airlock
Routes supported project edits into a Git worktree for review, accept or reject. Worktree routing is not a filesystem sandbox.
What it does
- Draws a pane, the status line, toasts
- Adds /airlock-status, /airlock-diff, /airlock-accept, /airlock-reject
- Watches Read, Edit, Write, NotebookEdit calls and can refuse them
- Hooks prompt.section, session.start, turn.complete, turn.start
- Keeps its own state between turns
Good points
- No network calls
- Written in TypeScript
- Handles errors
Code to start from
Two kinds: a starter modscode writes from the design above, and the lines of the mod's own code that draw it.
Starter (register.tsx)
import type { Register } from 'claude-code'
// Drawn like airlock by billymrx (pane, status, toast), as modscode read it from the mod's code:
// https://modscode.com/gallery/billymrx1-airlock/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the pane: open it with $.ui.open({ id: 'my-pane', title: "Airlock review" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box, Text, Code, Button } = $.ui.resolve(e)
const txRoot = '…'
const length = '…'
const files = '…'
const length2 = '…'
const skipped = '…'
const length3 = '…'
const length4 = '…'
const text = '…'
return (
<Box flexDirection="column">
<Text>
{"Transaction "}
(unknown)
{" · "}
REVIEW
</Text>
<Text dimColor>
{"Repository: "}
</Text>
<Text dimColor>
{"Worktree: "}
{txRoot}
</Text>
<Text>
{"Changes: "}
{length}
{" file(s), +"}
0
/-
0
</Text>
<Text>
{"Files: "}
{files}
{` and ${length} more`}
</Text>
<Text dimColor>
{"Untracked files included in baseline: "}
{length2}
</Text>
<Text dimColor>
{"Skipped files: "}
{skipped}
</Text>
<Text dimColor>
{"Side-effect events: "}
{length3}
{" ("}
{length4}
{" denied). Effects already performed outside the workspace cannot be rolled back by reject."}
</Text>
<Text dimColor>
Checks: Airlock does not run your project test suite. Accept checks concurrent edits and patch fit before applying. Rej…
</Text>
<Text>
APPLY_FAILED: this transaction may be partially applied. Preserve the workspace and backup for manual recovery; Accept …
</Text>
<Box flexDirection="column">
<Text dimColor>
Pane preview is capped at 10,000 characters; the diff may be incomplete.
</Text>
<Code source={`${text}`} />
</Box>
<Box flexDirection="row">
<Button label="Review" hotkey="v" />
<Button label="Accept" hotkey="a" variant="primary" />
<Button label="Reject" hotkey="r" variant="secondary" />
</Box>
</Box>
)
})
on('session.start', async ($, e, next) => {
const transactionId = '…'
await $.ui.status(`airlock: transaction ${transactionId} is open in another session — mutations blocked here`)
await $.ui.toast(`This review pane is stale. Open the current transaction review before acting.`)
await $.ui.toast(`Airlock review is ready; use /airlock-review to open the pane, or /airlock-diff.`)
return next(e)
})
}
The mod's own code
Shown under the mod's licence (MIT); its text is below. Keep the notice if you copy these lines.
hooks/register.ts lines 24–24 · Pane
on('ui.render', { component: 'Pane', requestId: REVIEW_PANE }, onReviewRender)hooks/tx/commands.tsx lines 717–776 · Pane
export async function onReviewRender($: any, e: any): Promise<unknown> {
const { Box, Text, Button, Code } = $.ui.resolve(e)
const tx = await storedTransaction($)
if (!tx) return <Box flexDirection="column"><Text>Airlock has no open transaction for this repository.</Text></Box>
const stats = tx.stats ?? {}
const files = Array.isArray(tx.changedFiles) ? tx.changedFiles : []
const skipped = Array.isArray(tx.skippedFiles) ? tx.skippedFiles : []
const untracked = Array.isArray(tx.untrackedCopied) ? tx.untrackedCopied : []
const effects = Array.isArray(tx.sideEffectEvents) ? tx.sideEffectEvents : []
const savedDiff = await $.store.get(diffKey(ctx.repoRoot)) as { transactionId?: string; text?: string; truncated?: boolean } | undefined
const currentDiff = savedDiff?.transactionId === tx.transactionId ? savedDiff : undefined
return (
<Box flexDirection="column">
<Text>Transaction {tx.transactionId ?? '(unknown)'} · {tx.state ?? 'REVIEW'}</Text>
<Text dimColor>Repository: {tx.repoRoot ?? ctx.repoRoot}</Text>
<Text dimColor>Worktree: {tx.txRoot}</Text>
<Text>Changes: {stats.files ?? files.length} file(s), +{stats.insertions ?? 0}/-{stats.deletions ?? 0}</Text>
{files.length > 0 && <Text>Files: {files.slice(0, 8).join(', ')}{files.length > 8 ? ` and ${files.length - 8} more` : ''}</Text>}
{untracked.length > 0 && <Text dimColor>Untracked files included in baseline: {untracked.length}</Text>}
{skipped.length > 0 && <Text dimColor>Skipped files: {skipped.join(', ')}</Text>}
{effects.length > 0 && <Text dimColor>Side-effect events: {effects.length} ({effects.filter(x => x.action === 'denied').length} denied). Effects already performed outside the workspace cannot be rolled back by reject.</Text>}
<Text dimColor>Checks: Airlock does not run your project test suite. Accept checks concurrent edits and patch fit before applying. Reject discards this worktree.</Text>
{tx.state === 'APPLY_FAILED' && <Text>APPLY_FAILED: this transaction may be partially applied. Preserve the workspace and backup for manual recovery; Accept cannot retry this apply.</Text>}
{typeof currentDiff?.text === 'string' && currentDiff.text !== '' && (currentDiff.truncated
? <Box flexDirection="column"><Text dimColor>Pane preview is capped at 10,000 characters; the diff may be incomplete.</Text><Code source={currentDiff.text} /></Box>
: <Code source={currentDiff.text} format="diff" />)}
<Box flexDirection="row">
<Button key="review-diff" label="Review" hotkey="v" onPress={async () => {
if (!(await isCurrentReview($, tx.transactionId ?? ''))) return
const patch = await $.process.run(['git', 'diff', tx.baselineCommit ?? tx.baseHead ?? 'HEAD', '--binary'], { cwd: tx.txRoot })
const latest = await storedTransaction($)
if (latest?.transactionId !== tx.transactionId) return
const text = patch.exitCode === 0 ? patch.stdout : `Could not read the transaction diff (exit code ${patch.exitCode ?? 'unknown'}).`
await $.store.set(diffKey(ctx.repoRoot), {
transactionId: tx.transactionId,
text: text.slice(0, 10000),
truncated: patch.isStdoutTruncated || text.length > 10000,
})
$.ui.invalidate('ui.render')
}} />
<Button key="accept" label="Accept" hotkey="a" variant="primary" onPress={async e => {
if (!(await isCurrentReview($, tx.transactionId ?? ''))) return
const result: any = await onTxAccept($, {})
$.ui.toast(result?.text?.split('\n')[0] ?? 'Airlock accept finished.', { timeoutMs: 6000 })
if (await $.store.get(activeKey(ctx.repoRoot)) === undefined) await $.ui.close({ id: REVIEW_PANE })
else $.ui.invalidate('ui.render')
}} />
<Button key="reject" label="Reject" hotkey="r" variant="secondary" onPress={async e => {
if (!(await isCurrentReview($, tx.transactionId ?? ''))) return
const result: any = await onTxReject($, {})
$.ui.toast(result?.text?.split('\n')[0] ?? 'Airlock reject finished.', { timeoutMs: 6000 })
if (await $.store.get(activeKey(ctx.repoRoot)) === undefined) await $.ui.close({ id: REVIEW_PANE })
else $.ui.invalidate('ui.render')
}} />
</Box>
</Box>
)
}Licence text (MIT)
MIT License Copyright (c) 2026 billymrx Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
What its code calls
runs programswrites filesenv varstool callsremembers
The design, read from code
ReviewDrawn from the mod's source at the commit read, not from a run: a list is drawn three times, a condition takes its first branch that draws in the desktop app, and a value only the run time knows is shown as a made-up sample (dotted underline) or left out. Colours and type are this site's.
What its code shows
Read from the source at commit 0c7e681c9253 on 2026-10-06. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.
| Decides the listing: code you can check | |
|---|---|
| Entry read | Every module hooks/hooks.json names was read.hooks/register.ts |
| Parses | Every file parses as TypeScript or JavaScript.14 files parsed |
| All its code is in the mod | Every import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod |
| Readable | No minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs |
| Calls in the open | Network and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open |
| For you to weigh before installing | |
| Where it draws | The terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both |
| Install line | Whether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.listed in its repository's .claude-plugin/marketplace.json: installs from there |
| Programs on Windows | Whether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).hooks/tx/commands.tsx:193 mkdir (not on Windows); hooks/tx/commands.tsx:216 mkdir (not on Windows); hooks/tx/commands.tsx:219 cp (not on Windows); hooks/tx/commands.tsx:237 cp (not on Windows); hooks/tx/commands.tsx:254 rm (not on Windows) |
| Network | Whether every fetch names its https host in the code.no network |
| Programs | Whether every program it starts is named in the code and is not a shell, an interpreter or a network tool.hooks/tools/bash.ts:114 bash (a shell or interpreter) |
| Reads and sends | Whether it both reads files or environment variables and reaches the network.reads environment variables and files and reaches the network |
| Keys in the source | Whether the source holds what looks like an API key or a private key.no keys in the source |
| Licence | An open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets modscode show its code; otherwise the code is linked.MIT |
This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen
Install it
Check it yourself before you install it. Mods run unsandboxed, with your permissions, and modscode does not vouch for what this code does. Read the code below (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.
Its repository is its marketplace. Add that marketplace (in the terminal with these commands, or in the desktop app's plugin settings) and install the mod from it:
/plugin marketplace add BillyMRX1/airlock/plugin install airlock@airlock-marketplaceThis installs the marketplace's latest commit, which may not be the one read here (0c7e681c9253). Compare them before you install.
Ask Claude about it
With the modscode connector added, Claude can read this design, what its code reaches and its code, and build on them. Ask it like this:
Read the modscode design "billymrx1-airlock" with its code and make me a pane like itSearch them from Claude: the MCP connector
Similar designs
-
Ask Claude…AttemptsPlain3 attempts from src/ · nothing is applied until you press AdoptDiff of StealthHide+ src/app.ts
Footer label+ src/app.tsFooter label+ src/app.tsClassic more files not shown: open the worktree to see them.Footer labelClose x -
Ask Claude…CIcross Bash · Classicmain · a1b2c3d · failed at 14:32Open the run on GitHubFix it fClose x
(no log available)
-
Ask Claude…Gitbranch main · Pinned notice · 0, 0 untracked, 0 staged× git failed► Hint lineRefresh rStage all aCommit Ghost cClose xWorking tree clean.Fix loginMonoGenerate gCommitTop rowHint linesrc/app.tsbinDiffStageUnstageRevertTop rowHint linesrc/app.tsbinDiffStageUnstageRevertTop rowHint line… 3 moresrc/app.tsbinDiffStageUnstageRevertsrc/app.tsClosebuild (cut to fit)
Plainbuild (cut to fit)Plainbuild (cut to fit)MinimalMinimalMinimalPlain -
Ask Claude…Night shiftNight shiftEach task ran in its own worktree and branch; nothing is in your checkout until you press Adopt.Diff of Fix loginHide diff+ src/app.ts
Edit+ src/app.tsEdit+ src/app.tsAgent more files not shown: open the worktree to see them.EditClose x -
Ask Claude…Backgrounda1b2c3dok · 2h 10m · exit Follow latest
$ npm testNo output yet.Follow latest -
Ask Claude…對話 diffFix login+0-0只看還沒 commit 的重新整理全部收合關閉整段對話:每個檔案跟這個對話第一次改它之前比,commit 過的也算。這裡只能看,要還原請切回「只看還沒 commit 的」。已經 commit、之後沒再改(3):Edit● src/app.tsok+3-3(跟上次 commit 比)解釋還原復原Bash確定刪除取消Edit● src/app.ts(續)
Bash● src/app.ts(續)Bash● src/app.ts(續)… 還有 3 行 diff 太長沒顯示(這個檔案的 diff 太長,先收合上面幾個檔案再看它)Bash● src/app.tsok+3-3(跟上次 commit 比)解釋還原復原Bash確定刪除取消Edit● src/app.ts(續)Bash● src/app.ts(續)Bash● src/app.ts(續)… 還有 3 行 diff 太長沒顯示(這個檔案的 diff 太長,先收合上面幾個檔案再看它)Bash… 還有 3 個檔案沒列出來● src/app.tsok+3-3(跟上次 commit 比)解釋還原復原Bash確定刪除取消Edit● src/app.ts(續)Bash● src/app.ts(續)Bash● src/app.ts(續)… 還有 3 行 diff 太長沒顯示(這個檔案的 diff 太長,先收合上面幾個檔案再看它)Bash