modscode JA

modscode / Gallery / guardrails

guardrails

Clickable safety rules with presets: block rm -rf, force-push, destructive git, secret files, sudo, installs, network; lock Claude to the project folder or read-only; add your own block patterns.

Code you can checkTerminal + desktopPaneStatus lineToastBoxButtonInputText

What it does

  • Draws a pane, the status line, toasts
  • Adds /guard, /guard-preset
  • Watches tool calls and can refuse them
  • Hooks session.start
  • Keeps its own state between turns

Good points

  • No network calls
  • Starts no processes
  • Written in TypeScript
  • Handles errors

Code to start from

Two kinds: a starter modscode writes from the design above, and the lines of the mod's own code that draw it.

Starter (register.tsx)

register.tsx
import type { Register } from 'claude-code'

// Drawn like guardrails by Michael Goldenberg (pane, status, toast), as modscode read it from the mod's code:
// https://modscode.com/gallery/mishgoldenberg-guardrails/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
  // the pane: open it with $.ui.open({ id: 'my-pane', title: "Guardrails" })
  on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
    const { Box, Text, Button, Input } = $.ui.resolve(e)
    const status = '…'
    const i = '…'
    const title = '…'
    const explain = '…'
    const explain2 = '…'
    const explain3 = '…'
    const value = '…'
    const pattern = '…'
    const pattern2 = '…'
    const pattern3 = '…'
    const length = '…'
    const tool = '…'
    const rule = '…'
    const what = '…'
    const tool2 = '…'
    const rule2 = '…'
    const what2 = '…'
    const tool3 = '…'
    const rule3 = '…'
    const what3 = '…'
    return (
      <Box flexDirection="column" gap={1}>
        <Box gap={1}>
          <Text color="claude">
            ●
          </Text>
          <Text bold>
            guardrails
          </Text>
          <Text dimColor wrap="truncate-end">
            {status}
          </Text>
        </Box>
        <Box flexDirection="column">
          <Box gap={1}>
            <Text dimColor>
              Presets
            </Text>
          </Box>
          <Box gap={1} flexWrap="wrap">
            <Button hotkey={`${i}`} variant="primary" label={`${title}`} />
            <Button hotkey={`${i}`} variant="primary" label={`${title}`} />
            <Button hotkey={`${i}`} variant="primary" label={`${title}`} />
          </Box>
        </Box>
        <Box flexDirection="column">
          <Box gap={1}>
            <Text dimColor>
              Rules
            </Text>
          </Box>
          <Box flexDirection="column">
            <Box gap={1}>
              <Text color="claude">
                ●
              </Text>
              <Button plain label={`${title}`} />
            </Box>
            <Box paddingLeft={2}>
              <Text dimColor wrap="truncate-end">
                {explain}
              </Text>
            </Box>
          </Box>
          <Box flexDirection="column">
            <Box gap={1}>
              <Text color="claude">
                ●
              </Text>
              <Button plain label={`${title}`} />
            </Box>
            <Box paddingLeft={2}>
              <Text dimColor wrap="truncate-end">
                {explain2}
              </Text>
            </Box>
          </Box>
          <Box flexDirection="column">
            <Box gap={1}>
              <Text color="claude">
                ●
              </Text>
              <Button plain label={`${title}`} />
            </Box>
            <Box paddingLeft={2}>
              <Text dimColor wrap="truncate-end">
                {explain3}
              </Text>
            </Box>
          </Box>
        </Box>
        <Box flexDirection="column">
          <Box gap={1}>
            <Text dimColor>
              Your own block patterns (regex on shell commands)
            </Text>
          </Box>
          <Box flexDirection="column">
            <Text dimColor>
              {value}
            </Text>
            <Box gap={1}>
              <Text color="claude">
                ●
              </Text>
              <Text wrap="truncate-end">
                /
                {pattern}
                /
              </Text>
              <Button plain label="remove" />
            </Box>
            <Box gap={1}>
              <Text color="claude">
                ●
              </Text>
              <Text wrap="truncate-end">
                /
                {pattern2}
                /
              </Text>
              <Button plain label="remove" />
            </Box>
            <Box gap={1}>
              <Text color="claude">
                ●
              </Text>
              <Text wrap="truncate-end">
                /
                {pattern3}
                /
              </Text>
              <Button plain label="remove" />
            </Box>
            <Input placeholder="regex, e.g. docker\s+system\s+prune" submitLabel="Add" />
          </Box>
        </Box>
        <Box flexDirection="column">
          <Box gap={1}>
            <Text dimColor>
              {`Blocked this session (${length})`}
            </Text>
          </Box>
          <Box flexDirection="column">
            <Text dimColor>
              Nothing blocked yet. When a rule stops a command, it shows up here with the rule that caught it.
            </Text>
            <Text wrap="truncate-end">
              <Text color="error">
                ✗
              </Text>
              {" "}
              {tool}
              {" "}
              <Text dimColor>
                {rule}
                {": "}
                {what}
              </Text>
            </Text>
            <Text wrap="truncate-end">
              <Text color="error">
                ✗
              </Text>
              {" "}
              {tool2}
              {" "}
              <Text dimColor>
                {rule2}
                {": "}
                {what2}
              </Text>
            </Text>
            <Text wrap="truncate-end">
              <Text color="error">
                ✗
              </Text>
              {" "}
              {tool3}
              {" "}
              <Text dimColor>
                {rule3}
                {": "}
                {what3}
              </Text>
            </Text>
          </Box>
        </Box>
        <Text dimColor>
          Rules are best-effort pattern checks, a seatbelt, not a sandbox. Saved for all your sessions.
        </Text>
      </Box>
    )
  })

  on('session.start', async ($, e, next) => {
    const count = '…'
    const tool = '…'
    const rule = '…'
    await $.ui.status(`guard ${count} rules`)
    await $.ui.toast(`Blocked ${tool}: ${rule}`)
    await $.ui.toast(`That is not a valid regular expression.`)
    return next(e)
  })
}

The mod's own code

Shown under the mod's licence (MIT); its text is below. Keep the notice if you copy these lines.

plugins/guardrails/hooks/register.tsx lines 313–418 · Pane
  on('ui.render', { component: 'Pane', requestId: PANE }, async ($, e) => {
    const els = $.ui.resolve(e)
    const { Box, Text, Button } = els
    const Input = 'Input' in els ? els.Input : undefined
    const cfg = await read($, config)
    const recent = await read($, blocks)

    const kit = { Box, Text }
    const isActive = (p: (typeof PRESETS)[number]) => p.rules.length === cfg.enabled.length && p.rules.every(r => cfg.enabled.includes(r))
    const active = PRESETS.find(isActive)
    const count = cfg.enabled.length + cfg.custom.length
    const status =
      count === 0
        ? 'all rules off'
        : `${active?.title ?? 'custom set'} · ${count} rule${count === 1 ? '' : 's'} on${recent.length > 0 ? ` · ${recent.length} blocked` : ''}`

    return (
      <Box flexDirection="column" gap={1}>
        {header(kit, count > 0 ? GLYPH.on : GLYPH.off, count > 0 ? TONE.accent : TONE.dim, 'guardrails', status)}

        {section(
          kit,
          'Presets',
          <Box gap={1} flexWrap="wrap">
            {PRESETS.map((p, i) => (
              <Button key={`preset-${p.id}`} hotkey={String(i + 1)} variant={isActive(p) ? 'primary' : 'secondary'} label={p.title} onPress={() => void save($, c => ({ ...c, enabled: p.rules }))} />
            ))}
          </Box>,
        )}

        {section(
          kit,
          'Rules',
          RULES.map(rule => {
            const isOn = cfg.enabled.includes(rule.id)

            return (
              <Box flexDirection="column">
                <Box gap={1}>
                  <Text color={isOn ? TONE.accent : TONE.dim}>{isOn ? GLYPH.on : GLYPH.off}</Text>
                  <Button
                    key={`rule-${rule.id}`}
                    plain
                    label={rule.title}
                    onPress={() => void save($, c => ({ ...c, enabled: isOn ? c.enabled.filter(id => id !== rule.id) : [...c.enabled, rule.id] }))}
                  />
                </Box>
                <Box paddingLeft={2}>
                  <Text dimColor wrap="truncate-end">
                    {rule.explain}
                  </Text>
                </Box>
              </Box>
            )
          }),
        )}

        {section(
          kit,
          'Your own block patterns (regex on shell commands)',
          <Box flexDirection="column">
            {cfg.custom.length === 0 && empty(kit, String.raw`None yet. Example: terraform\s+destroy  or  kubectl\s+delete`)}
            {cfg.custom.map((c, i) => (
              <Box gap={1}>
                <Text color={TONE.accent}>{GLYPH.on}</Text>
                <Text wrap="truncate-end">/{c.pattern}/</Text>
                <Button key={`del-${i}`} plain label="remove" onPress={() => void save($, cur => ({ ...cur, custom: cur.custom.filter((_, j) => j !== i) }))} />
              </Box>
            ))}
            {Input !== undefined && (
              <Input
                key="add"
                placeholder="regex, e.g. docker\s+system\s+prune"
                submitLabel="Add"
                onSubmit={(value: string) => {
                  const pattern = value.trim()
                  if (pattern === '') return
                  try {
                    new RegExp(pattern)
                  } catch {
                    $.ui.toast('That is not a valid regular expression.')
                    return
                  }
                  void save($, c => ({ ...c, custom: [...c.custom, { pattern, note: '' }] }))
                }}
              />
            )}
          </Box>,
        )}

        {section(
          kit,
          `Blocked this session (${recent.length})`,
          <Box flexDirection="column">
            {recent.length === 0 && empty(kit, 'Nothing blocked yet. When a rule stops a command, it shows up here with the rule that caught it.')}
            {recent.slice(0, 6).map(b => (
              <Text wrap="truncate-end">
                <Text color={TONE.bad}>{GLYPH.fail}</Text> {b.tool} <Text dimColor>{b.rule}: {b.what}</Text>
              </Text>
            ))}
          </Box>,
        )}
        <Text dimColor>Rules are best-effort pattern checks, a seatbelt, not a sandbox. Saved for all your sessions.</Text>
      </Box>
    )
  })
plugins/guardrails/hooks/register.tsx lines 12–20 · Pane
function header({ Box, Text }: Kit, glyph: string, tone: string, name: string, status: string) {
  return (
    <Box gap={1}>
      <Text color={tone}>{glyph}</Text>
      <Text bold>{name}</Text>
      <Text dimColor wrap="truncate-end">{status}</Text>
    </Box>
  )
}
plugins/guardrails/hooks/register.tsx lines 23–33 · Pane
function section({ Box, Text }: Kit, label: string, rows: RenderChildren, aside?: RenderChildren) {
  return (
    <Box flexDirection="column">
      <Box gap={1}>
        <Text dimColor>{label}</Text>
        {aside}
      </Box>
      {rows}
    </Box>
  )
}
plugins/guardrails/hooks/register.tsx lines 45–47 · Pane
function empty({ Text }: Kit, text: string) {
  return <Text dimColor>{text}</Text>
}
Licence text (MIT)
MIT License

Copyright (c) 2026 Michael Goldenberg

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

What its code calls

tool callsremembers

The design, read from code

Drawn from the mod's source at the commit read, not from a run: a list is drawn three times, a condition takes its first branch that draws in the desktop app, and a value only the run time knows is shown as a made-up sample (dotted underline) or left out. Colours and type are this site's.

What its code shows

Read from the source at commit 6949e8dde6af on 2026-10-06. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.

Decides the listing: code you can check
Entry readEvery module hooks/hooks.json names was read.plugins/guardrails/hooks/register.tsx
ParsesEvery file parses as TypeScript or JavaScript.1 files parsed
All its code is in the modEvery import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod
ReadableNo minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs
Calls in the openNetwork and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open
For you to weigh before installing
Where it drawsThe terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both
Install lineWhether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.listed in its repository's .claude-plugin/marketplace.json: installs from there
Programs on WindowsWhether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).runs no program a Windows PC lacks
NetworkWhether every fetch names its https host in the code.no network
ProgramsWhether every program it starts is named in the code and is not a shell, an interpreter or a network tool.starts no programs
Reads and sendsWhether it both reads files or environment variables and reaches the network.reaches no network
Keys in the sourceWhether the source holds what looks like an API key or a private key.no keys in the source
LicenceAn open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets modscode show its code; otherwise the code is linked.MIT

This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen

Install it

Check it yourself before you install it. Mods run unsandboxed, with your permissions, and modscode does not vouch for what this code does. Read the code below (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.

Its repository is its marketplace. Add that marketplace (in the terminal with these commands, or in the desktop app's plugin settings) and install the mod from it:

/plugin marketplace add mishgoldenberg/claude-mods
/plugin install guardrails@claude-mods

This installs the marketplace's latest commit, which may not be the one read here (6949e8dde6af). Compare them before you install.

Ask Claude about it

With the modscode connector added, Claude can read this design, what its code reaches and its code, and build on them. Ask it like this:

Read the modscode design "mishgoldenberg-guardrails" with its code and make me a pane like it

Search them from Claude: the MCP connector

Similar designs