.claude/hooks/block-dangerous-commands.sh guards branch switches on this repository's main working tree, and correctly skips commands aimed at another repository — targets_this_main_tree returns false and the guard continues.
It parses the command text, so a -C argument that arrives through a shell variable is unresolvable, and unresolvable is treated as "targets this tree" and denied:
git -C $SKILLS_REPO switch release -> Blocked
git -C /absolute/path/to/skills-repo switch release -> allowed
Identical commands against a completely different repository, opposite outcomes.
Failing closed is the right default for a safety guard and should not change. But the hook's own comments say a guard that denies correct work teaches people to route around it, and this denies correct work with no hint that the variable is the cause.
Acceptance criteria
.claude/hooks/block-dangerous-commands.shguards branch switches on this repository's main working tree, and correctly skips commands aimed at another repository —targets_this_main_treereturns false and the guard continues.It parses the command text, so a
-Cargument that arrives through a shell variable is unresolvable, and unresolvable is treated as "targets this tree" and denied:Identical commands against a completely different repository, opposite outcomes.
Failing closed is the right default for a safety guard and should not change. But the hook's own comments say a guard that denies correct work teaches people to route around it, and this denies correct work with no hint that the variable is the cause.
Acceptance criteria
-Cargument as the reason-Cpointing outside this repository is not denied, or the message says to use a literal path