ModsCode / Claude Code Mods / Ranking / Safety guards
Safety guard mods
Mods that watch for risky actions: guards, denied commands, secrets and dangerous calls.
- ★413 mods in 253 repositories, ranked by stars
- Where it runs: the terminal, the desktop app, or both
- How far its code reaches, from drawing only to the network
Grouped by the words in each mod's name and description, not by reading its code. A mod can be in several groups; one that does not say what it is for is in none.
/
Mods run with your permissions. Check first.
The rest of the list did not load, so this search covers this page only.
Filters253 shown
Runs in:
Draws in:
Uses:
Reach:
Without:
Listed in:
- blast-radiusSee what a risky command would change before it runs.deepseek-ai★ 247,289
-
ruflo-protectorProject Anatole: an optional, learning watchdog for unattended agents. Deterministic OWASP-mapped rules, a per-project behavioural baseline, four modes (off, learn, notify, enforce), alerts you can read later.ruvnet★ 74,323
4 more in this repository
- ruflo-agentAgent runtimes for ruflo — local WASM-sandboxed agents (rvagent: 10 wasm_agent_*/wasm_gallery_* MCP tools, built on @ruvector/rvagent-wasm + @ruvector/ruvllm-wasm per ADR-070) plus Anthropic Claude Managed Agents as a cloud backend (manage…ruvnet★ 74,323
- ruflo-aidefenceAI safety scanning, PII detection, prompt injection defense, and adaptive threat learningruvnet★ 74,323
- ruflo-federationCross-installation agent federation with zero-trust security, peer discovery, consensus-based task routing, and per-call budget circuit breaker (ADR-097)ruvnet★ 74,323
- ruflo-security-auditSecurity review, dependency scanning, policy gates, and CVE monitoringruvnet★ 74,323
- cuelumeTwo cuelume sounds for Claude Code: ready when a long turn ends, attention when a permission prompt waits.Daniel Belyi★ 1,951
- ai-maestro-secretsLets an agent ask for a credential. You type it into a field in Claude Code; it goes to your local vault (aim-secret), never to the model or the chat.23blocks-OS★ 817
- hello-modThe smallest Claude Mod: logs one line when the session starts and refuses one Bash command. Three files, no dependencies, exists so you can see the validator print a footprint.Karan Bansal★ 483
- secrets-veilMasks secret values in tool results before the model reads them: named vendor variables, value-shape patterns, and high-entropy tokens. No reveal path.OrchestKit★ 292
- codev-spikeEXPERIMENT #1782 spike: Codev guard, attribution scrub, context band and issue peek. Never installed; loaded only by an explicit --plugin-dir.Codev★ 288
- pii-guardDe-identifies personal data before it reaches the model and restores it on the way back out, by asking the resident pii-guard hookd service on loopback. Tool results are redacted, writes and shell commands are restored, a prompt's @ refere…pii-guard-tw★ 247
- blast-radiusHolds risky Bash commands and shows what they would change before they run.Hamza Zafar★ 184
- blast-radiusHolds risky shell commands (rm -rf, git reset --hard, git clean, force push, migrations) and shows what they would change, with Proceed and Cancel buttons.Claude Code DevRel★ 127
- intentic-guardKeeps the sandbox's own decisions on tool calls final: a mod someone installs can neither answer nor overturn them.Intentic★ 77
- corgi-guardStops the Bash shapes that fail in corgi runs (zsh set -- $pair, rm -rf on corgi worktrees) and adds the corgi fix to errors it knowsAndrii Klymiuk★ 37
-
harness-modsHarness Mod layer: heartbeat/canary, native usage, rewrite explanations, measured subagent accounting, supervisor routing, secret redaction. Modes per guard in ~/.claude/mods/mods-config.json (classic | shadow_mod | mod).Wes Sander★ 28
4 more in this repository
- prodguardPRODUCTION GUARD: ambient project/environment context + a transport-independent policy core (DashClaw evidence classifier + offlocal policy engine) enforced natively on tool.call and tool.check. Blocks, asks, or contains before the command…claude-mods-rnd★ 28
- probe2Interception probe: deny, rewrite, replace result, delay, throw, register tool, classifyucsandman★ 28
- guardianGUARDIAN: executable policy that protects lab/demos/protected/** from Write/Edit/Bash, whatever CLAUDE.md saysucsandman★ 28
- tunnel-policyMIDDLEWARE TUNNEL stage 3: Policy: allows everything harmless; denies a matching ruleucsandman★ 28
- jev-permission-gateUses TypeSafe's Jev to allow or deny routine tool calls in auto mode, and hands uncertain ones to the built-in classifierMadison Rickert★ 27
- rollback-noticeWhen a gate denies a Bash call, tells the model the whole call was rolled back and must be re-run in full; refuses git commit -F from shared /tmp.BioInfo★ 27
- modtestSandbox for Claude Code mods experiments (not published)dstoic★ 20
- force-push-guardRefuses git push --force before it runsKen Kousen★ 19
- wp-credential-guardMasks WordPress usernames and Application Passwords in prompts with session-scoped placeholders, and restores them into Bash commands at execution time.Nathan Onn★ 19
- lemo-guard限时:Claude 单轮工作超时自动中止 · 等你确认的时间不计 · 默认关闭,在「安全」页开启 / Time limit: stops Claude when a turn runs over time · time waiting for you does not count · off by default, switch on in Safetylemomo★ 16
- orbitDurable tasks, sandboxed parallel runs, and PR-gated delivery for AI coding agents. Adds Orbit's MCP tools and workflow skills to Claude Code.constellation-works★ 14
-
redactMasks credential-shaped strings in a Read tool result before the model reads it.thkt★ 12
1 more in this repository
- lightningAgent skills for the Lightning AI platform: GPU Studios, batch jobs, deployments, sandboxes, the LLM gateway, shareable artifact links, and up-front cost estimates.Lightning AI★ 9
- wardenKOZMOS Warden: a guard for destructive shell commands. Before Claude or a subagent runs rm -rf on a broad path, git push --force, reset --hard, clean -fd, DROP TABLE, mkfs, format, curl | sh and their kin, warden asks you (Allow once / Den…KOZMOS★ 9
- collision-guardAsks before Claude edits a file another open chat changed in the last 30 minutes: Proceed, Move to a worktree, or Cancel (/guard)Nate Herk★ 8
- ensemblr-modsEnsemblr's Claude Code function hooks: refuse git moves that break the workspace model, redact known secret values, keep control-tool ids through compaction, and add the linked Linear issue to a conversation.Ensemblr★ 8
- guardsConfirms git commands that would discard changes this session did not make and commands that start cloud billing; refuses global random seedswmayner★ 8
- jev-guardProbability-scored guardrails for Claude Code: deny rule-breaking edits and unasked-for deploys, route your own docs into each prompt, and check the final answer against the turn's own evidence.Oguzhan Cakmak★ 7
- storage-guardAfter an edit that keeps browser data in localStorage or sessionStorage, names each line, so the model stores the data in a cookie instead.Kerem Gok★ 7
- guardrailsClickable safety rules with presets: block rm -rf, force-push, destructive git, secret files, sudo, installs, network; lock Claude to the project folder or read-only; add your own block patterns.Michael Goldenberg★ 6
-
loop-guardTells the model, out of the user's sight, to stop when the same call fails twice with the same errorMehmet Aras★ 6
2 more in this repository
- secret-guardKeeps secrets out of the conversation: hides API keys and private keys before the model or the transcript sees them, and blocks reads of credential files and commands that print secretsMehmet Aras★ 6
- guardrailsBlocks shell commands you pick in /config: Cloudflare cf writes, attribution lines in commits and PRs, claude/ branch names. All rules start offMehmet Aras★ 6
-
redact-outputExample: rewrites Bash output so the model never reads tokensBeLazy167★ 6
1 more in this repository
- risky-modSynthetic fixture: every red flag on purpose. Never install.AgriciDaniel★ 6
- taxi-speedcam위험한 Bash 명령 앞의 과속 단속 카메라: force push·rm -rf·DB 삭제·변경 폐기·운영 배포를 찰칵 잡아 [가주세요]/[세워주세요]로 묻습니다개발동생 (devbrothers)★ 6
-
findmutlu-soundsSound packs for the moments that need you: a prompt sent, a permission prompt, a long job done, a subagent back, a failed test, a git push, a compaction. Packs from StarCraft, Warcraft, Age of Empires, Command & Conquer, Diablo, Counter-St…Mehmet Mutlu★ 5
2 more in this repository
- dash-guardRefuses prose that Claude writes with an em dash, an en dash or a double hyphen, and tells Claude which lines to rewriteMehmet Mutlu★ 5
- shared-file-guardRefuses a shell write to a shared file (STATUS.md, CLAUDE.md, MEMORY.md, or the files you name) that this session has not read, or that another session changed sinceMehmet Mutlu★ 5
- honmoon-redactClient-side secret/PII redaction hooks: keep API keys and sensitive identifiers out of Claude Code's model context by redacting Read/Bash/Grep tool output, blocking prompts that carry secrets, and denying reads of known credential files. S…Honmoon★ 5
- budget-guardStops a session before it runs past a budget. Three figures are guarded, each with a limit you set: the session cost in dollars, the 5-hour plan window and the 7-day plan window. It says nothing until a figure nears its limit, then pins a …Arunjay★ 4
-
budget-guardHolds a prompt back once your 5-hour or weekly usage is at or over a limit you set (90% by default); sending it again goes through. No tokens spent.Vedant Andhale★ 4
4 more in this repository
- collision-guardAsks before Claude edits a file another chat on this machine changed in the last 30 minutes. Each chat keeps its own small ledger; no model calls, no network.Vedant Andhale★ 4
- loop-guardHolds back a shell command once when the exact same command already failed twice in a row, and tells Claude to change approach; retrying it still goes through.Vedant Andhale★ 4
- reread-guardStops Claude re-reading a file it already read in this conversation, with Read or a plain cat, sed -n, head, tail or Get-Content, when the file has not changed since; a deliberate second attempt still goes through.Vedant Andhale★ 4
- write-guardSteers Claude to Edit instead of rewriting an existing file in full with Write: the first rewrite in a conversation goes through with a one-line note, a later one is held back once; a deliberate retry still goes through.Vedant Andhale★ 4
- hangar-bridgeTells Hangar.AI what the Claude Code session in each of its panes is doing: turns, permission prompts, context and plan usage. Loaded by Hangar for the panes it launches; does nothing anywhere else.simnJS★ 4
- install-doctorReports the install-doctor verdict at session start and refuses tool calls while the install is provably brokenRaymond Manaloto★ 4
- lexi-modsOpt-in Claude Code mods for lexi: gate phase in the status line and a band above the prompt, a toast when the lexi guard blocks an edit, and a pane of running subagents, colored by type, each opening onto its tool-call timeline and answer.Savino Fiore★ 4
- prod-guardHolds production deploys and database commands in a dialog that shows what would shipJeremy Winterberg★ 4
-
redactHides secrets (API keys, tokens, private keys) from the model in prompts and tool resultsThisaruGuruge★ 4
1 more in this repository
- secret-redactorKeeps secrets, email addresses and IP addresses out of the session transcript: swaps each one for a stable placeholder on the way in, and puts the real value back on the way into a tool callRay Amjad★ 4
- allowlist-coachCounts permission dialogs per rule and, after repeated approvals, offers to add the rule to permissions.allow, asking before it writesLucas Fernandes★ 3
- cockpitAgent cockpit for Claude Code: live context, limits, cost, tools, files, tests and a guard for risky commandsdrkokorev★ 3
-
flywheel-modHolds risky Bash, PowerShell and file-edit calls with the Flywheel pre-action monitor, writes a hash-chained receipt for every turn, and shows held and passed counts above the prompt. Adds holds only; never approves a call.Zain Dana Harper★ 3
1 more in this repository
- read-only-modeToggle a reminder guard that refuses built-in mutating tools and Bash.Yash Thakker★ 3
- screen-guardMasks sensitive names, orgs and secrets in the transcript for screen sharing; /mask toggles, click a mask to revealDustin Yuchen Teng★ 3
- signet-eval-functionsOptional Claude Code 2.1.274 and 2.1.280 function hooks for Signet-eval policy and output redactionWander★ 3
- ultramodThe best all-in-one mod pack for Claude Code: a usage limits and context HUD, a guard with undo for rm -rf and git reset --hard, .env and secret protection, and a receipt for every turn.Mert Kaya★ 3
- agent-usage-guardA Claude Code mod that holds subagent fan-out, heavy-context prompts and retry loops before they spend your usage window. It reads your plan's usage, counts agents across every session, and asks in Claude Code's own dialog.Riccardo Bartoli★ 2
- ato-guardIn the ATO repository only: masks TFNs, ABNs, bank details and Xero/Bearer tokens in tool results, blocks Xero API and SBR/lodgement writes, refuses other mods that rewrite tool calls or prompts, and keeps a local audit of counts onlyUnite-Group★ 2
-
bash-guardA seatbelt for YOLO mode: blocks catastrophic shell commands (rm -rf ~, mkfs, dd to a disk, fork bombs) and asks before risky ones (force-push, reset --hard, DROP TABLE, curl | sh), even with permissions bypassed.awesome-claude-mods★ 2
5 more in this repository
- file-guardKeeps Claude's file edits inside the project: refuses writes outside it (symlinks resolved), never lets a tool touch .git internals, and asks before it changes lockfiles, CI workflows, migrations or secrets.awesome-claude-mods★ 2
- injection-guardDefuses prompt injection in tool output: strips invisible Unicode that hides text from you but not from the model, and flags web pages, files and command output that carry instructions aimed at Claude.awesome-claude-mods★ 2
- net-guardStops data exfiltration and surprise network calls: checks every curl, wget, ssh, scp, git push and WebFetch against allow and deny lists, and asks before data goes to a host you haven't approved.awesome-claude-mods★ 2
- secret-shieldKeeps secrets out of Claude's context: API keys, tokens, private keys and passwords in tool output are replaced with [REDACTED:kind] before the model or the transcript ever sees them.awesome-claude-mods★ 2
- slopsquat-guardStops Claude from installing hallucinated or typosquatted packages: every npm, pip, uv, poetry, cargo and gem install is checked against its registry first. Packages that don't exist are blocked; brand-new, barely used or lookalike package…awesome-claude-mods★ 2
- cache-guardWarns once before a message that will cost far more than usual: a large Claude Code context whose prompt cache has expired, or a model or effort change that resets it. Shows the estimated cost, and offers a handoff file written by a cheap …Agulhas Labs★ 2
- concurrency-guardCaps parallel subagents and monitors; more need a stated reason and the user's approvalMichael Prömpler★ 2
- credential-pasterPut API keys and other secrets into any config file without them appearing in chat, shell history or tool output.Tim Arnold★ 2
-
game-barrierStops irreversible calls: force-push to main, reset --hard, rm -r outside the project, publishing, DROP TABLE, and file edits outside the projectReason of Moon★ 2
3 more in this repository
- game-trap-guardStops tool calls that would leak a secret: literal keys in commands or source files, cat .env / echo $API_KEY, reading key files into the conversationReason of Moon★ 2
- game-earcons8-bit sound cues on macOS, Windows and Linux: a permission prompt or question waiting on you, a long turn finished, an error, a guard refusing a call, a saveReason of Moon★ 2
- game-spell-checkVague words (적당히, 알아서, 대충 …) underlined while you type and secrets in red; a vague prompt with no done condition asks Claude to state one first; your messages drawn as P1 with the done conditionReason of Moon★ 2
- launch-codesDangerous Bash commands need launch codes: red alert pane, siren, a code to arm and a LAUNCH to fireOneWave AI★ 2
- mod5dive telemetry producer, seat panel, command surface and tool-call policy guard for Claude Code function hooks (early access). Publishes turn and session boundaries and the account's usage reading from inside the harness process to a per-…5dive★ 2
- osmReplaces a secret with a format-preserving fake before the model reads it, and restores the real credential on the way into a tool call. The map survives a resume or a reload; set persist off to keep it in memory only.pratikbin★ 2
- pdpa-thaiHelps reduce personal data sent to Claude: redacts detected Thai and international personal data before sending and masks it on screen. Detection runs locally and the mod makes no network calls of its own; the redacted conversation is stil…Boom-Vitt★ 2
- redactSecrets found by betterleaks reach the model as ‹secret:…› tokens; Write/Edit restore them, other tools refuse themStephan Schreiber★ 2
- redactorRedacts secrets from what the model reads and posts a digest.modmgr fixtures★ 2
- secret-maskMask token-like strings in tool output before they reach the conversationGary★ 2
- secrets-guardStops Claude reading .env and key files, masks API keys in command output, and lets you hand Claude a key through a pane without it ever seeing the valueCharlie Hills★ 2
- supabase-guardSupabase guard: stops Supabase calls aimed at a project other than the current folder's, and asks in a one-key popup before destructive SQL, branch resets or project pauses. /supaor toggles. Hungarian or English.Szota Szabolcs★ 2
-
agent-firewallA live pane of every tool call the agent makes: green when it ran, red when it was blocked, with counters. Open it with /firewall.Baselane★ 1
38 more in this repository
- audit-packThree read-only audit commands in one mod: /secret-scan, /conflicts and /licenses. They read git, project files and dependency folders. They copy results to the clipboard.Baselane★ 1
- beads-guardAsks before bd commands that delete data or rewrite history: delete, purge, prune, gc, sql, admin, import, rename, forget, restore, migrate and more. Reads only the command text, runs no bd.Baselane★ 1
- big-file-guardAsks before a Write creates content over 1 MB, or git add names a file over 5 MB. Measures the files with find.Baselane★ 1
- chmod-guardAsks before chmod makes files world-writable (777, a+w, o+w) or chmod or chown runs recursively on a broad path (/, a system folder, a home folder).Baselane★ 1
- ci-config-guardAsks before Write or Edit changes CI config: .github/workflows, .gitlab-ci.yml or .circleci/config.yml.Baselane★ 1
- cron-guardAsks before scheduled jobs or services are wiped or stopped: crontab -r, crontab replaced from stdin or a file, launchctl unload or bootout, systemctl stop, disable or mask.Baselane★ 1
- curl-pipe-guardAsks before a download is piped into a shell or interpreter (curl | sh, wget -O- | bash, bash <(curl ...)).Baselane★ 1
- db-reset-guardAsks before a framework wipes a database: prisma migrate reset, rails or rake db:drop and db:reset, alembic downgrade, django flush, supabase db reset, knex rollback --all.Baselane★ 1
- deploy-guardAsks before a production deploy: vercel --prod, netlify deploy --prod, firebase deploy, fly deploy, gcloud app deploy, eb deploy, heroku rollback, serverless deploy to prod.Baselane★ 1
- docker-guardAsks before Docker commands that delete data: system, volume or image prune, rm -f, volume rm and compose down -v.Baselane★ 1
- env-exfil-guardAsks before a command prints your environment, echoes a secret variable or sends local data to a remote host.Baselane★ 1
- git-history-guardAsks before git commands that throw away work or rewrite history: reset --hard, clean, rebase, filter-branch, filter-repo, push --delete, branch -D and stash clear.Baselane★ 1
- gitignore-checkAsks before git add or commit when secret-looking files are not ignored or are already tracked. Checks with git ls-files.Baselane★ 1
- guard-devopsAsks before harsh DevOps commands: destructive Docker, Kubernetes and Helm calls, CI config edits, broad chmod and chown, and git commands that lose work. Add infra-guard for plain kubectl delete.Baselane★ 1
- guard-essentialsAsks only before harsh or disaster commands: destructive infra, git and SQL, piping downloads into a shell, sudo, leaking or committing secrets. Reads git. The quiet choice for daily work.Baselane★ 1
- guard-packThe 15 core Baselane guards in one mod (secrets, git, infra, packages, path jail). Some read git, measure files with find, read HOME with printenv, or check where a path really lands.Baselane★ 1
- infra-guardAsks before terraform destroy, kubectl delete, force-push, DROP TABLE or rm -rf.Baselane★ 1
- k8s-guardAsks before kubectl apply or replace with --force, kubectl drain, helm uninstall, and kubectl delete behind global flags (plain kubectl delete is infra-guard's).Baselane★ 1
- lockfile-guardAsks before a lockfile is written or edited by hand; the package manager should change it.Baselane★ 1
- migration-guardAsks before Write or Edit changes a migration that already exists; new migration files pass.Baselane★ 1
- no-verify-guardAsks before git hooks are skipped (--no-verify, commit -n, HUSKY=0, core.hooksPath=/dev/null).Baselane★ 1
- package-guardAsks before a new dependency is installed (npm, pnpm, yarn, bun, pip, uv, poetry, cargo, go, gem) and names the packages.Baselane★ 1
- prod-db-guardAsks before destructive SQL runs in a command: TRUNCATE, DELETE or UPDATE with no WHERE.Baselane★ 1
- protect-mainAsks before a commit, push or merge while you are on main or master. Reads the branch with git.Baselane★ 1
- publish-guardAsks before a package is published: npm, pnpm, yarn or bun publish, cargo publish, twine upload, gem push, poetry or uv publish. Dry runs pass.Baselane★ 1
- registry-push-guardAsks before an image or chart is pushed to a registry: docker push, docker buildx --push, podman push, helm push, gcloud artifacts docker push. Local registries pass.Baselane★ 1
- secret-commit-guardAsks before a git commit that would record a credential or a secret-named file. Reads the staged diff with git.Baselane★ 1
- secret-filename-guardAsks before a Bash command touches a secret-looking file (.env, private keys, credentials).Baselane★ 1
- secret-guardAsks before a live API key, token or private key is written, edited or run.Baselane★ 1
- secret-output-guardTells Claude not to repeat a credential that showed up in command or file output, and names the source to rotate.Baselane★ 1
- secret-scanAdds /secret-scan: tracked files and line numbers that hold secret-shaped text, found with git grep. Never prints a matched value. Read-only. Copies the result to your clipboard.Baselane★ 1
- security-modeChecks each change for injection, secrets, authorization and unsafe input, and states the risks it checked.Baselane★ 1
- ship-safe-packThe release-pack guards plus db-reset-guard and upload-guard: asks before publish, tag push, production deploy, registry push, database wipes and file uploads. Reads tags with git.Baselane★ 1
- ssh-guardAsks before a private key in .ssh is read, authorized_keys or the SSH config is changed, or ssh-keygen would overwrite a key. Public keys and ssh -i pass. Reads HOME with printenv.Baselane★ 1
- sudo-guardAsks before sudo, doas or su -c runs a command with elevated rights.Baselane★ 1
- tag-guardAsks before release tags go to a remote: git push --tags, --follow-tags or --mirror, a push of a tag ref, and a push that deletes a remote tag. Dry runs pass. Reads tags with git.Baselane★ 1
- team-packTeam habits in one install: Conventional Commits, test-first work and a security check on every change.Baselane★ 1
- upload-guardAsks before local files go to a remote host: scp or rsync to host:path, piped input to nc, curl -T, sftp put. Local copies, downloads and localhost pass.Baselane★ 1
- are-you-sure-broMod: confirms only dangerous Bash commands (data loss, irreversible) and writes to sensitive files; optional strictness and noisy-output capDaniel Riddell★ 1
- barmkin-modClaude Code mods security layer: secret redaction, untrusted-content taint with a Rule-of-Two egress gate, skill inline-shell mediation guard, MCP tool-poisoning guard, skill-content screen, agent-to-agent firewall, and a Jev System One cl…samfrmr★ 1
-
bash-guardBlocks catastrophic shell commands (rm -rf ~, curl | sh, force-push to main, DROP DATABASE, format C:) and asks before risky ones (git reset --hard, rm -rf, terraform apply), in Bash and PowerShell.mako-code★ 1
10 more in this repository
- branch-guardKeeps work off protected branches: no commit, merge, rebase, cherry-pick, am or push on main/master/release/* (or an explicit push to one), with an optional auto-branch for commits.mako-code★ 1
- cache-guardAsks before /model, /output-style, /fast, /effort, MCP or plugin changes and /config rows that would throw away a warm prompt cache, with the cost of rewriting it; names the rebuilds it could not prevent.mako-code★ 1
- clobber-guardStops accidental truncation of real code: no "// ... rest of the code" placeholders over real code, and a question before a Write or Edit throws away most of a file.mako-code★ 1
- jev-seclintAn instant security reviewer on every code edit: ~20 yes/no checks per edit answered by Jev in a few hundred ms, fed back to Claude.mako-code★ 1
- jev-test-guardCatches tests being weakened to make them pass: every test-file edit is judged by Jev in a few hundred ms against what you asked for.mako-code★ 1
- path-guardProtected files and a project boundary: Claude can't edit .env, keys or .git, asks before touching lockfiles and migrations, and asks before writing outside the project.mako-code★ 1
- secret-shieldKeeps credentials out of your code, your shell commands and Claude's context: blocks hard-coded secrets in edits, asks before commands with literal keys, redacts secrets from tool results and flags them in prompts.mako-code★ 1
- watchdogRuns your dev server or watcher for the session, flags its errors above the prompt, and lets Claude read its output.mako-code★ 1
- explain-commandPlain English under every permission prompt: what the command does and how risky it is.mako-code★ 1
- readonly-mode"Look, don't touch": /readonly on blocks edits and every command that is not provably read-only, and tells Claude to investigate and explain instead.mako-code★ 1
- blast-guardHolds risky shell commands for a yes/no with a dry-run report, blocks Python heredocs carrying backslash escapes, and caps concurrent subagents at 4.satyamk4517★ 1
- blast-radius-koAnthropic의 blast-radius 샘플을 한글화하고 위험 명령 목록을 넓힌 k-mods 수정판. rm -rf, git reset --hard, force push, prisma/psql/docker의 파괴적인 명령을 멈추고 영향 범위를 먼저 보여줍니다.SeongGwangJu★ 1
- block-force-pushA starter mod: refuses a Bash call that force pushes with git, and passes every other tool call through.joeVenner★ 1
- blocked-runWhen auto mode blocks a command, shows it above the prompt with a button to run it yourselfDamian★ 1
- bouncerBouncer for Claude Code: enforce condition-based markdown guardrail rules on tool calls — deny or annotate any call whose content matches, instead of file-path-only rules.Frank Falor★ 1
- burnrateFull mod: live limits band above the prompt plus the guard (cache watchdog and limit brake).Talap-creator★ 1
- chronicleWrite and guard your project's history — craft commits (auto simple/atomic), author reviewer-legible PRs/MRs, cut config-first releases, and promote cockpit decisions into ADRs.Q★ 1
- cost-guardWatches session and daily spend, warns when the context grows large, and holds a prompt once when the prompt cache has expired on a big context.Santiago Fernandez★ 1
- effort-guardClaude Code mod: context/token band, escalation signals and per-turn effort log.Stefano Chieli★ 1
-
env-guardAsks you before Claude reads a .env or key file, and refuses when no one is there to answer.seanrobertwright★ 1
2 more in this repository
- feishu-notifyFeishu DMs via lark-cli when a long turn ends or Claude waits on a permission prompt or questionJenwein★ 1
- guard-widgetA tally of this session's permission checks: what was allowed, what you were asked about and what was denied.oMaN-Rod★ 1
- guardrails-mdGUARDRAILS.md gate: a System One decision model judges every Bash command before it runs — destructive / credentials / GUARDRAILS.md policyBerget AI★ 1
- guardsdotfiles のガード群 (git 操作のスキル強制・ブランチロック・コメント規約・文脈注入)。機能ごとに hooks/ 配下の 1 ファイルvoid2610★ 1
- lensPuts tsc, linter and secret-scan diagnostics in the result of every Edit and Write, so Claude fixes what it broke in the same turnPedro La Rosa★ 1
- p3c-guardAgent 写 Java 时,新增的阿里 Java 规约(p3c)违规落不了盘。Blocks Java writes that add Alibaba p3c violations.alexlifexyz★ 1
- prdeckPR feed, review pane and security checks above the promptVishal K Setti★ 1
- ratchetGuardrails, task board and spec-driven agent roles for Claude Code, enforced by hooks instead of prompts.ratchet contributors★ 1
-
rd-bandWatchdog test fixture, not a mod to install. release-delivery probe: two band cards on digit 2, a queued-prompt context, /rdprobe fork and notewatchdog live probe★ 1
18 more in this repository
- fcforkWatchdog test fixture, not a mod to install. first-check probe: a slow agent for the 30s summary fork, and register timing before session.startwatchdog live probe★ 1
- fcholdWatchdog test fixture, not a mod to install. first-check probe: hold the main Agent tool.call 8s and return context, or spin the hooks worker for the .catchwatchdog live probe★ 1
- fcreloadWatchdog test fixture, not a mod to install. first-check probe: what survives a userConfig reload ($.state, $.store, module variables, timers)watchdog live probe★ 1
- fcscopeWatchdog test fixture, not a mod to install. first-check probe: log the engine tool.check verdict and the response row fields, change nothingwatchdog live probe★ 1
- fcsubmitWatchdog test fixture, not a mod to install. first-check probe: own prompt.submit hook for a yielded, an unyielded and a clock submitwatchdog live probe★ 1
- rd-queueWatchdog test fixture, not a mod to install. release-delivery probe: hold one main turn.complete and time the next turn's hookswatchdog live probe★ 1
- rd-steerWatchdog test fixture, not a mod to install. release-delivery probe: append a wrapped note while the first reply streams, log each main step's usagewatchdog live probe★ 1
- rd-subWatchdog test fixture, not a mod to install. release-delivery probe: notes appended into a subagent during a tool call and after its answer, then a resumewatchdog live probe★ 1
- rd-uilogWatchdog test fixture, not a mod to install. release-delivery probe: $.ui.log rows of 5000 and 10000 characterswatchdog live probe★ 1
- rf-overflowWatchdog test fixture, not a mod to install. live probe: replaces a watchdog Read of overflow.txt with a payload past the context limitwatchdog live probe★ 1
- rfmodelWatchdog test fixture, not a mod to install. live probe: the model the engine runs for an agent registered with one aliaswatchdog live probe★ 1
- rrceilingWatchdog test fixture, not a mod to install. live probe: tool.check ceiling an org setswatchdog live probe★ 1
- rrdenyWatchdog test fixture, not a mod to install. live probe: --disallowedTools Agent and Taskwatchdog live probe★ 1
- rrpeerWatchdog test fixture, not a mod to install. live probe: a second plugin's spawn against the session-wide subagent capwatchdog live probe★ 1
- rrpermWatchdog test fixture, not a mod to install. live probe: parent permission mode and Edit versus Writewatchdog live probe★ 1
- rrspawnWatchdog test fixture, not a mod to install. live probe: spawn sites the spec leaves openwatchdog live probe★ 1
- rrstopWatchdog test fixture, not a mod to install. live probe: TaskStop results and the per-plugin spawn capwatchdog live probe★ 1
- wdprobeWatchdog test fixture, not a mod to install. live probe observer: logs the events it sees and changes nonewatchdog live probe★ 1
- redactRedacts secrets and PII from every row Claude Code stores, before the model reads it and before the transcript keeps it. Reach L0: no network, no processes, no files.Karan Bansal★ 1
- risky-holdHolds a risky shell command (rm -rf, reset --hard, force push, DROP, migrations) until you answer Run or Refuse. Fails closedtimoncool★ 1
- safety-netBlocks destructive tool calls before they run (force pushes, rm -rf outside the project, DROP TABLE, terraform destroy, writes to .env and keys, ...) and explains why.Troy Lorents★ 1
- scope-guardNotices when Claude drifts outside your request. Clear drift waits for your answer in a question dialog; milder drift is flagged above the prompt with a pull-back key.Atchyut★ 1
-
scope-guardCounts the distinct files a turn edits and stops at a threshold to make the goal get restated, so a small ask cannot quietly become a refactor.Yash Gadodia★ 1
2 more in this repository
- merge-gateDenies a Bash merge (gh pr merge, git merge on main, push onto main) unless the latest human message says the word merge; ship, push and deploy do not count.Yash Gadodia★ 1
- receiptKeeps a per-turn tally of edits, runs, curls and destructive commands and shows it on the turn footer; a claim with no run flags the spinner, a destructive Bash unfolds its tool group, and an edit-without-run turn suggests running the test…Yash Gadodia★ 1
- secret-guardA mod that redacts secret-shaped strings (GitHub, Anthropic, OpenAI, Google, AWS, Slack and Stripe keys, PEM private keys) to [redacted:<kind>] before they are kept in the conversation: in your prompt before it is sent, and in the model's …Seiya Kawamura★ 1
-
secret-guardBlocks Write, Edit and Bash calls that would put an API key, token or private key into a file or command.Malhar Ujawane★ 1
4 more in this repository
- branch-guardStops Claude from editing files or running mutating git commands on main or master, and points it at a worktree instead.Malhar Ujawane★ 1
- path-guardBlocks Write, Edit and MultiEdit calls that target a path outside the project root or inside .git, plus optional deny globs.Malhar Ujawane★ 1
- sensitive-file-guardBlocks Read, Write, Edit, Grep, Glob and Bash calls that touch .env files, private keys and credential stores.Malhar Ujawane★ 1
- test-guardBlocks edits that make tests pass by weakening them: new skip/only markers, fewer assertions, a gutted test file, or deleting a test file.Malhar Ujawane★ 1
- secret-guardKeeps secrets out of Claude's context: gitleaks scans every tool output, prompt and attachment before the model reads it, and you decide what the model sees.Legostin Vyacheslav★ 1
- secret-guardHides secrets in tool results before Claude reads them: the secret values of every .env and .env.* from your session's folder up to the drive root, and anything that looks like a secret (KEY=VALUE under a secret name, passwords in URLs, pr…Chien Vu Minh★ 1
- secret-maskMasks secrets (API keys, tokens, passwords, private keys) in the transcript; hover a masked value to reveal it.Fazzani★ 1
- secretsHand Claude an API token without it reading the value: you type it into a field above the prompt, Claude uses it in Bash as $NAME, and it is redacted from every tool result.crockalet★ 1
- ttsr-rulesoh-my-pi TTSR rules: a regex rule denies the tool call that would break it, with the rule as the reason; a question rule is judged after each turn.kzarzycki★ 1
- turn-receiptKeeps a per-turn tally of edits, runs, curls and destructive commands and shows it on the turn footer; any non-read-only Bash counts as a run, a claim (English or Japanese) with no run flags the spinner, a destructive Bash unfolds its tool…yoshihiko555★ 1
- vaultCredential vault for Claude Code: macOS Keychain secrets, per-directory grants, injected env, redacted output, pane with import/exportyocloud-code★ 1
- ad-ldapActive Directory administration over LDAPS for Claude Code: an MCP server (FastMCP + ldap3) with 15 tools, admin agents, slash commands, a safety skill, and a guard that refuses any AD write until the identical call has been dry-run first.…seanGSISG★ 0
- agent-guardGuard for dispatching subagents: denies isolation "worktree", checks a declared WORKTREE is a separate, clean, never-dispatched git worktree, and in opted-in repos requires non-read-only subagents to declare one.AbyssCN★ 0
- all-modsAll 4 workflow mods in one install: status-strip, next-steps, ship-it, usage-guard.Liberty-Technical-Solutions★ 0
- anchorwatch-modExperimental port of Anchorwatch's Bash deny rules to a Claude Code function hook (a 'mod'): a typed tool.call handler that refuses destructive rm/git/SQL/disk/permission commands, curl|sh, .env reads, and shell writes to secret files. Loa…Anchorwatch★ 0
- anime-cheerVoiced pixel anime girls who roam the Claude Code transcript: they dance while Claude works and serve tea when it is done, and they do chores too: usage reports, a guard on dangerous commands, secret scans, quick code reviews and task reca…a252937166★ 0
- approve-blockedRetries an auto-mode-blocked call up to three times so Claude Code's own permission prompt (and Moshi) can ask you.adammhal★ 0
- artifact-watchdogEnforces the subagent output contract: watches each Agent dispatch's artifact file, flags a 5-minute stall, wakes an idle Claude once per stall, offers a Stop buttonm2ai-portfolio★ 0
- ask-on-auto-denyWhen auto mode's classifier blocks a tool call, asks you above the prompt and lets you allow that exact call oncetylergraydev★ 0
- auth-guardSpots an expired CLI login in tool output and offers a Login button that signs in and retries.Dominick Giordano★ 0
- bash-explainExplains in Korean the shell command a permission dialog asks about: what it does, what it changes and how risky it isKKK12142★ 0
- benign-guardBlocks edits to .env filesthinx-pro★ 0
- blast-radiusHolds destructive shell commands, shows what they would delete or overwrite, and asks Proceed or Cancel.Alyan Khattak★ 0
- blast-radiusWhen a Bash command asks for permission, preview its blast radius: rm targets measured (files, size, what git can't restore), plus your own regex -> dry-run rules per command in a chain or pipe. A line under the dialog, details in a side p…nguyen.duy.vu★ 0
- blast-radiusFaengt gefaehrliche Shell-Befehle (Bash und PowerShell) ab, zeigt Befehl und Folge und fragt vor dem Ausfuehren nach; Standard aus, mit /ward fuer die Sitzung einschaltenDan Enso★ 0
- blast-radiusDry-runs risky Bash commands (recursive deletes, destructive git, kubectl delete, SQL wipes) and asks Proceed or Cancel first.cskwork★ 0
- blast-radiusShows how far each change can reach: the files that depend on every file Claude edits, and a flag on wide-reaching shell commands. Show only, never blocks.gauravruhela07★ 0
- blast-radiusCatches risky shell commands (rm -rf, git reset --hard, force push, ...) before they run, forces a permission prompt, and shows what they would touch in a side pane.harshitmywork17★ 0