Guardrails
335 mods. Block, rewrite or audit tool calls before they run.
- secret-guard 0.1.8 Keeps secrets out of the conversation: hides API keys and private keys before the model or the transcript sees them, and blocks reads of credential files and commands that print secrets 5
- compact-keeper 0.1.1 Saves each compaction's summary, with the files edited before it, to ~/.claude/handoffs so the context before /compact can be recovered 5
- loop-guard 0.1.0 Tells the model, out of the user's sight, to stop when the same call fails twice with the same error 5
- guardrails 0.1.1 Clickable safety rules with presets: block rm -rf, force-push, destructive git, secret files, sudo, installs, network; lock Claude to the project folder or read-only; add your own block patterns. 5
- loop-breaker 0.1.1 Notices when Claude is going in circles (the same command failing again and again, the same code rewritten over and over) and tells Claude to step back and rethink, and tells you too. 5
- mesimon 1.0.0 mesimon's bridge into a Claude Code session it started: reports the session's events to the board, refuses writes to the board's files, serves the board's tools and carries the board's commands back. Laid and loaded by mesimon; nothing to install. 4
- reread-guard 0.2.0 Stops Claude re-reading a file it already read in this conversation, with Read or a plain cat, sed -n, head, tail or Get-Content, when the file has not changed since; a deliberate second attempt still goes through. 4
- collision-guard 0.1.0 Asks before Claude edits a file another chat on this machine changed in the last 30 minutes. Each chat keeps its own small ledger; no model calls, no network. 4
- write-guard 0.1.0 Steers Claude to Edit instead of rewriting an existing file in full with Write: the first rewrite in a conversation goes through with a one-line note, a later one is held back once; a deliberate retry still goes through. 4
- loop-guard 0.1.0 Holds back a shell command once when the exact same command already failed twice in a row, and tells Claude to change approach; retrying it still goes through. 4
- forged-consent-sample 0.0.1 Self-hostable, model-agnostic AI workstation and coding harness. Run any model (frontier or local) behind one OpenAI-compatible surface, run a gated coding agent over your folders, and keep a proof receipt you can re-check offline. Verified-inference loop, receipt-wrapped tool calls, composed lan... 3
- unowned-dirty 0.1.0 Warns when a git add/stash/checkout/restore/reset may sweep dirty files this session did not write (shared checkouts have several agents). A toast for the person, a note in the model's context; never blocks. Port of the pi extension of the same name. 3
- permissive-policy-sample 0.0.1 Self-hostable, model-agnostic AI workstation and coding harness. Run any model (frontier or local) behind one OpenAI-compatible surface, run a gated coding agent over your folders, and keep a proof receipt you can re-check offline. Verified-inference loop, receipt-wrapped tool calls, composed lan... 3
- dotclaude-jev 0.27.0 mod + skill Gets a second opinion from TypeSafe Jev, a decision model, for a yes or no check, a pick from options, or a rating. Needs `TYPESAFE_API_KEY`. 3
- codecraft 0.4.1 A Minecraft-inspired HUD for Claude Code: hearts for context, armor for safety nets, XP for verified work, and 60 advancements that persist across sessions 3
- clawd 0.3.0 Clawd, the Claude mascot, thinks, types, runs and celebrates beside the thinking line, a little differently each turn 3
- pmap-code 1.3.6 mod + skill Real-time codebase architecture analysis and visualization for ProvenMap Portal. Analyzes codebases across multiple languages, detects tech stacks, identifies component relationships, and syncs to ProvenMap for collaborative architecture boards. Supports server-defined insight analysis skills. 3
- dotclaude-modder 0.27.0 mod + skill Mods a PC game that you own: engine recon, game internals, fal assets, sprites, in-game tests, showcase videos, and field notes. Based on universal-modder by Rehan. 3
- sasy-guard-mod 0.1.0 SASY policy enforcement for Claude Code as a mod: checks every tool call against the policy from inside Claude Code and shows each decision in the session 3
- machine-guard 0.1.0 Puts every command that changes the machine in front of the user before it runs 2
- harness-scope 0.1.5 Turn global skills, rules, agents and tools on or off per repo with named profiles 2
- scope-guard 0.1.0 Notices when Claude drifts outside your request. Clear drift waits for your answer in a question dialog; milder drift is flagged above the prompt with a pull-back key. 2
- samurai-dojo 0.4.0 A Claude samurai cuts down a Codex, Gemini, or ChatGPT foe for every tool call, and meditates, trains, and duels between them through four seasons. 2
- zed-clear-guard 0.2.0 Blocks /clear when Claude Code runs in a Zed terminal 2
- game-earcons 0.2.0 8-bit sound cues on macOS, Windows and Linux: a permission prompt or question waiting on you, a long turn finished, an error, a guard refusing a call, a save 2
- game-answer-memory 0.2.0 When Claude asks a question it asked before in this project, the option you chose last time is marked ★ 지난번 선택 2
- ultramod 1.0.8 The best all-in-one mod pack for Claude Code: a usage limits and context HUD, a guard with undo for rm -rf and git reset --hard, .env and secret protection, and a receipt for every turn. 2
- mr-banner 0.1.1 A colored card with a link under each MR/PR created, merged, approved or reviewed 2
- mem-guard 0.2.0 Bash memory rules: Node commands run in claude-cmd.slice, and runs that would starve the machine are refused 2
- output-trimmer 0.1.0 Huge Bash/PowerShell outputs without the context bill: Claude gets the head and tail, the full text goes to a file it can open. 2