Guardrails
341 mods. Block, rewrite or audit tool calls before they run.
- spike-probe 0.1.0 Reports every hook event to a local HTTP receiver and takes permission, abort and submit commands from it. 0
- clef-guard 0.3.0 Has Cloudflare's Clef decision model rate each Bash command's risk, and asks you itself, in any permission mode, before running one it finds risky. 0
- work-ledger 0.1.0 ターンごとのトークンとツール呼び出しを JSONL に記録し、/note で作業メモを残す 0
- blast-radius 0.1.0 Hält gefährliche Bash-Befehle an (rm -rf, git reset --hard, git clean, force-push …), zeigt was sie anrichten würden, und fragt vor dem Ausführen 0
- shell-edit-guard 0.1.0 Blocks Bash commands that write files (inline scripts, sed -i, redirects, tee) and points the model at Edit/Write instead 0
- clean-code 0.1.1 Setzt Clean-Code-Regeln als Hooks um: Lint-Hinweis nach Code-Änderungen, Referenzordner mit Quellcode der Bibliotheken und Schutz für CLAUDE.md, AGENTS.md und Skills. 0
- guardia-llaves 1.1.0 Tapa las llaves y contrasenas antes de que Claude las vea, y le prohibe imprimir archivos de secretos. 0
- right-tool 0.1.0 Stop Claude using cat, grep, find, and sed in Bash when the Read, Grep, and Glob tools fit. Each redirected call saves a permission prompt and keeps raw shell output out of context. 0
- circuit-breaker 0.1.0 Stop Claude from retrying the same failing shell command over and over. After N identical failures the next attempt is held, and you choose: stop, or try once more. 0
- fence 0.1.2 Limit which paths Claude may edit in a project with one /fence command. Edits outside the fence are refused with a reason Claude can act on. 0
- pkg-guard 0.1.1 Hold npm, pnpm, yarn, pip, uv, and cargo installs of packages that don't exist, are brand new, or are barely downloaded, with the registry facts in the question. Catches hallucinated and typosquat packages before they land. 0
- red-green 0.1.1 Run the project's tests after any turn that edited files, print pass or fail under Claude's answer, and send the failure back to Claude with one /fix command. 0
- standup 0.1.0 Your day, written for you. Every turn is logged; /standup turns today's work across every session on the machine into a three-bullet update, or a Markdown file. 0
- style-cop 0.1.0 Enforce the style rules Claude keeps ignoring: banned words and phrases, a comment-density cap on added code, and files that must not gain comments. Rules live in .claude/style-cop.md and are both shown to Claude and enforced on edits. 0
- trust-but-verify 0.1.0 Check what Claude claims against what it ran. When an answer says the tests pass, the build is clean, or something was committed, a line under it says whether a matching command actually ran this turn and succeeded. 0
- undo-agent 0.1.1 Undo the file edits a subagent made. /rewind restores your own turns, but not a subagent's edits; this snapshots them and puts the files back with one command. 0
- cmd-guard 0.2.4 Blocks destructive shell commands (rm -rf /, force push, DROP TABLE...) 0
- watchtower 0.1.0 One line above the prompt showing what your guard mods are doing: the fence, pins, the breaker threshold, the test command and its last result, and every call refused this session. 0
- shared-repo-guard 0.1.0 For repos where several AI agents (or you and an agent) work in the same folder: stops secret values from leaving your .env, pushes to public remotes, and git commands that would wipe work this session did not write. 0
- jev-guard 0.1.0 Jev gates Bash, Write and Edit, and screens Read and Bash results for injected instructions 0
- ask-jev-file 0.1.0 Ask Jev a yes/no, a choice or a score about one file without reading it 0
- ask-jev-files 0.1.0 Ask Jev the same typed questions of many files in parallel, then pick the one to open first 0
- safety-net 0.1.0 Blocks catastrophic shell commands and asks before risky ones or edits to secret files. 0
- session-journal 0.1.0 Logs what you did with Claude across sessions; /journal and an AI-written /standup. 0
- sdk-sync 0.2.0 After an SDK release (v* tag): /release-check gathers what changed and asks Claude for a read-only audit of the sibling SDKs, docs and examples. Never acts while you work. 0
- handily-quiet-items 0.4.0 One short row in place of each tracker write in the transcript. 0
- handily-simple-view 0.4.0 One short row for each Bash, Edit, Write, Read, Grep and Glob call, with buttons to open and copy its output, /simple to switch it and /simple show to print a call in full. 0
- house-style 0.1.1 Hold documents Claude writes to your house style: no dashes, British spelling, none of your banned words. It enforces the author's own style: see the note below the table. 0
- released-objects 0.2.0 Flag SAP objects in ABAP code that are not released, deprecated or have no API, with SAP's successor, using SAP's own release lists. It flags, never blocks. 0
- secret-guard 0.1.0 Stops Claude from reading or editing .env files, private keys and credential files, including through symlinks and shell commands 0