Safety Nets
please can discard work. It never does so quietly.
Destructive operations require confirmation
Anything that can discard work, please sync exactly, please discard, please revert on a conflict cancel path, please stash drop, explains the consequences up front and requires you to type yes before it proceeds.
See the reference table on the Commands page for which commands are marked destructive.
Explicit overrides, not blanket blocks
Guardrails such as the sensitive file check and the junk directory check in please commit can always be bypassed by staging the file yourself first. please assumes intent over blocking outright: if you already ran git add on a .env file, that is treated as your explicit choice to include it.
A stricter layer in agent mode
Agent mode and please chat add a second layer on top of the destructive operation confirmations above, because here the developer isn’t the one typing the command.
Read only calls run immediately; everything that mutates the repo, whether it’s a raw git/gh call or a please subcommand, asks [y/N] first — with the agent’s own reasoning printed before you’re asked, so you’re never confirming blind. A handful of commands can only be confirmed by someone at a real keyboard (discard, purge, revert, squash, sync exactly, stash drop, switching to a branch that doesn’t exist yet); the agent refuses those outright and tells you to run them yourself instead of attempting them.
See Agent Mode for the full explanation.