Before ANY destructive, irreversible, or high-impact action, pause and surface a clear checklist of what's about to happen...
File Operations:
rm, rm -rf, rmdirmv on important filesDatabase:
DROP TABLE, DROP DATABASEDELETE FROM without WHERE or with broad WHERETRUNCATEUPDATE on multiple rowsGit:
git push --forcegit reset --hardgit clean -fdDeployment:
Permissions/Security:
chmod 777)Bulk Operations:
When you're about to execute something from the trigger list, STOP.
You Sure?
You're about to:
[ ] [Specific action 1]
[ ] [Specific action 2]
[ ] [Specific action 3]
Impact:
- [What will change]
- [What could break]
- [Affected scope: N files/rows/users]
Reversibility:
- [Can this be undone? How?]
- [Backup available: Yes/No]
Environment: [dev/staging/prod]
Type 'go' to proceed, or 'abort' to cancel.
Do NOT proceed on:
Only proceed on:
This forces intentionality.
This affects PRODUCTION and cannot be easily undone.
You're about to: [ ] DROP TABLE users (48,293 records)
This will permanently delete all user data.
Backup status: [Check for recent backup] Rollback: Not possible without backup restore
Are you absolutely sure? Type 'confirmed' to proceed.
**HIGH** - Destructive but recoverable:
HIGH - You Sure?
You're about to: [ ] rm -rf ./build/*
This will delete 847 files in the build directory. Recoverable: Yes (can rebuild)
Type 'go' to proceed.
**MEDIUM** - Notable changes:
You Sure?
You're about to: [ ] git push --force origin feature-branch
This will rewrite history on the remote branch. Others pulling this branch will need to reset.
Type 'go' to proceed.
</severity>
## Smart Detection
Don't be annoying on obviously safe operations:
**DO trigger:**
- `rm -rf /important/path`
- `DELETE FROM users`
- `git push -f origin main`
**DON'T trigger:**
- `rm temp_file.txt` (single temp file)
- `DELETE FROM users WHERE id = 1` (single row, specific)
- `git push origin feature-branch` (normal push)
Use judgment:
- Known test/temp files -> skip
- Production paths -> always trigger
- Broad operations -> trigger
- Narrow, specific operations -> skip unless destructive
## NEVER
- Auto-execute destructive operations without confirmation
- Accept vague confirmation ("sure", "yep")
- Proceed if user seems uncertain
- Skip sanity check because user is in a hurry
- Execute destructive operations in a loop without per-batch confirmation
## ALWAYS
- Show exactly what will happen (not vague descriptions)
- Show affected scope (number of files/rows/users)
- State whether it's reversible
- Require explicit confirmation word
- Offer to show preview/dry-run when available
## Examples
### Example 1: Database Delete
User: "Delete all inactive users"
You Sure?
You're about to: [ ] DELETE FROM users WHERE last_active < '2024-01-01'
Impact:
Reversibility:
Want me to: A) Show a preview first (SELECT COUNT) B) Proceed with delete
Type 'go' to proceed, or 'preview' to check first.
### Example 2: Force Push
User: "Force push to main"
CRITICAL - You Sure?
You're about to: [ ] git push --force origin main
Impact:
Reversibility:
This is rarely the right choice for main branch. Did you mean to push to a feature branch?
Type 'confirmed' to force push to main anyway.
### Example 3: Bulk File Delete
User: "Clean up all the log files"
You Sure?
You're about to: [ ] rm -rf ./logs/*.log
Impact:
Reversibility:
Type 'go' to proceed.
### Example 4: Safe Operation (No Trigger)
User: "Delete that temp file we made"
[No sanity check needed - single temp file, user knows about it]
Done. Deleted temp_output.json ```