Guardrails
341 mods. Block, rewrite or audit tool calls before they run.
- subagent-effort 0.2.1 Run each subagent on any model (gpt-6, grok-4.7, ...) at any reasoning effort, through model and effort parameters on the Agent tool 0
- blast-radius 0.1.0 See what a risky command would change before it runs. 0
- blast-radius 0.1.0 See what a risky command would change before it runs. 0
- swamp 0.1.0 Gives Claude a tool that runs a swamp workflow and returns its result. 0
- slop-detector 0.1.0 Catches slop as Claude writes it: refuses a file edit that replaces code with a '... rest of the code' placeholder, and tracks TODO stubs, not-implemented throws, debug prints, @ts-ignore and other leftovers in a band above the prompt and a /slop pane. 0
- pin-everywhere A pinned session keeps its Remote Control on (reconnected after app restarts) once machine-tag has put the machine icon in the title, so it shows by name and icon on every other computer and the phone; unpinning turns it back off 0
- blast-radius 0.2.0 Faengt gefaehrliche Shell-Befehle (Bash und PowerShell) ab, zeigt Befehl und Folge und fragt vor dem Ausfuehren nach; Standard aus, mit /ward fuer die Sitzung einschalten 0
- image-peek 0.1.1 Previews pasted images and images Claude sends, with Open and Reveal buttons (Explorer on WSL/Windows, Finder on macOS) 0
- context-saver 0.1.0 Refuses a main-agent Read over the token cap so a subagent reads the file and reports back. 0
- lint-guard 0.1.0 An ordinary eslint wrapper: lints after every Write/Edit, a /lint command, and a band showing current findings. 0
- pr-proof 0.2.9 mod + skill Shows the proof behind a PR under the reply that names it: checks, before/after screenshots, what was not checked, with Open and Reveal buttons 0
- guardrails 1.1.0 Stops risky shell commands before they run: killing ports owned by Docker containers, printing secrets from the environment, rewriting your kubeconfig, and asks before kubectl writes on production contexts. 0
- blast-radius 0.1.0 Before a shell command deletes or discards files, shows exactly what it would hit and waits for Cancel or Proceed. 0
- greve-generale 0.2.0 Les outils de Claude se mettent en grève au hasard, pour des raisons très françaises 0
- done-gate 0.1.0 Claude cannot say "done" while the tests fail: a Stop gate runs your test command after every turn that changed files, and existing test files are locked so they cannot be patched green. 0
- block-destructive-commands 0.2.0 Denies Bash commands that match destructive patterns (recursive rm on roots, force push, hard reset, destructive SQL, disk formatting) before they run. A tool.call hook with a Bash matcher that returns { deny } without calling next. 0
- dense 0.1.1 A Claude Code plugin that folds everything per turn. 0
- collision-guard 0.1.0 Предупреждает, если файл недавно менял другой чат Claude Code 0
- nixie-hold-promise 0.0.0 Spike: a tool.call hook that holds a call on a promise of its own 0
- publish-guard 1.0.0 Stops Claude from typing private terms into the browser or writing them into your publishing files, and keeps a log of what it blocked 0
- toyon-tally 0.1.0 Counts tool calls and adds a /tally command: the smallest mod, for the Claude integration test 0
- buddy 0.11.1 Buddy: a pet sidekick for Claude Code. Sees all your chats, keeps your to-do list when Claude needs you, covers your secrets while you film, runs a team of helper agents and background chats, manages your skills, warns before a cold-cache message, and asks before sends and paid calls 0
- tailscale 0.3.2 Lets Claude query and modify the tailnet through the Tailscale API, using TS_API_KEY. 0
- approve-blocked 0.1.0 Retries an auto-mode-blocked call up to three times so Claude Code's own permission prompt (and Moshi) can ask you. 0
- compact-tail 0.1.1 Automatic compaction summarizes only the older part of the conversation and keeps the latest part word for word; a reopen tool brings back anything summarized, from a local archive 0
- ops-rules 0.1.0 Rules for the session started with LIFE_ROLE=ops: it decides and does not measure (analysis commands need the person's OK). 0
- soundtrack 0.1.0 A soft soundtrack for Claude Code: a rising chord when Claude starts, a quiet tick while tools run, a chime when it's done. 0
- pkexec-guard 0.2.0 Routes `sudo` in Bash calls to a password prompt the person can answer: pkexec on a Linux desktop, an osascript administrator dialog on macOS, and Windows sudo's UAC prompt on Windows. 0
- cortex-guard 0.1.2 Two rules no settings hook enforces, refused at the tool call: wiki pages and their generated ADR mirrors are written only through the Cortex wiki tool, and every git worktree lives at <repo>/.claude/worktrees/<name>/ (one created there is registered with disk_hygiene.py). 0
- zetetic-autopilot 0.1.1 Automatic effort and model: every request runs at the effort its grade calls for (zetetic-genius) and the tool loop steps down the ladder; subagents run on the family their type and the turn's class call for (haiku, sonnet, opus, fable); under quota or context pressure everything goes one notch d... 0