ModsCode / Claude Code Mods / Ranking / guardrails
guardrails
Clickable safety rules with presets: block rm -rf, force-push, destructive git, secret files, sudo, installs, network; lock Claude to the project folder or read-only; add your own block patterns.
What it does
- Draws a pane, the status line, toasts
- Adds /guard, /guard-preset, /guard-log
- Watches tool calls and can refuse them
- Hooks session.start
- Keeps its own state between turns
Good points
- No network calls
- Starts no processes
- Written in TypeScript
- Handles errors
Code to start from
A starter ModsCode writes from the drawing it read, and the mod's own lines that draw, where there are any.
Starter (register.tsx)
import type { Register } from 'claude-code'
// Drawn like guardrails by Michael Goldenberg (pane, status, toast), as ModsCode read it from the mod's code:
// https://modscode.com/claude-mods/mods/mishgoldenberg-guardrails/
// Written by ModsCode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the pane: open it with $.ui.open({ id: 'my-pane', title: "Guardrails" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box, Text, Button, Input } = $.ui.resolve(e)
const status = '…'
const i = '…'
const title = '…'
const explain = '…'
const explain2 = '…'
const explain3 = '…'
const value = '…'
const pattern = '…'
const pattern2 = '…'
const pattern3 = '…'
const length = '…'
const tool = '…'
const rule = '…'
const what = '…'
const tool2 = '…'
const rule2 = '…'
const what2 = '…'
const tool3 = '…'
const rule3 = '…'
const what3 = '…'
const total = '…'
const n = '…'
const rule4 = '…'
const n2 = '…'
const rule5 = '…'
const n3 = '…'
const rule6 = '…'
return (
<Box flexDirection="column" gap={1}>
<Box gap={1}>
<Text color="claude">
●
</Text>
<Text bold>
guardrails
</Text>
<Text dimColor wrap="truncate-end">
{status}
</Text>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text dimColor>
Presets
</Text>
</Box>
<Box gap={1} flexWrap="wrap">
<Button hotkey={`${i}`} variant="primary" label={`${title}`} />
<Button hotkey={`${i}`} variant="primary" label={`${title}`} />
<Button hotkey={`${i}`} variant="primary" label={`${title}`} />
</Box>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text dimColor>
Rules
</Text>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text color="claude">
●
</Text>
<Button plain label={`${title}`} />
</Box>
<Box paddingLeft={2}>
<Text dimColor wrap="truncate-end">
{explain}
</Text>
</Box>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text color="claude">
●
</Text>
<Button plain label={`${title}`} />
</Box>
<Box paddingLeft={2}>
<Text dimColor wrap="truncate-end">
{explain2}
</Text>
</Box>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text color="claude">
●
</Text>
<Button plain label={`${title}`} />
</Box>
<Box paddingLeft={2}>
<Text dimColor wrap="truncate-end">
{explain3}
</Text>
</Box>
</Box>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text dimColor>
Your own block patterns (regex on shell commands)
</Text>
</Box>
<Box flexDirection="column">
<Text dimColor>
{value}
</Text>
<Box gap={1}>
<Text color="claude">
●
</Text>
<Text wrap="truncate-end">
/
{pattern}
/
</Text>
<Button plain label="remove" />
</Box>
<Box gap={1}>
<Text color="claude">
●
</Text>
<Text wrap="truncate-end">
/
{pattern2}
/
</Text>
<Button plain label="remove" />
</Box>
<Box gap={1}>
<Text color="claude">
●
</Text>
<Text wrap="truncate-end">
/
{pattern3}
/
</Text>
<Button plain label="remove" />
</Box>
<Input placeholder="regex, e.g. docker\s+system\s+prune" submitLabel="Add" />
</Box>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text dimColor>
{`Blocked this session (${length})`}
</Text>
</Box>
<Box flexDirection="column">
<Text dimColor>
Nothing blocked yet. When a rule stops a command, it shows up here with the rule that caught it.
</Text>
<Text wrap="truncate-end">
<Text color="error">
✗
</Text>
{" "}
{tool}
{" "}
<Text dimColor>
{rule}
{": "}
{what}
</Text>
</Text>
<Text wrap="truncate-end">
<Text color="error">
✗
</Text>
{" "}
{tool2}
{" "}
<Text dimColor>
{rule2}
{": "}
{what2}
</Text>
</Text>
<Text wrap="truncate-end">
<Text color="error">
✗
</Text>
{" "}
{tool3}
{" "}
<Text dimColor>
{rule3}
{": "}
{what3}
</Text>
</Text>
</Box>
</Box>
<Box flexDirection="column">
<Box gap={1}>
<Text dimColor>
{`Last 7 days (${total})`}
</Text>
<Button plain label="clear" />
</Box>
<Box flexDirection="column">
<Text dimColor>
Nothing blocked this week. Blocks from every session and project add up here; /guard-log prints a summary.
</Text>
<Box gap={1}>
<Box width="4" flexShrink={0} justifyContent="flex-end">
<Text color="error">
{n}
</Text>
</Box>
<Text wrap="truncate-end">
{rule4}
</Text>
</Box>
<Box gap={1}>
<Box width="4" flexShrink={0} justifyContent="flex-end">
<Text color="error">
{n2}
</Text>
</Box>
<Text wrap="truncate-end">
{rule5}
</Text>
</Box>
<Box gap={1}>
<Box width="4" flexShrink={0} justifyContent="flex-end">
<Text color="error">
{n3}
</Text>
</Box>
<Text wrap="truncate-end">
{rule6}
</Text>
</Box>
</Box>
</Box>
<Text dimColor>
Rules are best-effort pattern checks, a seatbelt, not a sandbox. Scripts the agent writes are checked before they run, …
</Text>
</Box>
)
})
on('session.start', async ($, e, next) => {
const count = '…'
const tool = '…'
const rule = '…'
await $.ui.status(`guard ${count} rules`)
await $.ui.toast(`Blocked ${tool}: ${rule}`)
await $.ui.toast(`That is not a valid regular expression.`)
return next(e)
})
}
The mod's own code
Shown under the mod's licence (MIT); its text is below. Keep the notice if you copy these lines.
plugins/guardrails/hooks/register.tsx lines 464–585 · Pane
on('ui.render', { component: 'Pane', requestId: PANE }, async ($, e) => {
const els = $.ui.resolve(e)
const { Box, Text, Button } = els
const Input = 'Input' in els ? els.Input : undefined
const cfg = await read($, config)
const recent = await read($, blocks)
const week = summarize(await read($, weekLog), await $.clock.now())
const kit = { Box, Text }
const isActive = (p: (typeof PRESETS)[number]) => p.rules.length === cfg.enabled.length && p.rules.every(r => cfg.enabled.includes(r))
const active = PRESETS.find(isActive)
const count = cfg.enabled.length + cfg.custom.length
const status =
count === 0
? 'all rules off'
: `${active?.title ?? 'custom set'} · ${count} rule${count === 1 ? '' : 's'} on${recent.length > 0 ? ` · ${recent.length} blocked` : ''}`
return (
<Box flexDirection="column" gap={1}>
{header(kit, count > 0 ? GLYPH.on : GLYPH.off, count > 0 ? TONE.accent : TONE.dim, 'guardrails', status)}
{section(
kit,
'Presets',
<Box gap={1} flexWrap="wrap">
{PRESETS.map((p, i) => (
<Button key={`preset-${p.id}`} hotkey={String(i + 1)} variant={isActive(p) ? 'primary' : 'secondary'} label={p.title} onPress={() => void save($, c => ({ ...c, enabled: p.rules }))} />
))}
</Box>,
)}
{section(
kit,
'Rules',
RULES.map(rule => {
const isOn = cfg.enabled.includes(rule.id)
return (
<Box flexDirection="column">
<Box gap={1}>
<Text color={isOn ? TONE.accent : TONE.dim}>{isOn ? GLYPH.on : GLYPH.off}</Text>
<Button
key={`rule-${rule.id}`}
plain
label={rule.title}
onPress={() => void save($, c => ({ ...c, enabled: isOn ? c.enabled.filter(id => id !== rule.id) : [...c.enabled, rule.id] }))}
/>
</Box>
<Box paddingLeft={2}>
<Text dimColor wrap="truncate-end">
{rule.explain}
</Text>
</Box>
</Box>
)
}),
)}
{section(
kit,
'Your own block patterns (regex on shell commands)',
<Box flexDirection="column">
{cfg.custom.length === 0 && empty(kit, String.raw`None yet. Example: terraform\s+destroy or kubectl\s+delete`)}
{cfg.custom.map((c, i) => (
<Box gap={1}>
<Text color={TONE.accent}>{GLYPH.on}</Text>
<Text wrap="truncate-end">/{c.pattern}/</Text>
<Button key={`del-${i}`} plain label="remove" onPress={() => void save($, cur => ({ ...cur, custom: cur.custom.filter((_, j) => j !== i) }))} />
</Box>
))}
{Input !== undefined && (
<Input
key="add"
placeholder="regex, e.g. docker\s+system\s+prune"
submitLabel="Add"
onSubmit={(value: string) => {
const pattern = value.trim()
if (pattern === '') return
try {
new RegExp(pattern)
} catch {
$.ui.toast('That is not a valid regular expression.')
return
}
void save($, c => ({ ...c, custom: [...c.custom, { pattern, note: '' }] }))
}}
/>
)}
</Box>,
)}
{section(
kit,
`Blocked this session (${recent.length})`,
<Box flexDirection="column">
{recent.length === 0 && empty(kit, 'Nothing blocked yet. When a rule stops a command, it shows up here with the rule that caught it.')}
{recent.slice(0, 6).map(b => (
<Text wrap="truncate-end">
<Text color={TONE.bad}>{GLYPH.fail}</Text> {b.tool} <Text dimColor>{b.rule}: {b.what}</Text>
</Text>
))}
</Box>,
)}
{section(
kit,
`Last 7 days (${week.total})`,
<Box flexDirection="column">
{week.total === 0 && empty(kit, 'Nothing blocked this week. Blocks from every session and project add up here; /guard-log prints a summary.')}
{week.byRule.slice(0, 5).map(([rule, n]) => (
<Box gap={1}>
{num(kit, String(n), 4, TONE.bad)}
<Text wrap="truncate-end">{rule}</Text>
</Box>
))}
</Box>,
week.total > 0 ? <Button key="clear-log" plain label="clear" onPress={() => void clearLog($)} /> : undefined,
)}
<Text dimColor>Rules are best-effort pattern checks, a seatbelt, not a sandbox. Scripts the agent writes are checked before they run, and the agent can't edit these settings. Everything stays on this machine.</Text>
</Box>
)
})plugins/guardrails/hooks/register.tsx lines 12–20 · Pane
function header({ Box, Text }: Kit, glyph: string, tone: string, name: string, status: string) {
return (
<Box gap={1}>
<Text color={tone}>{glyph}</Text>
<Text bold>{name}</Text>
<Text dimColor wrap="truncate-end">{status}</Text>
</Box>
)
}plugins/guardrails/hooks/register.tsx lines 23–33 · Pane
function section({ Box, Text }: Kit, label: string, rows: RenderChildren, aside?: RenderChildren) {
return (
<Box flexDirection="column">
<Box gap={1}>
<Text dimColor>{label}</Text>
{aside}
</Box>
{rows}
</Box>
)
}plugins/guardrails/hooks/register.tsx lines 45–47 · Pane
function empty({ Text }: Kit, text: string) {
return <Text dimColor>{text}</Text>
}plugins/guardrails/hooks/register.tsx lines 36–42 · Pane
function num({ Box, Text }: Kit, value: string, width: number, color?: string) {
return (
<Box width={width} flexShrink={0} justifyContent="flex-end">
<Text color={color}>{value}</Text>
</Box>
)
}Licence text (MIT)
MIT License Copyright (c) 2026 Michael Goldenberg Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
How to build this: Pane (panel), Deny a tool call
What its code calls
tool callsremembers
What its code shows
Read from the source at commit 0954c978c110 on 2026-10-11. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.
| Decides the listing: code you can check | |
|---|---|
| Entry read | Every module hooks/hooks.json names was read.plugins/guardrails/hooks/register.tsx |
| Parses | Every file parses as TypeScript or JavaScript.1 files parsed |
| All its code is in the mod | Every import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod |
| Readable | No minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs |
| Calls in the open | Network and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open |
| For you to weigh before installing | |
| Where it draws | The terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both |
| Install line | Whether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.listed in its repository's .claude-plugin/marketplace.json: installs from there |
| Programs on Windows | Whether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).runs no program a Windows PC lacks |
| Network | Whether every fetch names its https host in the code.no network |
| Programs | Whether every program it starts is named in the code and is not a shell, an interpreter or a network tool.starts no programs |
| Reads and sends | Whether it both reads something of yours (files, environment variables, the transcript, settings) and reaches outside (the network, an MCP server, another session, telemetry).reaches nothing outside |
| Keys in the source | Whether the source holds what looks like an API key or a private key.no keys in the source |
| Licence | An open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets ModsCode show its code; otherwise the code is linked.MIT |
| Settings hooks | Hooks declared in hooks/hooks.json or plugin.json beside the module: a command (a shell when it has no args), an HTTP request, an MCP tool or a model prompt at an event. They run outside $.no settings hooks: its function hooks alone |
| Servers it ships | MCP servers (a program, or a URL; a headersHelper is a shell command; a .mcpb bundle is unpacked at run time), LSP servers, monitors (a shell command for the whole session) and bin/ (on the PATH of the Bash tool).ships no MCP or LSP server, no monitor, no bin/ |
| Skills, commands, agents | What its Markdown declares beyond text: allowed-tools granted for the turn, hooks added when a skill is invoked, a command run before Claude reads the skill.no skills, commands, agents or workflows |
| Tools and MCP | Whether every tool it calls through $.tool.call and $.mcp.call is named in the code, and none is a shell (Bash through the tool runs a shell without $.process).calls no tool, MCP server or command |
| Asks of the model | Completions it runs ($.model.complete, fork, classify), subagents it spawns, prompts it submits as you, and the tools, commands and agents it adds.adds command guard, adds command guard-preset, adds command guard-log |
| Events it hooks | By what a hook there can do: gates (refuse a tool call, a prompt, a setting, another plugin), shapes (what the model reads: the system prompt, tool descriptions, each request), reads (your input, the events of the settings hooks, every event with *), and the rest.gates: command.run (guard, guard-preset, guard-log), tool.call · also: session.start, ui.render (Pane) |
| Reads, by name | The environment variables and files it names, and whether it reads the transcript, settings.json, the prompt box or the mouse selection.reads no files, environment variables, settings or transcript |
| Writes, by name | The files and environment variables it names, and whether it changes settings, the prompt box, the clipboard, the conversation (a row the model reads) or another session.writes no files, environment variables, settings or conversation rows |
This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen
Install it
Check it yourself before you install it. Mods run unsandboxed, with your permissions, and ModsCode does not vouch for what this code does. Read its code (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.
From its marketplace
Its repository is its marketplace. Add that marketplace (in the terminal with these commands, or in the desktop app's plugin settings) and install the mod from it:
/plugin marketplace add mishgoldenberg/claude-mods/plugin install guardrails@claude-mods/reload-pluginsThis installs the marketplace's latest commit, which may not be the one read here (0954c978c110). Compare them before you install. /reload-plugins loads it into a session that is already open.
Try the commit ModsCode read
No marketplace needed. In a terminal, clone the repository, check out the commit read, validate the mod, and load it for one session:
git clone https://github.com/mishgoldenberg/claude-modsgit -C claude-mods checkout 0954c978c1101ebea60edee1331c8586a5d0ff6fclaude plugin validate claude-mods/plugins/guardrailsclaude --plugin-dir claude-mods/plugins/guardrailsThe validate line lists the events the mod hooks and what it asks Claude Code to do, without running it. The last line loads the mod for this session only and writes nothing to your settings. If the author has rewritten history, the commit may no longer exist.
Ask Claude about it
With the ModsCode connector added, Claude can read this mod's code and what it reaches, and build on them. Ask it like this:
Read the ModsCode mod "mishgoldenberg-guardrails" with its code and make me one like itSearch them from Claude: the MCP connector
Similar mods
- code-modernizationAnthropic★ 37,653
- great-ctoAlexander Velikiy★ 103
- agent-discoverkeshrath★ 7
- context-keeperMichael Goldenberg★ 6
- roadraven-hudShuffzord★ 6
- usage-meterMichael Goldenberg★ 6
More from this repository
- activityMichael Goldenberg★ 6
- changesMichael Goldenberg★ 6
- command-hubMichael Goldenberg★ 6
- context-keeperMichael Goldenberg★ 6
- loop-breakerMichael Goldenberg★ 6
- mod-managerMichael Goldenberg★ 6
See all 12 mods in this repository
Badge for your README
If this is your mod, paste this into your README. It links to this page.
[](https://modscode.com/claude-mods/mods/mishgoldenberg-guardrails/)