modscode / Gallery / gcloud-guard
gcloud-guard
Holds gcloud and gsutil commands that would create, change or delete cloud resources, shows the account, project, location and the current state of the targets, and asks you to Proceed or Cancel.
What it does
- Draws a pane, a band above the prompt
- Adds /gcloud-guard
- Watches Bash calls and can refuse them
- Hooks session.start
- Starts processes
Good points
- No network calls
- Written in TypeScript
- Handles errors
- Writes no files
Code to start from
Two kinds: a starter modscode writes from the design above, and the lines of the mod's own code that draw it.
Starter (register.tsx)
import type { Register } from 'claude-code'
// Drawn like gcloud-guard by davidho27941 (pane, band, toast), as modscode read it from the mod's code:
// https://modscode.com/gallery/davidho27941-gcloud-guard/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the pane: open it with $.ui.open({ id: 'my-pane', title: "gcloud-guard · ‹severityLabel›" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box } = $.ui.resolve(e)
return (
<Box flexDirection="column" borderStyle="round" paddingX={1} />
)
})
// the band above the prompt; what else goes there is drawn under it
on('ui.render', { component: 'AbovePrompt' }, async ($, e, next) => {
const { Box, Text } = $.ui.resolve(e)
return (
<Box flexDirection="column">
<Box flexDirection="column">
<Text wrap="truncate-end" dimColor>
en
</Text>
<Text dimColor>
────────
</Text>
</Box>
{await next(e)}
</Box>
)
})
}
The mod's own code
Shown under the mod's licence (MIT); its text is below. Keep the notice if you copy these lines.
plugins/gcloud-guard/hooks/register.tsx lines 611–617 · Pane
on('ui.render', { component: 'Pane', requestId: 'gcloud-guard' }, async ($, e, next) => {
const view = (await read($, heldState)) as HeldView | null
if (view === null) return next(e)
await read($, langState)
const snap = (await read($, contextState)) as GcloudContext | null
return draw($, e, view, e.props.bodyColumns ?? 80, snap?.kube ?? null)
})plugins/gcloud-guard/hooks/register.tsx lines 371–482 · Pane
function draw($: any, e: any, view: HeldView, columns: number, gke: GcloudContext['kube'] | null) {
const { Box, Text, Button } = $.ui.resolve(e)
const L = lang
const risk = view.risk
const report = view.report
const color = severityColor(risk.severity)
const ctx = report?.context ?? emptyContext(risk)
const unknown = t(L, 'value.unknown')
const projectSource = ctx.projectSource === 'flag' ? t(L, 'source.flag') : ctx.projectSource === 'config' ? t(L, 'source.config') : ''
const location = ctx.location ?? t(L, 'value.default')
const decide = (choice: Decision) => () => {
if (held && held.view.id === view.id && held.decision === null) held.decision = choice
}
const rows: any[] = []
rows.push(
<Text key="title" bold color={color}>
{t(L, 'title', { severity: severityLabel(L, risk.severity) })}
</Text>,
)
rows.push(
<Text key="head" bold color={color} wrap="truncate-end">
{report?.headline ?? headline(L, risk)}
</Text>,
)
rows.push(
<Text key="cmd" wrap="truncate-end">
<Text dimColor>{`${t(L, 'label.command')} `}</Text>
<Text bold>{truncate(view.command, Math.max(20, columns - 12))}</Text>
</Text>,
)
rows.push(
<Text key="account" wrap="truncate-end">
<Text dimColor>{`${t(L, 'label.account')} `}</Text>
<Text>{ctx.account ?? unknown}</Text>
{ctx.impersonate ? <Text dimColor>{` (impersonating ${ctx.impersonate})`}</Text> : null}
</Text>,
)
rows.push(
<Text key="project" wrap="truncate-end">
<Text dimColor>{`${t(L, 'label.project')} `}</Text>
<Text bold>{ctx.project ?? unknown}</Text>
{projectSource ? <Text dimColor>{` ${projectSource}`}</Text> : null}
{ctx.configuration ? <Text dimColor>{` · ${t(L, 'label.configuration')} ${ctx.configuration}`}</Text> : null}
</Text>,
)
rows.push(
<Text key="location" wrap="truncate-end">
<Text dimColor>{`${t(L, 'label.location')} `}</Text>
<Text>{location}</Text>
{ctx.track !== 'ga' ? <Text color="magenta">{` · ${t(L, 'label.track')} ${ctx.track}`}</Text> : null}
</Text>,
)
if (gke && gke.kind === 'gke') {
rows.push(
<Text key="gke" wrap="truncate-end">
<Text dimColor>{`${t(L, 'label.gke')} `}</Text>
<Text>{`${gke.cluster} (${gke.location})`}</Text>
{gke.project && ctx.project && gke.project !== ctx.project ? <Text color="yellow">{` ≠ ${t(L, 'label.project').toLowerCase()} ${gke.project}`}</Text> : null}
</Text>,
)
}
if (ctx.quiet) {
rows.push(
<Text key="quiet" color="yellow">
{t(L, 'quiet.warn')}
</Text>,
)
}
if (report && report.lines.length) {
rows.push(
<Box key="lines" flexDirection="column" marginTop={1}>
{report.lines.map((line, i) => (
<Text key={`l${i}`} wrap="truncate-end">
{` ${line}`}
</Text>
))}
</Box>,
)
}
if (report && report.notes.length) {
rows.push(
<Box key="notes" flexDirection="column">
{report.notes.map((note, i) => (
<Text key={`n${i}`} dimColor italic wrap="wrap">
{note}
</Text>
))}
</Box>,
)
}
if (!report) {
rows.push(
<Text key="measuring" dimColor>
…
</Text>,
)
}
rows.push(
<Box key="buttons" marginTop={1} gap={2}>
<Button key="proceed" label={t(L, 'btn.proceed')} hotkey="1" plain onPress={decide('proceed')} />
<Button key="cancel" label={t(L, 'btn.cancel')} hotkey="2" plain autoFocus onPress={decide('cancel')} />
<Text key="hint" dimColor>
{t(L, 'waiting')}
</Text>
</Box>,
)
return (
<Box flexDirection="column" borderStyle="round" borderColor={color} paddingX={1}>
{rows}
</Box>
)
}plugins/gcloud-guard/hooks/register.tsx lines 619–646 · Band
on('ui.render', { component: 'AbovePrompt' }, async ($, e, next) => {
const view = (await read($, heldState)) as HeldView | null
await read($, langState)
if (view !== null) {
if (view.where !== 'band') return next(e)
// The report takes the whole band while the command is held: the buttons must be on top
const snap = (await read($, contextState)) as GcloudContext | null
return draw($, e, view, e.props.bodyColumns ?? 80, snap?.kube ?? null)
}
if (e.props.hasSurvey || !settings.showContext || (await read($, isBandHidden))) return next(e)
const ctx = (await read($, contextState)) as GcloudContext | null
const text = contextLine(lang, ctx, settings)
if (text === null) return next(e)
const ui = $.ui.resolve(e)
const { Text } = ui
// AbovePrompt is a chain: draw our line in its frame, then whatever the plugins beneath drew
const below = await next(e)
return frameBand(
ui,
settings.bandStyle,
kubeProjectMismatch(ctx),
e.props.bodyColumns,
<Text wrap="truncate-end" dimColor>
{text}
</Text>,
below,
)
})plugins/gcloud-guard/hooks/register.tsx lines 654–678 · Band
function frameBand(ui: { Box: any; Text: any }, style: BandStyle, isWarning: boolean, bodyColumns: number | undefined, content: any, below: any) {
const { Box, Text } = ui
const hasBelow = below !== null && below !== undefined && (below as { type?: string }).type !== 'engine'
const own =
style === 'box' ? (
<Box key="frame" flexDirection="column" borderStyle="round" borderDimColor={isWarning ? undefined : true} borderColor={isWarning ? 'yellow' : undefined} paddingX={1}>
{content}
</Box>
) : style === 'rule' ? (
<Box key="frame" flexDirection="column">
{content}
{hasBelow ? <Text key="rule" dimColor>{'─'.repeat(Math.max(8, Math.min(bodyColumns ?? 60, 200)))}</Text> : null}
</Box>
) : (
<Box key="frame" flexDirection="column">
{content}
</Box>
)
return (
<Box flexDirection="column">
{own}
{below}
</Box>
)
}Licence text (MIT)
MIT License Copyright (c) 2026 davidho27941 Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
What its code calls
runs programsreads filesenv varstool calls
What its code shows
Read from the source at commit ba99db26b864 on 2026-10-06. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.
| Decides the listing: code you can check | |
|---|---|
| Entry read | Every module hooks/hooks.json names was read.plugins/gcloud-guard/hooks/register.tsx |
| Parses | Every file parses as TypeScript or JavaScript.3 files parsed |
| All its code is in the mod | Every import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod |
| Readable | No minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs |
| Calls in the open | Network and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open |
| For you to weigh before installing | |
| Where it draws | The terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both |
| Install line | Whether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.listed in its repository's .claude-plugin/marketplace.json: installs from there |
| Programs on Windows | Whether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).runs no program a Windows PC lacks |
| Network | Whether every fetch names its https host in the code.no network |
| Programs | Whether every program it starts is named in the code and is not a shell, an interpreter or a network tool.plugins/gcloud-guard/hooks/register.tsx:200 a program named at run time |
| Reads and sends | Whether it both reads files or environment variables and reaches the network.reaches no network |
| Keys in the source | Whether the source holds what looks like an API key or a private key.no keys in the source |
| Licence | An open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets modscode show its code; otherwise the code is linked.MIT |
This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen
Install it
Check it yourself before you install it. Mods run unsandboxed, with your permissions, and modscode does not vouch for what this code does. Read the code below (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.
Its repository is its marketplace. Add that marketplace (in the terminal with these commands, or in the desktop app's plugin settings) and install the mod from it:
/plugin marketplace add davidho27941/cockpit/plugin install gcloud-guard@cockpitThis installs the marketplace's latest commit, which may not be the one read here (ba99db26b864). Compare them before you install.
Ask Claude about it
With the modscode connector added, Claude can read this design, what its code reaches and its code, and build on them. Ask it like this:
Read the modscode design "davidho27941-gcloud-guard" with its code and make me a pane like itSearch them from Claude: the MCP connector
Similar designs
-
Ask Claude…2h 10m · █████░░░✓ build ✓ build ✓ buildJavaKotlin3 Python■ ok 3 ■ ok 3 ■ ok 3 Razor proven 3 Razor proven 3 Razor proven 3Phases ──────── 3/3build Pythonbuild Pythonbuild Python… 3 more phasesLua ──────── 3/Kotlin■ the whole upgrade Ruby■ build build Ruby■ build build Ruby■ build build Ruby … 3 moreNext ──────── PythonRuby (by hand)Podsclick a button, or ctrl+x tab then Tab, EnterAttention ──────── 3! Scala ! Scala ! Scala … 3 moreSession ──────── okJava
-
Open a file first: /crit-tui file <path>Reopen this one in the crit browser view.Ask Claude…
-
Ask Claude…TodayOct 63 left · Mar overdueRemCTL: Sep✓ All done for today.● build3● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● build3● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● build3● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓● Fix login ● ⚑Jul · build✓Updated 14:32UndoRefresh
-
Ask Claude…TO graph› Fix login › Fix login › Fix loginScopeThis featureWhole projectHide done stepsReconnect
-
Ask Claude…Blast Radius⚠ Blast Radius · buildCommand npm testWould CancelProceed Proceed ProceedBash1 Proceed2 CancelClaude is waiting on your answer
-
Ask Claude…Agent Radar● Edit note · 2h 10m · 0 toolsnow: starting────────No messages yet.agent: (tool calls)agent: (tool calls)agent: (tool calls)Back bClose q