airlock
Routes supported project edits into a Git worktree for review, accept or reject. Worktree routing is not a filesystem sandbox.
何をするか
- 欄・ステータス行・トーストを描く
- /airlock-status・/airlock-diff・/airlock-accept・/airlock-reject を足す
- Read・Edit・Write・NotebookEdit の呼び出しを見張る(止めることがある)
- prompt.section・session.start・turn.complete・turn.startにフックする
- ターンをまたいで自分の状態を持つ
良いところ
- ネットワークに出ない
- TypeScript で書かれている
- エラーを扱う
作り始めるためのコード
2 種類あります。上のデザインから modscode が書いた雛形と、その Mod 自身のコードのうち描いている部分です。
雛形(register.tsx)
import type { Register } from 'claude-code'
// Drawn like airlock by billymrx (pane, status, toast), as modscode read it from the mod's code:
// https://modscode.com/gallery/billymrx1-airlock/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the pane: open it with $.ui.open({ id: 'my-pane', title: "Airlock review" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box, Text, Code, Button } = $.ui.resolve(e)
const txRoot = '…'
const length = '…'
const files = '…'
const length2 = '…'
const skipped = '…'
const length3 = '…'
const length4 = '…'
const text = '…'
return (
<Box flexDirection="column">
<Text>
{"Transaction "}
(unknown)
{" · "}
REVIEW
</Text>
<Text dimColor>
{"Repository: "}
</Text>
<Text dimColor>
{"Worktree: "}
{txRoot}
</Text>
<Text>
{"Changes: "}
{length}
{" file(s), +"}
0
/-
0
</Text>
<Text>
{"Files: "}
{files}
{` and ${length} more`}
</Text>
<Text dimColor>
{"Untracked files included in baseline: "}
{length2}
</Text>
<Text dimColor>
{"Skipped files: "}
{skipped}
</Text>
<Text dimColor>
{"Side-effect events: "}
{length3}
{" ("}
{length4}
{" denied). Effects already performed outside the workspace cannot be rolled back by reject."}
</Text>
<Text dimColor>
Checks: Airlock does not run your project test suite. Accept checks concurrent edits and patch fit before applying. Rej…
</Text>
<Text>
APPLY_FAILED: this transaction may be partially applied. Preserve the workspace and backup for manual recovery; Accept …
</Text>
<Box flexDirection="column">
<Text dimColor>
Pane preview is capped at 10,000 characters; the diff may be incomplete.
</Text>
<Code source={`${text}`} />
</Box>
<Box flexDirection="row">
<Button label="Review" hotkey="v" />
<Button label="Accept" hotkey="a" variant="primary" />
<Button label="Reject" hotkey="r" variant="secondary" />
</Box>
</Box>
)
})
on('session.start', async ($, e, next) => {
const transactionId = '…'
await $.ui.status(`airlock: transaction ${transactionId} is open in another session — mutations blocked here`)
await $.ui.toast(`This review pane is stale. Open the current transaction review before acting.`)
await $.ui.toast(`Airlock review is ready; use /airlock-review to open the pane, or /airlock-diff.`)
return next(e)
})
}
Mod 自身のコード
Mod のライセンス(MIT)に従って載せています。全文は下にあります。写すときは著作権表示を残してください。
hooks/register.ts 24〜24 行 · ペイン
on('ui.render', { component: 'Pane', requestId: REVIEW_PANE }, onReviewRender)hooks/tx/commands.tsx 717〜776 行 · ペイン
export async function onReviewRender($: any, e: any): Promise<unknown> {
const { Box, Text, Button, Code } = $.ui.resolve(e)
const tx = await storedTransaction($)
if (!tx) return <Box flexDirection="column"><Text>Airlock has no open transaction for this repository.</Text></Box>
const stats = tx.stats ?? {}
const files = Array.isArray(tx.changedFiles) ? tx.changedFiles : []
const skipped = Array.isArray(tx.skippedFiles) ? tx.skippedFiles : []
const untracked = Array.isArray(tx.untrackedCopied) ? tx.untrackedCopied : []
const effects = Array.isArray(tx.sideEffectEvents) ? tx.sideEffectEvents : []
const savedDiff = await $.store.get(diffKey(ctx.repoRoot)) as { transactionId?: string; text?: string; truncated?: boolean } | undefined
const currentDiff = savedDiff?.transactionId === tx.transactionId ? savedDiff : undefined
return (
<Box flexDirection="column">
<Text>Transaction {tx.transactionId ?? '(unknown)'} · {tx.state ?? 'REVIEW'}</Text>
<Text dimColor>Repository: {tx.repoRoot ?? ctx.repoRoot}</Text>
<Text dimColor>Worktree: {tx.txRoot}</Text>
<Text>Changes: {stats.files ?? files.length} file(s), +{stats.insertions ?? 0}/-{stats.deletions ?? 0}</Text>
{files.length > 0 && <Text>Files: {files.slice(0, 8).join(', ')}{files.length > 8 ? ` and ${files.length - 8} more` : ''}</Text>}
{untracked.length > 0 && <Text dimColor>Untracked files included in baseline: {untracked.length}</Text>}
{skipped.length > 0 && <Text dimColor>Skipped files: {skipped.join(', ')}</Text>}
{effects.length > 0 && <Text dimColor>Side-effect events: {effects.length} ({effects.filter(x => x.action === 'denied').length} denied). Effects already performed outside the workspace cannot be rolled back by reject.</Text>}
<Text dimColor>Checks: Airlock does not run your project test suite. Accept checks concurrent edits and patch fit before applying. Reject discards this worktree.</Text>
{tx.state === 'APPLY_FAILED' && <Text>APPLY_FAILED: this transaction may be partially applied. Preserve the workspace and backup for manual recovery; Accept cannot retry this apply.</Text>}
{typeof currentDiff?.text === 'string' && currentDiff.text !== '' && (currentDiff.truncated
? <Box flexDirection="column"><Text dimColor>Pane preview is capped at 10,000 characters; the diff may be incomplete.</Text><Code source={currentDiff.text} /></Box>
: <Code source={currentDiff.text} format="diff" />)}
<Box flexDirection="row">
<Button key="review-diff" label="Review" hotkey="v" onPress={async () => {
if (!(await isCurrentReview($, tx.transactionId ?? ''))) return
const patch = await $.process.run(['git', 'diff', tx.baselineCommit ?? tx.baseHead ?? 'HEAD', '--binary'], { cwd: tx.txRoot })
const latest = await storedTransaction($)
if (latest?.transactionId !== tx.transactionId) return
const text = patch.exitCode === 0 ? patch.stdout : `Could not read the transaction diff (exit code ${patch.exitCode ?? 'unknown'}).`
await $.store.set(diffKey(ctx.repoRoot), {
transactionId: tx.transactionId,
text: text.slice(0, 10000),
truncated: patch.isStdoutTruncated || text.length > 10000,
})
$.ui.invalidate('ui.render')
}} />
<Button key="accept" label="Accept" hotkey="a" variant="primary" onPress={async e => {
if (!(await isCurrentReview($, tx.transactionId ?? ''))) return
const result: any = await onTxAccept($, {})
$.ui.toast(result?.text?.split('\n')[0] ?? 'Airlock accept finished.', { timeoutMs: 6000 })
if (await $.store.get(activeKey(ctx.repoRoot)) === undefined) await $.ui.close({ id: REVIEW_PANE })
else $.ui.invalidate('ui.render')
}} />
<Button key="reject" label="Reject" hotkey="r" variant="secondary" onPress={async e => {
if (!(await isCurrentReview($, tx.transactionId ?? ''))) return
const result: any = await onTxReject($, {})
$.ui.toast(result?.text?.split('\n')[0] ?? 'Airlock reject finished.', { timeoutMs: 6000 })
if (await $.store.get(activeKey(ctx.repoRoot)) === undefined) await $.ui.close({ id: REVIEW_PANE })
else $.ui.invalidate('ui.render')
}} />
</Box>
</Box>
)
}ライセンスの全文(MIT)
MIT License Copyright (c) 2026 billymrx Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
コードが呼ぶもの
プログラム起動ファイル書き込み環境変数ツール呼び出し保存
コードから読み取ったデザイン
Review読み取ったコミットのソースから描いたもので、動かした結果ではありません。一覧は 3 回描き、条件はデスクトップアプリで描く最初の分岐を取り、動かしたときにだけ決まる値は仮の例(点線の下線)にするか省きます。色と書体はこのサイトのものです。
コードから読めること
2026-10-06 に読んだコミット 0c7e681c9253 のソースから。最初のまとまりが載せる条件で、残りは自分で判断するための材料です。後のコミットは、次に読むまで見ていません。
| 載せる条件: 確かめやすいコード | |
|---|---|
| 入口を読んだ | hooks/hooks.json が名指すモジュールをすべて読んだ。hooks/register.ts |
| 解析できる | すべてのファイルが TypeScript か JavaScript として解析できる。14 ファイルを解析 |
| コードが Mod の中で完結 | import は Mod 自身のファイルかエンジンのモジュールだけ。パッケージも require もない。コードはすべて Mod の中 |
| 読める | 圧縮した行・eval・new Function・計算した道の import()・符号化した塊がない。圧縮・eval・符号化した塊なし |
| 呼び出しが見える | 通信とプログラム起動はその場で $.http.fetch・$.process.run と書き、他へ渡さない。外への呼び出しはすべてその場の $ で |
| 入れる前に自分で判断する材料 | |
| 描く場所 | コードから読んだ、描く先。ターミナル・デスクトップアプリ・両方・何も描かない(フックだけ: 見張りやプロンプトの書き換え)のどれか。出すだけで、外す理由にはしない。ターミナルとデスクトップアプリに同じように描く |
| 入れる手順 | リポジトリ自身の .claude-plugin/marketplace.json にこの Mod が載っていて、ページに書いた手順でそのマーケットプレイスから入れられるか。リポジトリの .claude-plugin/marketplace.json に載っており、そこから入れられる |
| Windows のプログラム | $.process で起動するプログラムが Windows にあるか(tail・date・open・osascript・/usr/… などは無い)。hooks/tx/commands.tsx:193 mkdir(Windows にない); hooks/tx/commands.tsx:216 mkdir(Windows にない); hooks/tx/commands.tsx:219 cp(Windows にない); hooks/tx/commands.tsx:237 cp(Windows にない); hooks/tx/commands.tsx:254 rm(Windows にない) |
| 通信 | fetch の送り先(https のホスト)がコードに書いてあるか。通信なし |
| プログラム | 起動するプログラムの名前がコードに書いてあり、シェル・インタプリタ・通信用の道具でないか。hooks/tools/bash.ts:114 bash(シェル・インタプリタ) |
| 読んで送る | ファイルや環境変数を読み、かつ通信するか。reads environment variables and files and reaches the network |
| ソースの鍵 | ソースに API キーや秘密鍵らしきものがあるか。ソースに鍵なし |
| ライセンス | オープンなライセンス(MIT・Apache-2.0・BSD・ISC・Unlicense・0BSD・CC0)で全文があれば、modscode にコードを載せる。違えばリンクだけ。MIT |
コードの文面を読んだだけで、安全の審査ではありません。動かしてはおらず、起動するプログラムの中で何が起きるかも見えません。入れる前の確認はあなたの役目です。 載せる条件
入れる
入れる前に、必ず自分で確かめてください。Mod はサンドボックスなしで、あなたの権限で動きます。modscode はこのコードの安全を保証しません。下のコードを読み(またはフォルダーで claude plugin validate .)、触るものを見て、読んだコミットを入れてください。
リポジトリがそのままマーケットプレイスです。このマーケットプレイスを足し(ターミナルでは次のコマンド、デスクトップアプリではプラグインの設定)、そこから Mod を入れます。
/plugin marketplace add BillyMRX1/airlock/plugin install airlock@airlock-marketplace入るのはマーケットプレイスの最新のコミットで、ここで読んだもの(0c7e681c9253)と違うことがあります。入れる前に見比べてください。
Claude に聞く
modscode のコネクタを入れると、Claude がこのデザイン・コードが触るもの・コードを読んで、それをもとに作れます。たとえば:
modscode のデザイン「billymrx1-airlock」をコードごと読んで、同じようなペインを作って似たデザイン
-
Claude に頼む…AttemptsPlain3 attempts from src/ · nothing is applied until you press AdoptDiff of StealthHide+ src/app.ts
Footer label+ src/app.tsFooter label+ src/app.tsClassic more files not shown: open the worktree to see them.Footer labelClose x -
Claude に頼む…CIcross Bash · Classicmain · a1b2c3d · failed at 14:32Open the run on GitHubFix it fClose x
(no log available)
-
Claude に頼む…Gitbranch main · Pinned notice · 0, 0 untracked, 0 staged× git failed► Hint lineRefresh rStage all aCommit Ghost cClose xWorking tree clean.Fix loginMonoGenerate gCommitTop rowHint linesrc/app.tsbinDiffStageUnstageRevertTop rowHint linesrc/app.tsbinDiffStageUnstageRevertTop rowHint line… 3 moresrc/app.tsbinDiffStageUnstageRevertsrc/app.tsClosebuild (cut to fit)
Plainbuild (cut to fit)Plainbuild (cut to fit)MinimalMinimalMinimalPlain -
Claude に頼む…Night shiftNight shiftEach task ran in its own worktree and branch; nothing is in your checkout until you press Adopt.Diff of Fix loginHide diff+ src/app.ts
Edit+ src/app.tsEdit+ src/app.tsAgent more files not shown: open the worktree to see them.EditClose x -
Claude に頼む…Backgrounda1b2c3dok · 2h 10m · exit Follow latest
$ npm testNo output yet.Follow latest -
Claude に頼む…對話 diffFix login+0-0只看還沒 commit 的重新整理全部收合關閉整段對話:每個檔案跟這個對話第一次改它之前比,commit 過的也算。這裡只能看,要還原請切回「只看還沒 commit 的」。已經 commit、之後沒再改(3):Edit● src/app.tsok+3-3(跟上次 commit 比)解釋還原復原Bash確定刪除取消Edit● src/app.ts(續)
Bash● src/app.ts(續)Bash● src/app.ts(續)… 還有 3 行 diff 太長沒顯示(這個檔案的 diff 太長,先收合上面幾個檔案再看它)Bash● src/app.tsok+3-3(跟上次 commit 比)解釋還原復原Bash確定刪除取消Edit● src/app.ts(續)Bash● src/app.ts(續)Bash● src/app.ts(續)… 還有 3 行 diff 太長沒顯示(這個檔案的 diff 太長,先收合上面幾個檔案再看它)Bash… 還有 3 個檔案沒列出來● src/app.tsok+3-3(跟上次 commit 比)解釋還原復原Bash確定刪除取消Edit● src/app.ts(續)Bash● src/app.ts(續)Bash● src/app.ts(續)… 還有 3 行 diff 太長沒顯示(這個檔案的 diff 太長,先收合上面幾個檔案再看它)Bash