Hooks that stop a Claude Code agent from doing the things you cannot take back: pushing to the branch that deploys, force-pushing over history, committing a live API key, and sweeping another session's half-finished work into its own commit. Rules in CLAUDE.md are prose, and an agent forty turns into a task drops prose. These are PreToolUse hooks. Claude Code runs them before every matching tool call, and a deny stops the call, bypass-permissions mode included. What's in it Push gate: no force push, no push to protected branches, plus held commands such as npm publish that a human runs. Staging gate: no git add -A, git add . or git commit -a. Explicit paths only. Secret gate: no live key written into a tracked file, committed, or staged via .env. Anthropic, OpenAI, Stripe, AWS, GitHub, Supabase JWTs and more, matched on the real key shape. Skill gate: "run skill X before touching Y", enforced instead of hoped for. Session detection and worktrees: the agent is told when another session shares the tree, and worktree.py gives it its own, with .env copied and node_modules linked. Invariant checker: your repo rules as regexes, each with examples it must catch and lookalikes it must ignore. An installer that merges into your existing settings, runs every self-test and feeds real payloads through the installed hooks. Plus a Claude Code subagent that reads your repo and does the whole install for you. Python 3.9+ standard library only. No pip install, no network calls, no API keys. Windows, macOS and Linux. An independent kit, not made by or affiliated with Anthropic. Background on how these were built: unstucked.dev/fixes