in the blocked list. These commands destroyed Parker's Finder aliases, other agents' uncommitted edits, and user files multiple times on Mar 28-29.\n\nThe fix adds a new DESTRUCTIVE_PATTERNS list that fires on ALL branches, not just main. The guard also closes several bypass vectors: `node -e` removed from the allowed list, python/node file-write patterns detected, and `git checkout` narrowed to branch-switching only.\n\n## What changed\n\n- Added DESTRUCTIVE_PATTERNS: git clean -f, git checkout --, git stash drop/pop/clear, git reset --hard, git restore, python/node bypasses\n- Removed `git checkout` blanket allow. Now only allows `git checkout <branch>` (switching)\n- Removed `git stash drop` from allowed list\n- Removed `node -e` from allowed bash patterns (bypass vector)\n- Added `git stash show` and `git restore --staged` as safe read-only operations\n- Deny message tells agent to use worktrees and safety checkpoints instead\n\n## Issues closed\n\n- #240 (branch guard + harness directories)\n- #241 (python bypass detection)\n- PR #284\n\n## How to verify\n\n```bash\n# These should all be BLOCKED:\n# git clean -fd\n# git checkout -- somefile\n# git stash drop\n# git stash pop\n# git reset --hard\n# python3 -c \"open('f','w').write('x')\"\n\n# These should still WORK:\n# git checkout main (branch switching)\n# git stash list (read-only)\n# git status, git log, git diff\n# Normal worktree workflow\n```\n\nv1.9.55 | 2026-03-28T19:02:36.027Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.55\n\nForce redeploy: .worktrees guard fix.\n\n## The story\n\nv1.9.53 had the guard fix but deploy-public was missed. v1.9.54 force-redeployed but installer had already cached v1.9.54. This version ensures the public repo and npm are in sync so ldm install deploys the correct guard.mjs with .worktrees convention.\n\n## Issues closed\n\n- #240 (partial)\n\nv1.9.54 | 2026-03-28T18:54:15.676Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.54\n\nForce redeploy: guard files were stale after v1.9.53.\n\n## The story\n\nv1.9.53 published the .worktrees guard fix to npm but ldm install saw the version as current and skipped redeploying the files. The deployed guard.mjs was still the old version. This release forces a version bump so the installer re-deploys.\n\nThis is a bug in the installer: it checks version numbers but not file contents. Filed for future fix.\n\n## Issues closed\n\n- #240 (partial: .worktrees convention)\n\nv1.9.53 | 2026-03-28T18:45:23.164Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.53\n\n**One-line summary of what this release does**\n\nTell the story. What was broken or missing? What did we build? Why does the user care?\nWrite at least one real paragraph of prose. Not just bullets. The release notes gate\nwill block if there is no narrative. Bullets are fine for details, but the story comes first.\n\n## The story\n\n(Write a paragraph here. What was the problem? What does this release fix? Why does it matter?\nThis is what users read. Make it worth reading.)\n\n## Issues closed\n\n- #282\n\n## How to verify\n\n```bash\n# Commands to test the changes\n```\n\nv1.9.52 | 2026-03-27T15:14:09.663Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.52\n\n**Fix branch guard false-blocking bash commands targeting worktree paths**\n\n## What changed\n\n- Branch guard now extracts absolute paths from any bash command (mkdir, cp, mv, touch, etc.) and resolves the git branch from the target path's repo, not the CWD\n- `findRepoRoot()` improved to walk up to existing directories for paths that don't exist yet (handles mkdir for new directories)\n- Added `.ldm/worktrees` to allowed worktree locations alongside `_worktrees/` and `.claude/worktrees`\n\n## Why\n\nWhen Claude Code launches from `~/wipcomputerinc/` (on main) and runs bash commands targeting files inside a worktree (e.g., `mkdir -p /path/to/_worktrees/repo--branch/new-dir/`), the guard only knew how to extract paths from `cd` and `git -C` patterns. Any other command fell back to CWD resolution, saw \"main\", and blocked incorrectly. This caused minutes of wasted time every session.\n\n## Issues closed\n\n- wipcomputer/wip-ldm-os#187\n\n## How to verify\n\n```bash\n# From CWD on main, this should no longer be blocked:\n# mkdir -p /path/to/_worktrees/repo--branch/new-directory/\n# cp file.txt /path/to/_worktrees/repo--branch/\n```\n\nv1.9.51 | 2026-03-24T17:41:11.077Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.51\n\n## Branch Guard: Workspace Files Allowlist (#185)\n\nAdded TOOLS.md, MEMORY.md, IDENTITY.md, SOUL.md, WHERE-TO-WRITE.md, HEARTBEAT.md to the shared state allowlist. Both agents can now write to workspace files on main without being blocked.\n\nPreviously only SHARED-CONTEXT.md was allowed. This broke Lesa's ability to edit her own workspace files during the migration to ~/wipcomputerinc/.\n\n## TECHNICAL.md: Backup Documentation\n\nUpdated LDM Dev Tools.app backup section to reflect the unified backup system. backup.sh now calls `~/.ldm/bin/ldm-backup.sh` (deployed by ldm install from wip-ldm-os-private/scripts/).\n\nv1.9.50 | 2026-03-20T17:39:15.795Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.50\n\n**wip-release: require product update doc on every release.**\n\n## What changed\n\nNew quality gate in wip-release: checks that `ai/dev-updates/product-update/*-product-update.md` was modified since the last release tag. Same pattern as dev-updates, roadmap, and readme-first checks.\n\nThe product update doc is a human-readable test guide. Each release entry has: what changed, how it's supposed to work, and how to test. New entries go at the top. Additive only.\n\n## Why\n\nThree repos now have product update docs but nothing enforced keeping them current. Without the gate, the docs will drift immediately (same problem we had with TECHNICAL.md).\n\n## Issues closed\n\n- #220\n\n## How to verify\n\n```bash\nwip-release patch --dry-run\n# Should warn if product update doc not modified since last release\n```\n\nv1.9.49 | 2026-03-20T16:29:17.521Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.49\n\n**TECHNICAL.md audit: 2 weeks of undocumented features now documented.**\n\n## What changed\n\nFull TECHNICAL.md audit covering v1.9.15 through v1.9.48. Two passes. Key additions:\n\n- **wip-release quality gates:** Technical docs gate, interface coverage gate, product docs auto-sync, all skip flags documented.\n- **deploy-public.sh:** Full 8-step pipeline including GitHub Packages publishing, repo URL rewrite, co-author sync.\n- **wip-license-guard:** Now documented as both CLI and Claude Code PreToolUse hook (guard.mjs). Enforcement details.\n- **wip-branch-guard:** Worktree requirement on branches, non-repo file passthrough, workflow teaching messages.\n- **wip-repos claude:** Cross-repo CLAUDE.md ecosystem generator fully documented.\n- **Source code table:** Missing files added (guard.mjs, claude.mjs, mcp-server.mjs).\n- **Log paths:** Fixed stale /tmp/ references to ~/.ldm/logs/.\n\n## Why\n\n15 releases shipped without TECHNICAL.md updates. Agents reading the docs were missing critical features: release gates, license enforcement hooks, deploy pipeline details.\n\n## Issues closed\n\n- #218\n\n## How to verify\n\n```bash\ngrep \"Interface coverage\" TECHNICAL.md    # new gate\ngrep \"guard.mjs\" TECHNICAL.md             # license-guard hook\ngrep \"GitHub Packages\" TECHNICAL.md       # deploy pipeline\n```\n\nv1.9.48 | 2026-03-20T15:07:45.945Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.48\n\n**Document wip-repos claude command in SKILL.md and TECHNICAL.md.**\n\n## What changed\n\n- SKILL.md: added `wip-repos claude` commands to the wip-repos section\n- TECHNICAL.md: full documentation of how the ecosystem generator works, template locations, delimiter convention\n\n## Why\n\nv1.9.47 shipped the `wip-repos claude` command without updating technical docs. Now documented.\n\n## Issues closed\n\n- #212 (docs portion)\n\n## How to verify\n\n```bash\ngrep \"wip-repos claude\" SKILL.md TECHNICAL.md\n```\n\nv1.9.47 | 2026-03-20T14:20:03.703Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.47\n\n**New: `wip-repos claude` command + CLAUDE.md templates.**\n\n## What changed\n\n### `wip-repos claude` (Phases 1-3 of the CLAUDE.md plan)\n\nNew subcommand that generates cross-repo ecosystem sections in CLAUDE.md files. When an agent opens repo-A, it can't read repo-B. This command pre-generates the context.\n\n```bash\nwip-repos claude              # regenerate all repos\nwip-repos claude my-repo      # regenerate one repo\nwip-repos claude --init       # create CLAUDE.md for repos missing one\nwip-repos claude --dry-run    # preview changes\n```\n\nFeatures:\n- Reads all repos from manifest, extracts metadata (package.json, SKILL.md, directory structure)\n- Generates `## Ecosystem` sections with delimiter comments (`<!-- wip-repos:start/end -->`)\n- Hand-written sections are never overwritten\n- Relevance filtering: only related repos shown (same category + core repos)\n- `--init` creates starter CLAUDE.md from template for repos missing one\n\n### Templates\n\n- `templates/global-claude-md.md` ... universal CLAUDE.md for ~/.claude/CLAUDE.md\n- `templates/repo-claude-md.template` ... per-repo starter with ecosystem placeholder\n\n## Why\n\nAgents lose context across repos. They can't read sibling repos at runtime. Pre-generating cross-repo maps into CLAUDE.md solves this without requiring runtime access.\n\n## Issues closed\n\n- #212 (partial: Phases 1-3 of 6)\n\n## How to verify\n\n```bash\nwip-repos claude --dry-run\n```\n\nv1.9.46 | 2026-03-19T03:34:31.441Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.46\n\n**Centralized worktree management: guard rule, wip-release prune, Dev Guide convention.**\n\n## What changed\n\n### Guard: worktree path warning (#212)\nBranch guard now warns when `git worktree add` creates a worktree outside `_worktrees/`. Shows the convention and suggests `ldm worktree add`. Warning only, not a hard block.\n\n### wip-release: worktree prune (#212)\nNew step 12 in the release pipeline. After branch cleanup, prunes stale worktrees from `_worktrees/` whose branches are merged into main. Automatic cleanup after every release.\n\n### Dev Guide: _worktrees/ convention (#212)\nDocuments the centralized worktree convention:\n- All worktrees go in `_worktrees/<repo-name>--<branch-suffix>/`\n- Use `ldm worktree add` (auto-detects repo, creates in the right place)\n- Guard warns about worktrees outside the convention\n- `wip-release` auto-prunes merged worktrees\n\n## Why\n\nWorktrees created as repo siblings confused iCloud sync, looked like real repos in directory listings, and were never cleaned up. This session alone created 10+ stale worktrees. The convention keeps them organized and the release pipeline cleans them automatically.\n\n## Issues closed\n\n- #212\n- #213\n\n## How to verify\n\n```bash\n# Guard warning:\ncd /path/to/repo\ngit worktree add ../my-worktree -b test   # should warn about _worktrees/\n\n# Correct path:\nldm worktree add cc-mini/test             # creates _worktrees/<repo>--cc-mini--test/\n```\n\nv1.9.45 | 2026-03-19T02:23:19.306Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.45\n\n**Guard now teaches the workflow instead of just blocking.**\n\n## What changed\n\n- **Branch guard error messages overhauled (#213).** When the guard blocks a write on main, it now shows the full 8-step process: worktree, branch, commit, push, PR, merge, wip-release, deploy-public. Includes the lesson that release notes go on the feature branch, not as a separate PR.\n- **Separate error for \"on branch but not in worktree.\"** Tells the agent to go back to main and create a worktree properly.\n- **CLAUDE.md added to shared state allowlist.** Was patched in the deployed guard but missing from source. Now in sync.\n\n## Why\n\nAgents kept getting blocked by the guard and then trying workarounds instead of following the process. The error message said \"Use a worktree\" but didn't explain the full workflow. Today's session hit this 5+ times. The guard works. The gap was agent knowledge.\n\n## Issues closed\n\n- #213\n- #256\n\n## How to verify\n\n```bash\n# In any repo on main, try to edit a file. The error should show the full workflow.\n# In any repo on a branch (not worktree), try to edit. Should show worktree instructions.\n```\n\nv1.9.44 | 2026-03-17T15:24:36.913Z | user\n\n# Guard non-repo files fix + UTC date fix\n\nTwo bugs fixed in one PR.\n\n## Bug 1: Guard blocks files outside git repos (#77)\n\n**Problem:** When Write/Edit targets a file outside any git repo (e.g. `~/.claude/plans/`), `findRepoRoot()` returns null. The guard fell back to CWD (`~/.openclaw` on main) and blocked the operation. Files outside repos aren't the guard's concern.\n\n**Fix:** If `findRepoRoot(filePath)` returns null for Write/Edit operations, allow immediately. The guard only protects git repos from direct-on-main edits.\n\n**File:** `tools/wip-branch-guard/guard.mjs`\n\n## Bug 2: UTC date mismatch in wip-release\n\n**Problem:** Dev-update files are named with local date (e.g. `2026-03-16--cc-mini--...md`). But `new Date().toISOString().split('T')[0]` returns UTC date. After midnight UTC (4 PM PST), the dates diverge. Release notes gate fails to find today's dev-update.\n\n**Fix:** Replaced all three instances of `toISOString()` date extraction with explicit local date construction using `getFullYear()/getMonth()/getDate()`.\n\n**Files:**\n- `tools/wip-release/cli.js` (line 80, dev-update detection)\n- `tools/wip-release/core.mjs` (line 92, CHANGELOG date)\n- `tools/wip-release/core.mjs` (line 582, product docs sync date)\n\nv1.9.43 | 2026-03-17T14:48:47.064Z | user\n\n# Guard non-repo files fix + UTC date fix\n\nTwo bugs fixed in one PR.\n\n## Bug 1: Guard blocks files outside git repos (#77)\n\n**Problem:** When Write/Edit targets a file outside any git repo (e.g. `~/.claude/plans/`), `findRepoRoot()` returns null. The guard fell back to CWD (`~/.openclaw` on main) and blocked the operation. Files outside repos aren't the guard's concern.\n\n**Fix:** If `findRepoRoot(filePath)` returns null for Write/Edit operations, allow immediately. The guard only protects git repos from direct-on-main edits.\n\n**File:** `tools/wip-branch-guard/guard.mjs`\n\n## Bug 2: UTC date mismatch in wip-release\n\n**Problem:** Dev-update files are named with local date (e.g. `2026-03-16--cc-mini--...md`). But `new Date().toISOString().split('T')[0]` returns UTC date. After midnight UTC (4 PM PST), the dates diverge. Release notes gate fails to find today's dev-update.\n\n**Fix:** Replaced all three instances of `toISOString()` date extraction with explicit local date construction using `getFullYear()/getMonth()/getDate()`.\n\n**Files:**\n- `tools/wip-release/cli.js` (line 80, dev-update detection)\n- `tools/wip-release/core.mjs` (line 92, CHANGELOG date)\n- `tools/wip-release/core.mjs` (line 582, product docs sync date)\n\nv1.9.42 | 2026-03-17T13:52:07.904Z | user\n\n# Guard non-repo files fix + UTC date fix\n\nTwo bugs fixed in one PR.\n\n## Bug 1: Guard blocks files outside git repos (#77)\n\n**Problem:** When Write/Edit targets a file outside any git repo (e.g. `~/.claude/plans/`), `findRepoRoot()` returns null. The guard fell back to CWD (`~/.openclaw` on main) and blocked the operation. Files outside repos aren't the guard's concern.\n\n**Fix:** If `findRepoRoot(filePath)` returns null for Write/Edit operations, allow immediately. The guard only protects git repos from direct-on-main edits.\n\n**File:** `tools/wip-branch-guard/guard.mjs`\n\n## Bug 2: UTC date mismatch in wip-release\n\n**Problem:** Dev-update files are named with local date (e.g. `2026-03-16--cc-mini--...md`). But `new Date().toISOString().split('T')[0]` returns UTC date. After midnight UTC (4 PM PST), the dates diverge. Release notes gate fails to find today's dev-update.\n\n**Fix:** Replaced all three instances of `toISOString()` date extraction with explicit local date construction using `getFullYear()/getMonth()/getDate()`.\n\n**Files:**\n- `tools/wip-release/cli.js` (line 80, dev-update detection)\n- `tools/wip-release/core.mjs` (line 92, CHANGELOG date)\n- `tools/wip-release/core.mjs` (line 582, product docs sync date)\n\nv1.9.41 | 2026-03-17T13:40:04.793Z | user\n\n# Doc enforcement gates for wip-release\n\n**Date:** 2026-03-16\n**Closes:** #117, #128\n\n## What changed\n\nTwo new pre-release gates in wip-release:\n\n**Technical Docs Gate (#117):** When source code (*.mjs, *.js, *.ts) changed since the last release tag, checks that SKILL.md or TECHNICAL.md was also modified. Catches code shipping without doc updates. Warns on patch, blocks on minor/major. Skip with `--skip-tech-docs-check`.\n\n**Interface Coverage Gate (#128):** For toolbox repos, scans each tool in tools/*/ for actual interfaces (CLI, Module, MCP, OC Plugin, Skill, CC Hook) and compares to the coverage table in README.md and SKILL.md. Reports: tools missing from table, interfaces detected but not marked Y, interfaces marked Y but not detected, tool count mismatches. Warns on patch, blocks on minor/major. Skip with `--skip-coverage-check`.\n\nBoth follow the same pattern as existing gates (checkProductDocs, checkStaleBranches). Both run in real and dry-run modes.\n\n## Why\n\nSource code was shipping without doc updates constantly. SKILL.md and TECHNICAL.md fell behind the code. Interface coverage tables drifted from reality. These gates catch it before release instead of after.\n\nv1.9.40 | 2026-03-16T22:22:05.112Z | user\n\n# Auto-sync product docs version/date on release\n\n**Date:** 2026-03-16\n**Closes:** #202\n\n## What changed\n\nwip-release now auto-updates version and date lines in product docs before the release commit. No more stale \"Current version: v1.9.1\" when you're shipping v1.9.39.\n\nFiles updated automatically:\n- `ai/product/plans-prds/roadmap.md`: \"Current version\" and \"Last updated\"\n- `ai/product/readme-first-product.md`: \"Last updated\" and \"What's Built (as of vX.Y.Z)\"\n\nRuns between changelog update and git commit (step 3.75). Only touches files that exist. Only updates lines that match the expected patterns.\n\n## Why\n\nThese files were stale from v1.9.1 through v1.9.39 (8 days, 38 releases). Nobody remembered to update them. The existing product docs gate warned about it but couldn't fix it. Now it fixes itself.\n\nv1.9.39 | 2026-03-16T22:06:02.126Z | user\n\n# Wire license-guard as Claude Code PreToolUse hook\n\n**Date:** 2026-03-16\n**Closes:** #130\n\n## What changed\n\nlicense-guard now registers as a Claude Code PreToolUse hook on install. Previously the hook code existed (hook.mjs) but was never wired into the deploy system. Now:\n\n- Renamed hook.mjs to guard.mjs (matches file-guard/branch-guard convention that LDM OS deploy.mjs expects)\n- Added `claudeCode.hook` config to package.json (event: PreToolUse, matcher: Bash, timeout: 5)\n- On next `ldm install`, the hook auto-registers in ~/.claude/settings.json\n\nThe hook blocks git commit and git push when license compliance fails:\n- LICENSE file missing\n- Copyright doesn't match .license-guard.json config\n- CLA.md missing\n- README.md missing ## License section\n- MIT+AGPL config but LICENSE or README only mentions MIT\n\nRepos without .license-guard.json are not affected (the hook silently passes).\n\n## Also done\n\n- Updated plan statuses: license guard Phase 1 complete, bootstrap LDM OS complete\n- Bootstrap LDM OS was already shipped in install.js (lines 740-812)\n\nv1.9.38 | 2026-03-16T21:56:14.387Z | user\n\n# GitHub Packages publish from public repo\n\n**Date:** 2026-03-16\n**Closes:** #193\n\n## What changed\n\n`deploy-public.sh` now publishes to GitHub Packages from the public repo clone after the npm publish step. Previously, GitHub Packages were only published from the private repo during `wip-release`, so they showed on the private repo's Packages tab. Users couldn't see them.\n\nNow packages show on the public repo's Packages tab where users expect to find them. Uses `gh auth token` for authentication (already available from the gh CLI).\n\n## Why\n\nThe Packages tab on public repos was empty. Users visiting wipcomputer/wip-ldm-os or wipcomputer/wip-ai-devops-toolbox saw no packages even though they were published. The packages existed but were linked to the private repo.\n\nv1.9.37 | 2026-03-16T21:31:43.854Z | user\n\n# GitHub Packages publish from public repo\n\n**Date:** 2026-03-16\n**Closes:** #193\n\n## What changed\n\n`deploy-public.sh` now publishes to GitHub Packages from the public repo clone after the npm publish step. Previously, GitHub Packages were only published from the private repo during `wip-release`, so they showed on the private repo's Packages tab. Users couldn't see them.\n\nNow packages show on the public repo's Packages tab where users expect to find them. Uses `gh auth token` for authentication (already available from the gh CLI).\n\n## Why\n\nThe Packages tab on public repos was empty. Users visiting wipcomputer/wip-ldm-os or wipcomputer/wip-ai-devops-toolbox saw no packages even though they were published. The packages existed but were linked to the private repo.\n\nv1.9.36 | 2026-03-16T18:21:08.860Z | user\n\n# GitHub Packages publish from public repo\n\n**Date:** 2026-03-16\n**Closes:** #193\n\n## What changed\n\n`deploy-public.sh` now publishes to GitHub Packages from the public repo clone after the npm publish step. Previously, GitHub Packages were only published from the private repo during `wip-release`, so they showed on the private repo's Packages tab. Users couldn't see them.\n\nNow packages show on the public repo's Packages tab where users expect to find them. Uses `gh auth token` for authentication (already available from the gh CLI).\n\n## Why\n\nThe Packages tab on public repos was empty. Users visiting wipcomputer/wip-ldm-os or wipcomputer/wip-ai-devops-toolbox saw no packages even though they were published. The packages existed but were linked to the private repo.\n\nv1.9.35 | 2026-03-16T18:01:49.928Z | user\n\n# GitHub Packages publish from public repo\n\n**Date:** 2026-03-16\n**Closes:** #193\n\n## What changed\n\n`deploy-public.sh` now publishes to GitHub Packages from the public repo clone after the npm publish step. Previously, GitHub Packages were only published from the private repo during `wip-release`, so they showed on the private repo's Packages tab. Users couldn't see them.\n\nNow packages show on the public repo's Packages tab where users expect to find them. Uses `gh auth token` for authentication (already available from the gh CLI).\n\n## Why\n\nThe Packages tab on public repos was empty. Users visiting wipcomputer/wip-ldm-os or wipcomputer/wip-ai-devops-toolbox saw no packages even though they were published. The packages existed but were linked to the private repo.\n\nv1.9.34 | 2026-03-16T16:32:46.956Z | user\n\n# GitHub Packages publish from public repo\n\n**Date:** 2026-03-16\n**Closes:** #193\n\n## What changed\n\n`deploy-public.sh` now publishes to GitHub Packages from the public repo clone after the npm publish step. Previously, GitHub Packages were only published from the private repo during `wip-release`, so they showed on the private repo's Packages tab. Users couldn't see them.\n\nNow packages show on the public repo's Packages tab where users expect to find them. Uses `gh auth token` for authentication (already available from the gh CLI).\n\n## Why\n\nThe Packages tab on public repos was empty. Users visiting wipcomputer/wip-ldm-os or wipcomputer/wip-ai-devops-toolbox saw no packages even though they were published. The packages existed but were linked to the private repo.\n\nv1.9.33 | 2026-03-15T23:16:03.514Z | user\n\n# --version on all CLIs + issue cleanup\n\n**Date:** 2026-03-15\n**Closes:** #190, #191, #169, #123, #119\n\n## What changed\n\nAll 7 CLI tools now support `--version` and `-v`. Each reads its own `package.json` and prints the version. Previously, `wip-release --version` printed the help text instead of a version number.\n\nTools updated: wip-release, wip-repos, wip-license-guard, wip-repo-permissions, wip-repo-init, wip-readme-format, wip-file-guard, wip-branch-guard.\n\nwip-license-guard also got a proper README (#169) with all commands, config format, and integration docs.\n\n## Issues closed\n\n- #190: wip-release --version should work\n- #191: enforce --version on all CLI tools\n- #169: wip-license-guard needs its own README\n- #123: Merge/Deploy/Install conflated (enforced across v1.9.25-v1.9.30)\n- #119: All destructive tools must have --dry-run (all confirmed)\n\nv1.9.32 | 2026-03-15T23:14:36.259Z | user\n\n# --version on all CLIs + issue cleanup\n\n**Date:** 2026-03-15\n**Closes:** #190, #191, #169, #123, #119\n\n## What changed\n\nAll 7 CLI tools now support `--version` and `-v`. Each reads its own `package.json` and prints the version. Previously, `wip-release --version` printed the help text instead of a version number.\n\nTools updated: wip-release, wip-repos, wip-license-guard, wip-repo-permissions, wip-repo-init, wip-readme-format, wip-file-guard, wip-branch-guard.\n\nwip-license-guard also got a proper README (#169) with all commands, config format, and integration docs.\n\n## Issues closed\n\n- #190: wip-release --version should work\n- #191: enforce --version on all CLI tools\n- #169: wip-license-guard needs its own README\n- #123: Merge/Deploy/Install conflated (enforced across v1.9.25-v1.9.30)\n- #119: All destructive tools must have --dry-run (all confirmed)\n\nv1.9.31 | 2026-03-15T22:53:58.565Z | user\n\n# Release Notes: wip-ai-devops-toolbox v1.9.31\n\nBranch guard no longer blocks global npm operations on main.\n\n## What changed\n\nMoved `npm install -g` and `npm link` from BLOCKED_BASH_PATTERNS to ALLOWED_BASH_PATTERNS in `wip-branch-guard/guard.mjs`. Global npm operations modify `/opt/homebrew/`, not the repo. Local `npm install` (no -g flag) remains blocked.\n\n## Why\n\nDuring LDM OS v0.4.0 dogfood, a CC session couldn't run `npm install -g @wipcomputer/wip-ldm-os@0.4.0` even after Parker explicitly said \"install.\" The guard was too aggressive. Original intent (issue #137) was to block repo writes on main, not system-level package installs.\n\n## Issues closed\n\n- Closes #188 (branch guard blocks npm install -g)\n- Cross-ref: wipcomputer/wip-ldm-os#44\n\n## How to verify\n\n```bash\n# On main branch, these should now succeed:\nnpm install -g @wipcomputer/wip-ldm-os@0.4.0\nnpm link\n# This should still be blocked on main:\nnpm install\n```\n\nv1.9.30 | 2026-03-15T22:17:27.303Z | user\n\n# Release notes must be a file on disk\n\n**Date:** 2026-03-15\n\n## What changed\n\nwip-release no longer accepts the `--notes` flag. Release notes MUST come from a file on disk:\n\n1. `RELEASE-NOTES-v{version}.md` in repo root (auto-detected)\n2. `ai/dev-updates/YYYY-MM-DD--description.md` (auto-detected)\n3. `--notes-file=path` (explicit file path)\n\nIf no file exists, the release is blocked. The gate scaffolds a template (`RELEASE-NOTES-v{version}.md`) so the agent has something to fill in.\n\n## Why\n\nThe `--notes` flag was the root cause of every bad release note. Agents passed one-liners like `--notes=\"fix bug\"` and the gate let them through. Even after we added length checks and changelog detection, agents found ways around it. The flag was an escape hatch that undermined the entire system.\n\nThe file-on-disk requirement solves three problems:\n1. **Reviewability.** The file is on the branch. It shows up in the PR diff. Parker can read and approve the release notes before merge.\n2. **Quality.** Writing a file forces the agent to think about what changed and why. A flag encourages one-liners.\n3. **History.** The file is committed to git. The release notes are part of the repo history, not a transient CLI argument.\n\n## What agents need to do\n\nBefore running `wip-release`:\n1. Write `RELEASE-NOTES-v{version}.md` or `ai/dev-updates/YYYY-MM-DD--description.md`\n2. Commit it on the branch\n3. The file shows up in the PR for review\n4. After merge to main, `wip-release` auto-detects it\n\nIf the agent forgets, `wip-release` blocks and scaffolds a template.\n\nv1.9.29 | 2026-03-15T22:14:11.764Z | user\n\n# Release notes must be a file on disk\n\n**Date:** 2026-03-15\n\n## What changed\n\nwip-release no longer accepts the `--notes` flag. Release notes MUST come from a file on disk:\n\n1. `RELEASE-NOTES-v{version}.md` in repo root (auto-detected)\n2. `ai/dev-updates/YYYY-MM-DD--description.md` (auto-detected)\n3. `--notes-file=path` (explicit file path)\n\nIf no file exists, the release is blocked. The gate scaffolds a template (`RELEASE-NOTES-v{version}.md`) so the agent has something to fill in.\n\n## Why\n\nThe `--notes` flag was the root cause of every bad release note. Agents passed one-liners like `--notes=\"fix bug\"` and the gate let them through. Even after we added length checks and changelog detection, agents found ways around it. The flag was an escape hatch that undermined the entire system.\n\nThe file-on-disk requirement solves three problems:\n1. **Reviewability.** The file is on the branch. It shows up in the PR diff. Parker can read and approve the release notes before merge.\n2. **Quality.** Writing a file forces the agent to think about what changed and why. A flag encourages one-liners.\n3. **History.** The file is committed to git. The release notes are part of the repo history, not a transient CLI argument.\n\n## What agents need to do\n\nBefore running `wip-release`:\n1. Write `RELEASE-NOTES-v{version}.md` or `ai/dev-updates/YYYY-MM-DD--description.md`\n2. Commit it on the branch\n3. The file shows up in the PR for review\n4. After merge to main, `wip-release` auto-detects it\n\nIf the agent forgets, `wip-release` blocks and scaffolds a template.\n\nv1.9.28 | 2026-03-15T19:02:37.370Z | user\n\n# Release Notes Quality Gate\n\n**Date:** 2026-03-15\n\n## What changed\n\nwip-release now blocks ALL releases (patch, minor, major) if the release notes are bad. Previously, patch releases only warned. Now they block.\n\nThe gate checks:\n- Notes must be at least 50 characters\n- Notes can't look like a changelog entry (\"fix: ...\", \"add: ...\", \"update: ...\")\n- Minor/major still require a file (not --notes flag)\n\nIf the gate blocks, it tells you exactly how to fix it: write a RELEASE-NOTES file, write a dev update, or use --notes with at least 50 chars of real description.\n\n## Why\n\nRelease notes were consistently garbage. One-liner --notes flags like \"Fix bug\" or \"Update docs\" sailed through on patch releases. The warnings were ignored by both humans and agents. Every release page on GitHub had thin, useless notes that didn't explain what changed or why.\n\n## Also in this release\n\n- wip-repo-init templates renamed from ai/ to templates/ so they ship with npm install (deploy-public.sh was stripping them)\n- SKILL.md restart notice after install (hooks need session restart)\n- SPEC.md and TECHNICAL.md updated with all 17 tools and LDM OS links\n- Branch guard matcher fix (catches Bash + NotebookEdit)\n- Forced Git Worktrees and Branch Guard sections added to SKILL.md\n\nv1.9.27 | 2026-03-15T17:31:50.900Z | user\n\n# Release Notes Quality Gate\n\n**Date:** 2026-03-15\n\n## What changed\n\nwip-release now blocks ALL releases (patch, minor, major) if the release notes are bad. Previously, patch releases only warned. Now they block.\n\nThe gate checks:\n- Notes must be at least 50 characters\n- Notes can't look like a changelog entry (\"fix: ...\", \"add: ...\", \"update: ...\")\n- Minor/major still require a file (not --notes flag)\n\nIf the gate blocks, it tells you exactly how to fix it: write a RELEASE-NOTES file, write a dev update, or use --notes with at least 50 chars of real description.\n\n## Why\n\nRelease notes were consistently garbage. One-liner --notes flags like \"Fix bug\" or \"Update docs\" sailed through on patch releases. The warnings were ignored by both humans and agents. Every release page on GitHub had thin, useless notes that didn't explain what changed or why.\n\n## Also in this release\n\n- wip-repo-init templates renamed from ai/ to templates/ so they ship with npm install (deploy-public.sh was stripping them)\n- SKILL.md restart notice after install (hooks need session restart)\n- SPEC.md and TECHNICAL.md updated with all 17 tools and LDM OS links\n- Branch guard matcher fix (catches Bash + NotebookEdit)\n- Forced Git Worktrees and Branch Guard sections added to SKILL.md\n\nv1.9.26 | 2026-03-15T16:16:45.641Z | user\n\nAdd restart notice after install/update. Hooks need session restart to take effect.\n\nv1.9.25 | 2026-03-14T17:29:26.942Z | user\n\nFix branch guard matcher (catches Bash + NotebookEdit). Add Forced Git Worktrees and Branch Guard sections to SKILL.md. Update SPEC.md and TECHNICAL.md with all 17 tools and LDM OS links.\n\nv1.9.24 | 2026-03-14T17:05:30.366Z | user\n\nNumber tools in dry run and already-installed lists. Dogfood iteration.\n\nv1.9.23 | 2026-03-14T17:01:41.679Z | user\n\nForce verbatim tool list display. AI must show all 17 tools with descriptions, never summarize.\n\nv1.9.22 | 2026-03-14T16:54:35.642Z | user\n\nAll 17 tools listed with descriptions. New section order: Setup, Infrastructure, Repo Management, License, Release. Conversational prompt.\n\nv1.9.21 | 2026-03-14T16:41:56.637Z | user\n\nAdd Already Installed section with tool descriptions. Dogfood fix.\n\nv1.9.20 | 2026-03-14T16:27:17.457Z | user\n\nMake root package publishable. npm install -g @wipcomputer/wip-ai-devops-toolbox now installs all 12 CLI tools.\n\nv1.9.19 | 2026-03-14T16:16:45.333Z | user\n\nAdd websiteRepo to .publish-skill.json. Auto-publish SKILL.md to website on release. Fix install prompt URLs to use wip- prefix.\n\nArchive index:\n\nArchive v1.9.72: 10 files, 11262 bytes\n\nFiles: CHANGELOG.md (521b), guard.mjs (6220b), openclaw.plugin.json (222b), package.json (610b), README.md (5388b), REFERENCE.md (1667b), skill-card.md (1918b), SKILL.md (2731b), test.sh (6290b), _meta.json (134b)\n\nFile v1.9.72:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.72:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files outside shared state paths. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file (20 for shared state).\n3. **Shared state paths** (e.g. `~/.openclaw/workspace/`) are always writable. These are live agent workspace files, not code.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\nPASS: Allow Write to ~/.openclaw/workspace/TOOLS.md (shared state)\n\nResults: 11 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.72:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.72\",\n  \"publishedAt\": 1776806697219\n}\n\nFile v1.9.72:CHANGELOG.md\n\n# Changelog\n\n## 1.0.2 (2026-04-08)\n\nAdd `~/.openclaw/workspace/` to shared state paths. OpenClaw agent workspace files are live shared state, not code. The guard now checks shared state BEFORE exact-match protection, so workspace TOOLS.md, MEMORY.md, etc. can be written freely by the agent that owns them. Fixes Lēsa being unable to write her own workspace files after the guard was deployed to OpenClaw on Apr 4.\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.72:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.72:skill-card.md\n\n## Description:\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[parkertoddbrooks](https://clawhub.ai/user/parkertoddbrooks)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agent operators use this skill to install and configure a file-edit guard that blocks overwrites or destructive edits to protected identity, memory, and shared-context files.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: The security review marks this release as suspicious because broad path exceptions and fail-open behavior need review before installation.\n\nMitigation: Review and scan the skill before deployment; address path canonicalization, malformed protected-file events, and test/documentation alignment with the intended policy.\n\n## Reference(s):\n\n- [ClawHub skill page](https://clawhub.ai/parkertoddbrooks/skills/wip-file-guard)\n- [Publisher profile](https://clawhub.ai/user/parkertoddbrooks)\n- [Project homepage](https://github.com/wipcomputer/wip-file-guard)\n- [npm package](https://www.npmjs.com/package/@wipcomputer/wip-file-guard)\n- [Manual install and reference](REFERENCE.md)\n\n## Skill Output:\n\n**Output Type(s):** [guidance, shell commands, configuration, code]\n\n**Output Format:** [Markdown with shell and JSON configuration blocks]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Can produce hook configuration and command-line usage guidance for Claude Code, OpenClaw, and direct CLI use.]\n\n## Skill Version(s):\n\n1.9.72 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v1.9.72:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.72:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.69\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.68: 9 files, 9205 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4338b), _meta.json (134b)\n\nFile v1.9.68:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.68:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.68:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.68\",\n  \"publishedAt\": 1775050061534\n}\n\nFile v1.9.68:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.68:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.68:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.68:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.68\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.67: 9 files, 9205 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4338b), _meta.json (134b)\n\nFile v1.9.67:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.67:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.67:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.67\",\n  \"publishedAt\": 1774942071593\n}\n\nFile v1.9.67:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.67:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.67:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.67:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.67\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.66: 9 files, 9205 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4338b), _meta.json (134b)\n\nFile v1.9.66:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.66:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.66:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.66\",\n  \"publishedAt\": 1774877330071\n}\n\nFile v1.9.66:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.66:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.66:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.66:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.66\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.65: 9 files, 9205 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4338b), _meta.json (134b)\n\nFile v1.9.65:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.65:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.65:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.65\",\n  \"publishedAt\": 1774828649591\n}\n\nFile v1.9.65:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.65:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.65:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.65:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.65\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.64: 9 files, 9205 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4338b), _meta.json (134b)\n\nFile v1.9.64:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.64:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.64:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.64\",\n  \"publishedAt\": 1774827516209\n}\n\nFile v1.9.64:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.64:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.64:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.64:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.64\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.63: 9 files, 9165 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4248b), _meta.json (134b)\n\nFile v1.9.63:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.63:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.63:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.63\",\n  \"publishedAt\": 1774811525975\n}\n\nFile v1.9.63:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.63:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.63:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.63:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.63\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.62: 9 files, 9165 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4248b), _meta.json (134b)\n\nFile v1.9.62:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.62:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.62:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.62\",\n  \"publishedAt\": 1774811147637\n}\n\nFile v1.9.62:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.62:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.62:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.62:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.62\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.61: 9 files, 9165 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4248b), _meta.json (134b)\n\nFile v1.9.61:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.61:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.61:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.61\",\n  \"publishedAt\": 1774810705400\n}\n\nFile v1.9.61:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.61:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.61:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.61:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.61\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"claude-code\",\n    \"openclaw\",\n    \"hook\",\n    \"file-guard\",\n    \"ai-safety\",\n    \"pretooluse\"\n  ],\n  \"author\": \"Parker Todd Brooks\",\n  \"license\": \"MIT\",\n  \"repository\": {\n    \"type\": \"git\",\n    \"url\": \"git+https://github.com/wipcomputer/wip-file-guard.git\"\n  }\n}\n\nArchive v1.9.60: 9 files, 9165 bytes\n\nFiles: CHANGELOG.md (117b), guard.mjs (4855b), openclaw.plugin.json (222b), package.json (610b), README.md (5153b), REFERENCE.md (1667b), SKILL.md (2731b), test.sh (4248b), _meta.json (134b)\n\nFile v1.9.60:SKILL.md\n\n---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed.\n\nFile v1.9.60:README.md\n\n###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork it (so you can contribute back if you find bugs)?\n```\n\nYour agent will read the repo, explain the tool, and walk you through integration interactively.\n\nAlso see **[wip-release](https://github.com/wipcomputer/wip-release)** ... one-command release pipeline for agent-native software.\n\nSee [REFERENCE.md](REFERENCE.md) for manual install instructions (Claude Code, OpenClaw, CLI).\n\n## Four Interfaces\n\nOne core, four interfaces into the same guard logic.\n\n| Interface | File | What it does |\n|-----------|------|-------------|\n| **Core** | `guard.mjs` | Pure guard logic. Reads stdin JSON, decides allow/deny. |\n| **Claude Code** | `guard.mjs` (PreToolUse hook) | Hooks into CC's PreToolUse event. Blocks before the edit happens. |\n| **OpenClaw** | `openclaw.plugin.json` | Lifecycle hook for OpenClaw agents. Same rules, different runtime. |\n| **CLI** | `guard.mjs --list`, `test.sh` | Testing and inspection from the command line. |\n\nSee [REFERENCE.md](REFERENCE.md) for customization (adding protected files, changing thresholds).\n\n## Tests\n\n```bash\nbash test.sh\n```\n\n```\nwip-file-guard tests\n===================\n\nPASS: Block Write to CLAUDE.md\nPASS: Block Write to SHARED-CONTEXT.md\nPASS: Allow Write to random file\nPASS: Block Edit removing 5 lines from CLAUDE.md\nPASS: Allow Edit adding lines to CLAUDE.md\nPASS: Allow Edit on non-protected file (even removing lines)\nPASS: Allow Edit with small removal (2 lines)\nPASS: Block Edit with 4 line removal from SOUL.md\nPASS: Block Write to IDENTITY.md\nPASS: Block Write to TOOLS.md\n\nResults: 10 passed, 0 failed\n```\n\n## Why This Exists\n\nContext compaction erases behavioral rules. An agent that was told \"never delete content from CLAUDE.md\" forgets that instruction after compaction. It then proceeds to replace 50 lines with 10, confident it's improving the file.\n\nThis happened five times in one session. The fix isn't better prompting. It's a hook that blocks the operation before it executes. Behavioral rules degrade. Technical guards don't.\n\n---\n\n## License\n\n```\nCLI, OpenClaw plugin, hooks                    MIT    (use anywhere, no restrictions)\nHosted or cloud service use                    AGPL   (network service distribution)\n```\n\nAGPL for personal use is free.\n\nBuilt by Parker Todd Brooks, Lēsa (OpenClaw, Claude Opus 4.6), Claude Code (Claude Opus 4.6).\n\nFile v1.9.60:_meta.json\n\n{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.60\",\n  \"publishedAt\": 1774799051926\n}\n\nFile v1.9.60:CHANGELOG.md\n\n# Changelog\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md\n\nFile v1.9.60:REFERENCE.md\n\n###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```\n\nFile v1.9.60:openclaw.plugin.json\n\n{\n  \"name\": \"wip-file-guard\",\n  \"version\": \"1.0.0\",\n  \"description\": \"Blocks destructive edits to protected files (CLAUDE.md, SHARED-CONTEXT.md, SOUL.md, etc.)\",\n  \"lifecycle\": {\n    \"before_tool_use\": \"./guard.mjs\"\n  }\n}\n\nFile v1.9.60:package.json\n\n{\n  \"name\": \"@wipcomputer/wip-file-guard\",\n  \"version\": \"1.9.60\",\n  \"type\": \"module\",\n  \"description\": \"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\",\n  \"main\": \"guard.mjs\",\n  \"bin\": {\n    \"wip-file-guard\": \"./guard.mjs\"\n  },\n  \"scripts\": {\n    \"test\": \"bash test.sh\"\n  },\n  \"keywords\": [\n    \"clau...","readmeExcerpt":"Skill: Wip File Guard Owner: parkertoddbrooks Summary: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Tags: latest:1.9.72 Version history: v1.9.72 | 2026-04-21T21:24:57.219Z | user AI DevOps Toolbox v1.9.72 Promote v1.9.71-alpha series to stable Closes #256. Consolidates 21 alpha prereleases (v1.9.71-alpha.1 through v1.9.71-alpha.21) into a stable v1.9.72 release. No","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"grep -r \"/Users/lesa\" ldm-jobs/ tools/wip-branch-guard/test.sh\n# Should return zero results"},{"language":"bash","snippet":"# In any repo with multiple merged PRs since last tag, each having RELEASE-NOTES files:\nwip-release patch --dry-run\n# Should show: \"Combined release notes from N merged PRs\""},{"language":"bash","snippet":"# On main, without release notes: should error, NOT scaffold\ncd any-repo && git checkout main\nwip-release patch\n# Expected: \"Release notes missing. Write RELEASE-NOTES-v*.md on your feature branch before merging.\"\n# Expected: no RELEASE-NOTES file created in working tree\n\n# On a feature branch: should scaffold as before\ngit checkout -b test/scaffold-check\nwip-release patch\n# Expected: scaffolded template created"},{"language":"bash","snippet":"wip-release patch --dry-run\n# Should show no \"fatal\" or \"Not a valid object name\" errors\n# Guard tests: cd tools/wip-branch-guard && bash test.sh"},{"language":"bash","snippet":"wip-release patch\ngit status\n# Should show clean working tree after release"},{"language":"bash","snippet":"cd tools/wip-branch-guard && bash test.sh\n# Should show: 30 passed, 0 failed, 3 skipped"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: wip-file-guard\ndescription: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\nlicense: MIT\ninterface: [cli, module, hook, plugin, skill]\nmetadata:\n  display-name: \"Identity File Protection\"\n  version: \"1.0.1\"\n  homepage: \"https://github.com/wipcomputer/wip-file-guard\"\n  author: \"Parker Todd Brooks\"\n  category: dev-tools\n  capabilities:\n    - file-protection\n    - edit-blocking\n    - identity-guard\n  requires:\n    bins: [node]\n  openclaw:\n    requires:\n      bins: [node]\n    install:\n      - id: node\n        kind: node\n        package: \"@wipcomputer/wip-file-guard\"\n        bins: [wip-file-guard]\n        label: \"Install via npm\"\n    emoji: \"🛡️\"\ncompatibility: Requires node. Node.js 18+.\n---\n\n# wip-file-guard\n\nHook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw.\n\n## When to Use This Skill\n\n**Use wip-file-guard for:**\n- Protecting CLAUDE.md, SOUL.md, IDENTITY.md, MEMORY.md, and other identity files from being overwritten\n- Blocking AI agents from replacing file content instead of extending it\n- Surviving context compaction (behavioral rules get erased, but hooks don't)\n\n**This is a technical guardrail, not a prompt.** It blocks the operation before it happens.\n\n### Do NOT Use For\n\n- Protecting binary files or images\n- Blocking all edits (it allows small edits, only blocks destructive ones)\n- Repos without identity files\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files. Always. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file.\n\n### Protected Files\n\nCLAUDE.md, SHARED-CONTEXT.md, SOUL.md, IDENTITY.md, CONTEXT.md, TOOLS.md, MEMORY.md\n\n### Protected Patterns\n\nAny file matching: memory, memories, journal, diary, daily log\n\n## API Reference\n\n### CLI\n\n```bash\nnode guard.mjs --list          # list protected files\nbash test.sh                   # run test suite\n```\n\n### Claude Code Hook\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node \\\"/path/to/wip-file-guard/guard.mjs\\\"\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## Troubleshooting\n\n### Agent keeps trying to Write\n\nThe deny message tells the agent to re-read the file and use Edit instead. If the agent ignores it, it's likely post-compaction and has lost context. The hook will keep blocking.\n\n### Edit blocked unexpectedly\n\nCheck the net line removal. Edits that remove more than 2 lines from a protected file are blocked. Small edits (adding or replacing 1-2 lines) are allowed."},{"path":"README.md","content":"###### WIP Computer\n\n[![npm](https://img.shields.io/npm/v/@wipcomputer/wip-file-guard)](https://www.npmjs.com/package/@wipcomputer/wip-file-guard) [![CLI / TUI](https://img.shields.io/badge/interface-CLI_/_TUI-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![OpenClaw Plugin](https://img.shields.io/badge/interface-OpenClaw_Plugin-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/openclaw.plugin.json) [![Claude Code Hook](https://img.shields.io/badge/interface-Claude_Code_Hook-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/guard.mjs) [![Claude Code Skill](https://img.shields.io/badge/interface-Claude_Code_Skill-black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-file-guard/SKILL.md) [![Universal Interface Spec](https://img.shields.io/badge/Universal_Interface_Spec-black?style=flat&color=black)](https://github.com/wipcomputer/wip-ai-devops-toolbox/blob/main/tools/wip-universal-installer/SPEC.md)\n\n# File Guard\n\nPreToolUse hook that blocks destructive edits to protected files. When an AI agent tries to overwrite or strip content from files like CLAUDE.md, SHARED-CONTEXT.md, or SOUL.md... it gets blocked with a clear explanation of what went wrong.\n\n## The Problem\n\nAI agents replace content instead of extending it. After context compaction, behavioral rules like \"don't delete things\" vanish. The agent rewrites your CLAUDE.md, strips 30 lines from SHARED-CONTEXT.md, or replaces your SOUL.md with a shorter version. Every time.\n\nFile Guard is a technical guardrail. It doesn't ask the agent to be careful. It blocks the operation before it happens.\n\n## How It Works\n\nTwo rules:\n\n1. **Write is blocked** on protected files outside shared state paths. Use Edit instead.\n2. **Edit is blocked** when it removes more than 2 net lines from a protected file (20 for shared state).\n3. **Shared state paths** (e.g. `~/.openclaw/workspace/`) are always writable. These are live agent workspace files, not code.\n\nThe agent gets a deny message explaining what happened and telling it to re-read the file and add content instead of replacing it.\n\n### Protected Files\n\n| File | What it protects |\n|------|-----------------|\n| `CLAUDE.md` | Project instructions, boot sequence, system docs |\n| `SHARED-CONTEXT.md` | Cross-agent shared state |\n| `SOUL.md` | Agent identity |\n| `IDENTITY.md` | Agent identity (alternate format) |\n| `CONTEXT.md` | Current state snapshot |\n| `TOOLS.md` | Tool and workflow rules |\n| `MEMORY.md` | Persistent memory and preferences |\n\n## Install\n\nOpen your AI coding tool and say:\n\n```\nRead the README at github.com/wipcomputer/wip-file-guard.\nThen explain to me:\n1. What is this tool?\n2. What does it do?\n3. What would it change or fix in our current system?\n\nThen ask me:\n- Do you have more questions?\n- Do you want to integrate it into our system?\n- Do you want to clone it (use as-is) or fork i"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b4mj57xb02gqhvjzgzkxq557zz95h\",\n  \"slug\": \"wip-file-guard\",\n  \"version\": \"1.9.72\",\n  \"publishedAt\": 1776806697219\n}"},{"path":"CHANGELOG.md","content":"# Changelog\n\n## 1.0.2 (2026-04-08)\n\nAdd `~/.openclaw/workspace/` to shared state paths. OpenClaw agent workspace files are live shared state, not code. The guard now checks shared state BEFORE exact-match protection, so workspace TOOLS.md, MEMORY.md, etc. can be written freely by the agent that owns them. Fixes Lēsa being unable to write her own workspace files after the guard was deployed to OpenClaw on Apr 4.\n\n## 1.0.1 (2026-02-21)\n\nAlign description, add SKILL.md, add badges, agent-driven install, REFERENCE.md"},{"path":"REFERENCE.md","content":"###### WIP Computer\n# wip-file-guard ... Reference\n\nManual install instructions, CLI usage, and customization.\n\n## Install\n\nInstall to your LDM OS home:\n\n```bash\nmkdir -p ~/.ldm/extensions/wip-file-guard\ncp guard.mjs openclaw.plugin.json package.json ~/.ldm/extensions/wip-file-guard/\n```\n\nAll config paths should point to the installed location (`~/.ldm/extensions/`), not the source repo.\n\n## Claude Code\n\nAdd to `~/.claude/settings.json`:\n\n```json\n{\n  \"hooks\": {\n    \"PreToolUse\": [\n      {\n        \"matcher\": \"Edit|Write\",\n        \"hooks\": [\n          {\n            \"type\": \"command\",\n            \"command\": \"node ~/.ldm/extensions/wip-file-guard/guard.mjs\",\n            \"timeout\": 5\n          }\n        ]\n      }\n    ]\n  }\n}\n```\n\n## OpenClaw\n\n```bash\ncp -r ~/.ldm/extensions/wip-file-guard ~/.openclaw/extensions/wip-file-guard\n```\n\nThe `openclaw.plugin.json` registers a `before_tool_use` lifecycle hook that applies the same rules.\n\n## CLI\n\n```bash\n# List protected files\nnode guard.mjs --list\n\n# Test the guard with a simulated input\necho '{\"tool_name\":\"Write\",\"tool_input\":{\"file_path\":\"/foo/CLAUDE.md\"}}' | node guard.mjs\n\n# Run the test suite\nbash test.sh\n```\n\n## Customization\n\n### Adding Protected Files\n\nEdit the `PROTECTED` set in `guard.mjs`:\n\n```javascript\nconst PROTECTED = new Set([\n  'CLAUDE.md',\n  'SHARED-CONTEXT.md',\n  'SOUL.md',\n  'IDENTITY.md',\n  'CONTEXT.md',\n  'TOOLS.md',\n  'MEMORY.md',\n  'YOUR-FILE-HERE.md',   // add yours\n]);\n```\n\n### Changing the Line Threshold\n\nThe default blocks edits that remove more than 2 net lines. Change the threshold in the Edit handler:\n\n```javascript\nif (removed > 2) {   // change 2 to your threshold\n```"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Skill: Wip File Guard Owner: parkertoddbrooks Summary: Hook that blocks destructive edits to protected identity files. For Claude Code CLI and OpenClaw. Tags: latest:1.9.72 Version history: v1.9.72 | 2026-04-21T21:24:57.219Z | user AI DevOps Toolbox v1.9.72 Promote v1.9.71-alpha series to stable Closes #256. Consolidates 21 alpha prereleases (v1.9.71-alpha.1 through v1.9.71-alpha.21) into a stable v1.9.72 release. No","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1231,"uniquenessScore":45,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T16:38:13.640Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T21:19:13.020Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}