---
title: "rtk-dangerous-actions-blocker"
description: "Carved out for rtk-ai/rtk#1007: rtk's own decision table as a chock policy (rtk's own hooks may not block). Refuses rm -rf on root, home, parent or absolute paths; git push --force and '+' refspecs (not --force-with-leas"
canonical: https://agentpluginsdirectory.com/plugins/rtk-dangerous-actions-blocker--open-coder-ai
last-updated: 2026-09-14
---

# rtk-dangerous-actions-blocker
Carved out for rtk-ai/rtk#1007: rtk's own decision table as a chock policy (rtk's own hooks may not block). Refuses rm -rf on root, home, parent or absolute paths; git push --force and '+' refspecs (not --force-with-lease); reads of credential files (.env, *.pem, *.key, id_rsa, ~/.ssh, ~/.aws) and echoes or inline literals of *_API_KEY/*_SECRET/*_TOKEN; DROP/TRUNCATE/unscoped DELETE through psql, mysql, sqlite3, mongosh, redis-cli, and dropdb; plus the base policy's cloud rows (kubectl delete, terraform destroy, aws s3 rm --recursive, helm uninstall, gcloud delete, docker volume rm). Asks where rtk's table says ask: rm -rf on a relative path off the safe list; git reset --hard, clean -f, checkout., branch -D; docker prune and docker rm -f over a substitution. File checks are skipped inside docker/kubectl exec, as rtk specifies; rtk is a transparent prefix. Bypasses: aliases, quoting, indirection, sourced files, interpreters, indirect scripts. This is friction, not a security boundary.
- Slug: rtk-dangerous-actions-blocker--open-coder-ai
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock-catalog
- Manifest: base/rtk-dangerous-actions-blocker/plugin.json
- Version: 0.0.1
- License: Apache-2.0
- Category (editorial): other
- Skills: 1 (rtk-dangerous-actions-blocker)
- MCP servers: 0
- Stars: 2
- Repository created: 2026-08-17
- Repository last pushed: 2026-09-13
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/rtk-dangerous-actions-blocker--open-coder-ai
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- rtk-dangerous-actions-blocker: Carved out for rtk-ai/rtk#1007: rtk's own decision table as a chock policy (rtk's own hooks may not block). Refuses rm -rf on root, home, parent or absolute paths; git push --force and '+' refspecs (not --force-with-lease); reads of credential files (.env, *.pem, *.key, id_rsa, ~/.ssh, ~/.aws) and…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
