Design and review safe, portable, dry-run-first Bash scripts for local agentic workflows; gate writes, destructive commands, secrets, and offline validation.
Produce or review a Bash script that is portable, dry-run-first, and provably non-destructive before it touches the filesystem. The deliverable is a script (or review) plus a machine-checkable safety report that the offline validator passes. [DOC]
rm -rf, force push, secret leaks, or broad overwrite. [INFERENCE]sudo is implied. [DOC]--apply, --force, and fallback behavior. [DOC]Missing write surface or dry-run intent is a {VACIO_CRITICO}-class gap for the
runbook family — stop and ask; never auto-fill the destructive default. [INFERENCE]
assets/safe-scripting-and-bash-contract.json — machine-checkable script plan or review. [CONFIG]assets/write-surface-policy.json — declare read/write scope, paths, broad-write risk. [CONFIG]assets/dry-run-policy.json — require dry-run default, explicit apply, explicit force for overwrites. [CONFIG]assets/destructive-command-policy.json — block unsafe shell patterns unless approved and isolated. [CONFIG]assets/portability-policy.json — portability, quoting, repo-root detection, tempdir rules. [CONFIG]assets/validation-policy.json — require syntax checks and deterministic smoke tests. [CONFIG]assets/quality-rubric.json — blocking safety checks and the bound-verdict rule; see assets/README.md. [CONFIG]bash skills/safe-scripting-and-bash/scripts/check.shThe validator FAILS on any of: missing dry-run, missing repo-root detection, unknown write surface, unguarded destructive command, secrets exposure, unsafe tempdir, missing validation, or a Guardian "pass" verdict over a failed check. A green run is necessary, not sufficient — also satisfy Success Criteria. [CONFIG] Never report green as success when any individual check failed. [DOC]
rm -rf, git reset --hard, force push, or broad overwrite without explicit approval AND path isolation. [DOC]git rev-parse --show-toplevel or equivalent. [CODE]--force; --force requires a prior dry-run. [DOC]curl/network calls inside the validator or as a safety precondition — checks stay offline. [DOC]**/* or whole-repo rewrite): require dry-run, --apply, --force, and rollback notes before proceeding. [INFERENCE]/tmp/foo; use mktemp -d and trap-clean it. [CODE]"$var" and "${arr[@]}"; word-splitting is a write-surface hazard. [CODE]rm -rf, sudo, or an absolute path → stop, isolate, or refuse. [DOC]sudo, chmod 777, piping curl | bash. [DOC]If safe automation is unclear or a hard limit blocks it, produce a checklist and manual commands instead of a script — never ship an unsafe script to "get it done". [DOC]
--apply to write, --force to overwrite). [DOC]rm -rf, sudo, absolute paths, static tempdirs, and missing dry-run. [DOC]fdad39c
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.