ModsCode / Claude Code Mods / Ranking / Safety guards / Page 2 of 3
Safety guard mods
Mods that watch for risky actions: guards, denied commands, secrets and dangerous calls.
- ★413 mods in 253 repositories, ranked by stars
- Where it runs: the terminal, the desktop app, or both
- How far its code reaches, from drawing only to the network
Grouped by the words in each mod's name and description, not by reading its code. A mod can be in several groups; one that does not say what it is for is in none.
/
Mods run with your permissions. Check first.
The rest of the list did not load, so this search covers this page only.
Filters253 shown
Runs in:
Draws in:
Uses:
Reach:
Without:
Listed in:
- blast-radiusBefore a shell command deletes or discards files, shows exactly what it would hit and waits for Cancel or Proceed.JJ Englert★ 0
- blast-radiusHolds destructive Bash calls (rm -rf, git reset --hard, git clean, force push, migrations) and shows the files affected in a pane until you Proceed or Cancel.navin0812★ 0
-
blast-radiusBefore a risky Bash command runs, says what it will touch. A plain deletion is judged by git: files outside git or tracked and clean get only a short label, a Ukrainian dialog (with the rm line, the number of files and a typed 'Other' deci…noaod★ 0
3 more in this repository
- sandbox-guardDenies Edit/Write/Bash writes to Claude config paths the sandbox cannot write (settings, skills, plugins, hooks, projects, ...) and tells Claude to hand the user a ready Terminal command instead of trying workarounds.noaod★ 0
- secret-redactorMasks API keys, tokens, private keys and password assignments in tool results before the model sees them.noaod★ 0
- verification-guardChecks Claude's claims (tests pass, verified, fixed, no regression, API returns N) against the tool calls that actually ran. Unsupported claims get a visible warning; /evidence lists claims and the evidence behind each. Warns only, never b…noaod★ 0
- blast-radiusHält gefährliche Bash-Befehle an (rm -rf, git reset --hard, git clean, force-push …), zeigt was sie anrichten würden, und fragt vor dem Ausführenreifen01★ 0
- blast-radiusHolds risky Bash commands, shows what they would hit, and waits for Proceed or Cancel.Sönke★ 0
- blast-radiusHolds risky Bash commands, shows what they would change, and waits for Proceed or Cancel.qinyuanjie★ 0
- blast-radiusHolds risky Bash (migrations, force-push, DROP, hard reset, rm -rf, deleting .env) and shows a dry-run pane with Proceed / Cancel.mags★ 0
- blast-radius-plusHält riskante Shell-Befehle an (rm -rf, git reset --hard, Force-Push, Migrationen) und zeigt dir vorher, was sie ändern würden.Verselo Systems SL★ 0
- blast-shieldHolds risky shell commands (rm, git reset/clean/force-push, kubectl, terraform, docker, SQL and more), shows what they would change and whether you can undo it, and runs them only on your say-so.Oren Segal★ 0
- block-credsRedacts or blocks credentials (detected by betterleaks) before they are sent to the LLMskpersonal★ 0
-
branch-guardAsks the user before Edit/Write/NotebookEdit changes a file of a git repo whose current branch is main or master (once per repo and session)Vincent Lauriat★ 0
9 more in this repository
- commit-lintRefuses git commit commands whose message subject is not a Conventional Commit (type(scope)!: subject, header within a length limit)Vincent Lauriat★ 0
- commit-size-guardAsks before a git commit or git add includes large files, big binaries or build/release artifacts (dmg, zip, app, ipa, xcarchive, DerivedData, node_modules, .build, release/)Vincent Lauriat★ 0
- doc-sync-guardWarns above the prompt when a turn did not update COMMANDS.md, or changed code without updating CHANGES.mdVincent Lauriat★ 0
- env-protectAsks the user before Claude reads secret files (.env, private keys, .netrc, .npmrc, .aws/credentials, keychains…) with Read, Grep, Glob or BashVincent Lauriat★ 0
- french-guardToasts when the last answer looks English or is French written without accents; /french-guard off|on|statusVincent Lauriat★ 0
- main-guardRefuses git pushes to main/master, force pushes, tag creation and GitHub releases unless the person allows themVincent Lauriat★ 0
- rm-guardAsks the user before destructive Bash commands run: rm -rf, git reset --hard, git clean -f, discarding all changes, SQL DROP/TRUNCATE, find -delete, mkfs, dd onto a deviceVincent Lauriat★ 0
- secret-shieldRefuses Write, Edit and Bash calls that contain secret-looking values (API keys, tokens, private keys)Vincent Lauriat★ 0
- sparkle-guardProtects the Sparkle EdDSA signing key: denies deleting it from the keychain, asks before generate_keys may create or import a key and before an edit changes an existing SUPublicEDKeyVincent Lauriat★ 0
- browser-guardStops Chrome actions when the Chrome profile is not the one paired with the active cswap accountAbhinav Bansal★ 0
- burn-guardGuards the 5h usage window: caps expensive-tier spawns per turn, keeps Fable spawns manual-only, draws a colour-coded usage gauge above the prompt (5h bar, reset time, turn burn, cache warmth, context size), and offers handoff + clear past…Oguz Oral★ 0
- cache-guardKeeps the prompt cache warm while you are away, asks before a prompt that would re-cache a large conversation, and with Jev (TypeSafe) keeps the context lean: trims large tool output and compacts in about a second.Spencer Boucher★ 0
- claw-guardClaw mod: asks for your OK before any connector action that sends, deletes, pays, publishes or shares (fails closed, also when nobody is there to answer), and flags prompt-injection text inside emails, pages and files.threesil★ 0
- cm-block-dangerous-commandsRefuses destructive Bash commands (rm -rf /, force-push to main, DROP TABLE, curl | sh, ...) before Claude runs them, and tells Claude why.ClaudeMods★ 0
- cmd-guardBlocks destructive shell commands (rm -rf /, force push, DROP TABLE...)redjackfred★ 0
- cockpitA one-line band above the prompt and a roomy Cockpit panel (prompt-cache countdown, context, plan limits, cost, next tasks, shortcuts), plus guards: no Claude credit lines in shell commands, pasted API keys held back, impeccable nudge on U…cGradying★ 0
- code-buddyA rubber duck in your Claude Code session: a quiet second opinion on each turn, a guard for risky commands, reminders, and lessons about your codebaseAether Technical★ 0
- cold-cache-guardAsks what to do before Claude Code re-sends a large conversation whose prompt cache has expired: on a cold resume, and on the first prompt after an idle spell.Mediavee★ 0
- collision-guardWarns when another Claude session on the same repo already edited the file being changed, or claimed the same package version.eshin087★ 0
- command-guardRefuses shell commands a project's .claude/command-guards.json rules out, for the main loop and every subagentIain Partington★ 0
- commit-guardNever commits docs/superpowers, never pushes unless you said push, asks before committing on main/staging/prodirfanfaraaz★ 0
- context-guardContext window fill in the status line, with a heads-up before it runs outanthonyhungnguyen★ 0
- context-guardContext runway gauge: warns before your context line with Compact, Hand off and SnoozeGalih Citta★ 0
- context-saverRefuses a main-agent Read over the token cap so a subagent reads the file and reports back. Reads its toggle and settings from agent-rules.MahadSalim★ 0
- cortex-guardTwo rules no settings hook enforces, refused at the tool call: wiki pages and their generated ADR mirrors are written only through the Cortex wiki tool, and every git worktree lives at <repo>/.claude/worktrees/<name>/ (one created there is…cdeust★ 0
- council-of-elrondA council of specialist reviewers that gates risky tool calls before they run. Rules decide the tier; model members give a second opinion; anything uncertain comes to you.Deluhathol★ 0
-
danger-checkAsks you before a command that can destroy work, such as rm -rf, git reset --hard or git push --force.Anand Chapla★ 0
1 more in this repository
- dbx-traceFlight recorder for Databricks: every query, script and guardrail block Claude makes, in a band above the prompt and a per-session HTML trace with deep linksMatt Romano★ 0
- delete-guardA pane that lists the files a delete command would remove, with a keep/delete toggle per file and Confirm or Refuse buttons.EmanueleNene★ 0
- delete-guardDeleting outside the project folder requires the user's approval (Bash, PowerShell, cmd, subagents, MCP).systemNEO★ 0
- dev-guardBlocks catastrophic commands, asks before risky ones, and stops secrets from being written into filesnata★ 0
- dev-hooksPolyglot dev-workflow hooks for Claude Code: auto-lint on edit, verify tests/linters before stopping, a PreToolUse dangerous-command guard (catastrophic commands, plus an ask before a secret value would be printed into the transcript — cat…Mick Zijdel★ 0
- done-chimeChimes when a long turn finishes and when a permission prompt is waiting; /chime to toggleJump-High-Kid★ 0
- dot-guardBlock `git add` of a whole $HOME work-tree (dot add -A/./*), which would stage your entire home directory.theagitist★ 0
- driver-seat-guardLearn mode: one-step pacing, no unasked web search, no work on todos you haven't reachedIan Wilson★ 0
- effort-gateDenies a subagent or background session running Opus at xhigh or max effort unless the user said soBerkay Orhan★ 0
- env-guardClaude Code mod: blocks Claude from reading .env secret files and counts blocked attempts in the status lineABDUAZIZX★ 0
- eol-guardKeeps files' git line endings (CRLF/LF) after Claude's edits and shell commands, and stops prettier checks failing on a CRLF checkout.Tihomir Selak★ 0
- explain-permissionExplains each Claude Code permission request in plain English (WHAT, WHY, RISK) in a side paneHermann Peterscheck★ 0
- fast-laya-compactionVerbatim Laya-guided compaction for Claude Code sessions (local, no API key).kartikeyaagr★ 0
- file-guardDeny writes to protected files (.env/secrets/keys) and dangerous Bash patterns, with a toast explaining whyweave★ 0
- freigabeBlockiert Aktionen mit Außenwirkung und gibt nichts frei; fängt Regel-Fallen ab, schwärzt Secrets in Tool-Ausgaben, erinnert an liegengebliebene Mail-Entwürfe.Kanevry★ 0
- freio-de-maoFreio de mão: antes de um comando que apaga ou descarta (rm -rf, git reset --hard, git clean, push --force, pkill -f...), mede o estrago sem apagar e pergunta: prosseguir, lixeira, backup ou cancelar (/freio)INEMA★ 0
- gcloud-guardHolds gcloud and gsutil commands that would create, change or delete cloud resources, shows the account, project, location and the current state of the targets, and asks you to Proceed or Cancel.davidho27941★ 0
- gcp-reauthFlags expired Google Cloud credentials (invalid_rapt) with the login command to runMichel Radosavljevic★ 0
- ghost-proc-guardStops Claude from starting a second copy of your dev servers on the next free port (monorepos and worktrees included), tracks the servers it starts, and stops leftovers from a /procs pane.Thieu Nguyen★ 0
- grammar-guardGrammar fixes for prompts you type or dictate: optional auto-fix on send (LanguageTool rules or a light Haiku fix), Haiku drafts that know your project's terms, and word tools (your language to English, synonyms).Ev3nt1ne★ 0
- gsd-whisperShows you what gsd-core's hooks quietly tell the agent: context warnings, guard advice and guard denials.Dave Sienkowski★ 0
- guardPauses risky shell commands (rm -rf, force push, DROP TABLE) and asks you Proceed or Cancel firstCarl Vellotti★ 0
-
guardreads every Bash call and fork spawn before it runs: a floor command, a known hazard shape or a fork with no why-fork line is refused with its safe door, never a dialog; each refusal and escape shows in stash's band as a 🛡️ linedvakatsiienko★ 0
3 more in this repository
- redactkeeps secrets out of every transcript: api keys, tokens and private keys read as a stable placeholder in every kept row, and come back only inside the tool call that names themdvakatsiienko★ 0
- x-mod-guardreads every Bash call, fork spawn and Write before it runs: a Write over a tracked file the session never read, a floor command, a system, overwrite, prune or remote-delete command, a known hazard shape, a coder spawn whose brief has no x …dvakatsiienko★ 0
- x-mod-redactkeeps secrets out of every transcript: api keys, tokens and private keys read as a stable placeholder in every kept row, and come back only inside the tool call that names themdvakatsiienko★ 0
- guardBlocks risky shell commands (phone deletes, printing secrets, self-killing pkill) and strips secrets pasted into messagessoyakaai-studio★ 0
-
guardBlocks destructive shell commands and access to secret files before they run, anywhere in a compound commandStanislav Kozachenko★ 0
2 more in this repository
- redactKeeps secrets that tools print (keys, tokens, passwords, private keys) out of what the model reads and the next request sendsStanislav Kozachenko★ 0
- notifyNotifications that say what happened: a long turn finished (with its answer), a permission prompt or a question waiting, an Actions budget running low; on the desktop and, through Claude Code push, on your phoneStanislav Kozachenko★ 0
-
guardHolds shell commands that delete folders or overwrite workVuk Rosic★ 0
1 more in this repository
- guardclawGuardClaw guard for Claude Code: runs every shell command the model asks for through the GuardClaw Go engine (guardclaw-scan) and denies what it flags, protects credential and settings files from the file tools, and refuses other mods that…TakeInterest Inc.★ 0
- guardrailsA lint gate for Claude's edits: your project's rules, a baseline of existing violations, and a PreToolUse check that refuses only edits adding new ones.Azoof Ahmed★ 0
- guardrailsStops pushes, PRs and raw commits you did not ask for, steers Bash to the right tools, and runs each project's own formatter on the file Claude just edited.Chris Mellor★ 0
- guardrailsStops risky shell commands before they run: killing ports owned by Docker containers, printing secrets from the environment, rewriting your kubeconfig, and asks before kubectl writes on production contexts.Lucas Leandro★ 0
- guardrailsBlocks the Bash commands your own rules file names, and shows every block in /blocked. Ships no rules.Stoica-Mihai★ 0
- hajibHajib: a doorman that stops dangerous commands and asks for approval in Moroccan DarijaMohamed Ballouch★ 0
- harnessSkills and guard hooks: ai-code-cleanup, interrogate, shape-task, verify-change, setup, a shared-worktree git guard, and a guard against reading API-key config filesParadox07127★ 0
- harness-guardShadow or enforce the existing Harness PreToolUse guards as function hooksmyaji35★ 0
- heavy-waitguard-heavy-commands の hook が CPU の厳しさで止めた重い処理を、空くまで測り続け、空いたらセッションに知らせるmiyabi-satoh★ 0
-
hello-guard起動を記録し、rm -rf / を含む Bash を拒否する。関数フック(early access)が必要hide-sora★ 0
2 more in this repository
- intent-guardSends risky-looking Bash commands to an LLM judge and denies the ones it reads as destructive; regex only decides what is worth judging. Fails closed. Needs function hooks (early access).hide-sora★ 0
- secret-scrubMasks API keys, AWS/GitHub/Slack tokens, PEM private keys and Bearer values in Read, Grep and Bash results before the model reads them. Needs function hooks (early access).hide-sora★ 0
- house-rulesTurn CLAUDE.md rules into hard blocks: protected paths, no new report files, banned commands, and rules re-pinned every N prompts and after compaction.Daniil Bystrov★ 0
- hy-guardRoutes company MCP tools through a security gateway. Every request is signed with a device-bound key (DPoP); policy decides which tools the model can see.HackYeah team★ 0
- identity-guardStops commits and pushes under the wrong git identity (the work email) before they reach GitHub, and says exactly how to fix it.none-ascetic★ 0
- impact-radiusHolds risky shell commands (recursive deletes, git reset --hard, git clean, force pushes, discarded changes, migrations and third-party installs for the whole user or system), shows what they would change and waits for you to press Run or …pablodiazjorge★ 0
- jev-screenScreen fetched web content with Jev and warn the model about prompt injectionmanifoldfrs★ 0
-
kb-settings-guardDenies a delegated agent lane any write to this repo's Claude settings files.knowledge-base★ 0
1 more in this repository
- leak-guardRefuses a git commit that carries a value you listed as private.Rostech★ 0
- leakstopStops secrets from leaking before they are written, printed or committed to git.AlexandreMartinezOlmos★ 0
- linear-gateHolds every Linear write until you allow it.CJ★ 0
- lint-guardAn ordinary eslint wrapper: lints after every Write/Edit, a /lint command, and a band showing current findings.interop-probe★ 0
- lixeiraTroca o apagar de vez pela lixeira do sistema e barra comandos sem volta (git reset --hard, push --force, formatar) até o sim do usuárioMarcelo Diego★ 0
- low3dgs-guardChặn chạy thí nghiệm khi cây làm việc bẩn hoặc GPU đang bận, và hiện trạng thái dự án Low-3DGS trên một dòng.BuiTienDunghe★ 0
- lsp-firstLSP-first guards: refuses shell greps on code symbols and shell writes to source files, retries cclsp's cold start, folds the refusals to one linedjavrell★ 0
- main-guardA red band when you are on main or in prod, and no force-push, reset --hard or unconfirmed push to a protected branchShrithan Devaiah★ 0
- marcoshackPersonal collection of Claude Code skills: commit, code-review, security-scan, implement, dep-triage, okf-init, analyse-external-repo (with the read-only external-repo-analyst agent), plus a usage overlay showing plan usage, context and co…Marcos Hack★ 0
- mask-that-passMasks credentials in tool output (URL passwords, *_TOKEN / *_SECRET / *_PASSWORD values, API keys, bearer tokens, private keys) before Claude or the transcript sees them. No network, files or processes.Mask That Pass contributors★ 0
- masque-secretsMasks the values from ~/.claude/secrets/*.env in everything the model readstibzejoker★ 0
- memory-guardsRefuses the footgun commands Claude's memory notes warn about, with the reason and the safe alternativeTuncer Deniz★ 0
- memory-holeA list you were handed is a file, not a memory: a prompt with a list blocks edits until the list is written to a plan or scratchpad file.arazvan★ 0
- migration-guardMakes Claude ask before it touches your database migrations or runs destructive SQL, with the risk and what it found.Balen★ 0
- minecraftPlayable first-person voxel sandbox inside Claude Code. Mine, build, explore, and save your world.Adam Holter★ 0
- modwallA firewall for other mods: shows what each mod can reach as it loads, and audits, holds or refuses it by your policyRadTech★ 0
- native-guardRecusa edição de arquivo por sed -i / heredoc / python no shell e manda usar Edit e Writebps2414★ 0
- parallel-pacerWatches this PC's CPU, free memory and parallel chats, holds heavy commands back to one at a time when it is choked, and shows how many more chats fit. English and Japanesenakadadev★ 0
-
pii-mask個資去識別化:把手機、身分證、Email、地址等換成代號再送給模型,對照表只留在本機;/pii 開關與查看Ting Jia★ 0
1 more in this repository
- pii-shieldReplace protected people's names, Taiwan ID numbers, phone numbers and emails with placeholders before the model reads them.Jiang Yu-de★ 0
- pii-shieldMasks emails, names, account numbers and secrets on screen while you screen-record. Display only: the model and the transcript keep the real values.mrjk05★ 0
- pipe-guardAdds pipefail when Claude pipes a check (lint, typecheck, tests, git merge) into tail, so a failed check cannot read as a passMokaair★ 0
- pkexec-guardRoutes `sudo` in Bash calls to a password prompt the person can answer: pkexec on a Linux desktop, an osascript administrator dialog on macOS, and Windows sudo's UAC prompt on Windows.Josh Kerr★ 0
- pkg-guardHold npm, pnpm, yarn, pip, uv, and cargo installs of packages that don't exist, are brand new, or are barely downloaded, with the registry facts in the question. Catches hallucinated and typosquat packages before they land.Mohammed Mubarak★ 0
- plusAll claudecode-plus-mod Mods in one install: prompt-shield, cache-guard, human-tone, clear-intent and agent-charter.claudecode-plus-mod★ 0
- pm-guardSteers npm/npx/yarn to the package manager the repo's lockfile names (bun or pnpm), bun where there is nonenarrowstacks★ 0
- privacy-gatewayPII and secrets are swapped for placeholders (__PII_PERSON_1__) by regex and a local Gemma 4 before anything reaches Claude; placeholders are restored only where the work stays on this machine (local tool calls) and on screen.Kei Nakayama★ 0
- prose-guardBlocks em dashes in edits, shell commands and replies, and British spellings in prose files, commit messages and pull requests.cprentice9★ 0
- protect-env-filesSample mod: denies edits to .env filesConnor Prussin★ 0
- protocol-guardRequired workflow checks with Claude Code function hooks. Refuses a knowledge-file write, or a memory-service save in external memory mode, until knowledge-save is open, refuses hand edits to generated indexes, refuses a pull request, clos…Mike Rihm★ 0
- publish-approvalAsks the user in a dialog before a push, deploy or publish the publish guard gates, in every permission mode.Sarb0Z★ 0
- publish-guardStops Claude from typing private terms into the browser or writing them into your publishing files, and keeps a log of what it blockedBuild Alone★ 0
- push-guardBlocks git push and gh pr create until you confirm the commits, their authors and the diff size, with a side pane of the last checkkk5190★ 0
- query-guardAsks before Claude runs destructive or slow-looking SQL through a DB CLI: DELETE, UPDATE without WHERE, DROP, TRUNCATE, full scans and cartesian joins.nu0ma★ 0
- redactRewrites sensitive data (emails, IPs, credentials, addresses) out of what enters the model contextJinhaoFang★ 0
- repo-guardBlocks destructive git commands and asks before Claude first edits a repo other than the session's ownYuehengHan★ 0
- roclaudeRoblox Studio safety layer for Claude Code (Studio MCP): RemoteEvent security audit, undo, Team Create protection, a confirmation before destructive Luau, and a live activity view that replays every change.vink★ 0
- safety-guardBlocks destructive shell commands and access to secret files (.env, SSH keys, cloud credentials).Pradeep Kumar Balakrishnan★ 0
- safety-netBlocks dangerous shell commands (rm -rf, force push, hard reset, DROP TABLE)Coding Tips★ 0
- sandbox-tunerExplains each Claude Code sandbox block in plain words and turns recurring blocks into reviewed, one-press, undoable edits of your user settings.dot-agi★ 0
- seatbeltBlocks destructive shell commands and edits to secrets before they runNafees S★ 0
- secchain-maskHides SecChain's secret values in prompts, tool results and instructions before the model reads them, through secchain mask.bannzai★ 0
- secret-brokerPops up when Claude needs an API key or token for a terminal command and injects it without Claude ever seeing itcesarroger★ 0
- secret-guardKeeps API keys, tokens and passwords out of the transcript, tool output, files, commits, PRs and issues.hagaybar★ 0
- secret-guardBlocks reads of .env files and printing of API keys, with a red warning above the prompt.Saurav Verma★ 0
- secret-maskMasks secrets (API keys, tokens, passwords, .env values) in tool output and prompts before Claude reads themmashabek★ 0
- secret-maskコマンドの結果や読んだファイルに混じったAPIキー・パスワードを、Claudeが読む前に伏せるshoujiki-panman★ 0
- secret-sentryTwo-way secret scrubbing: redacts credentials before the model sees them and blocks writing them into tracked files or shell commandsChris Dwyer★ 0
- secret-shieldMasks API keys, tokens, passwords, private keys, and database URL passwords in tool output, prompts, and attached files before Claude reads them. /shield lists where it masked what (never values) and opens by itself when a secret turns up …Justin Hsu★ 0