Guardrails
335 mods. Block, rewrite or audit tool calls before they run.
- blast-radius 0.1.0 See what a risky command would change before it runs. 2
- jev-context 0.1.2 Jev-scored context pruning for Claude Code through OpenRouter: at compaction every tool call and result is scored by TypeSafe's Jev decision model, stale ones are dropped or truncated, everything kept stays verbatim. An optional gate truncates oversized tool outputs as they arrive. 1
- blast-radius 0.1.0 See what a risky command would change before it runs. 1
- reins-probe 0.1.0 Probe for docs/mods-probe.md: how the mod engine treats a slow, failing or dialog-opening tool.call hook, and where it sits against settings hooks. 1
- review-gate 0.1.0 The review gate as a tool.check function hook. Every shell call is decided in process, so the non-commit calls -- almost all of them -- cost no subprocess at all, and a blocked commit can be put to you as a question instead of refused outright. The decision itself is still bin/review-gate, run on... 1
- bouncer 0.1.0 mod + skill Bouncer for Claude Code: enforce condition-based markdown guardrail rules on tool calls — deny or annotate any call whose content matches, instead of file-path-only rules. 1
- sensitive-file-guard 0.1.0 Blocks Read, Write, Edit, Grep, Glob and Bash calls that touch .env files, private keys and credential stores. 1
- bash-guard 1.0.0 A seatbelt for YOLO mode: blocks catastrophic shell commands (rm -rf ~, mkfs, dd to a disk, fork bombs) and asks before risky ones (force-push, reset --hard, DROP TABLE, curl | sh), even with permissions bypassed. 1
- injection-guard 1.0.0 Defuses prompt injection in tool output: strips invisible Unicode that hides text from you but not from the model, and flags web pages, files and command output that carry instructions aimed at Claude. 1
- slopsquat-guard 1.0.0 Stops Claude from installing hallucinated or typosquatted packages: every npm, pip, uv, poetry, cargo and gem install is checked against its registry first. Packages that don't exist are blocked; brand-new, barely used or lookalike packages ask you first. 1
- command-explainer 1.0.0 Explains a shell command in one plain-English line, with its risk, right where you approve it, so you know what you're saying yes to. 1
- open-file-guard 0.1.0 Before Claude uses a Word, Excel or PowerPoint file you have open, asks you to close it instead of letting the write fail. 1
- ttsr-rules 0.1.0 oh-my-pi TTSR rules: a regex rule denies the tool call that would break it, with the rule as the reason; a question rule is judged after each turn. 1
- peek 0.1.1 Images in the terminal: Claude shows the pictures it makes or finds inline, as real pixels in kitty and Ghostty and as a colored-block preview elsewhere 1
- test-guard 0.1.0 Blocks edits that make tests pass by weakening them: new skip/only markers, fewer assertions, a gutted test file, or deleting a test file. 1
- review-lint 0.1.0 Hands Claude a cache-review checklist or test rules when an edit adds a cache or a brittle test assertion 1
- guard-widget 1.0.0 A tally of this session's permission checks: what was allowed, what you were asked about and what was denied. 1
- blast-radius-ko 1.2.0 Anthropic의 blast-radius 샘플을 한글화하고 위험 명령 목록을 넓힌 k-mods 수정판. rm -rf, git reset --hard, force push, prisma/psql/docker의 파괴적인 명령을 멈추고 영향 범위를 먼저 보여줍니다. 1
- status-ko 1.1.0 작업 중 줄을 지금 하는 일로, 턴이 끝난 줄을 모델·시간·도구·캐시 한 줄로 한국어로 보여줘요 1
- publish-guard 0.5.1 Asks before a package is published: npm, pnpm, yarn or bun publish, cargo publish, twine upload, gem push, poetry or uv publish. Dry runs pass. 1
- prod-db-guard 0.5.1 Asks before destructive SQL runs in a command: TRUNCATE, DELETE or UPDATE with no WHERE. 1
- lockfile-guard 0.5.1 Asks before a lockfile is written or edited by hand; the package manager should change it. 1
- ci-config-guard 0.5.1 Asks before Write or Edit changes CI config: .github/workflows, .gitlab-ci.yml or .circleci/config.yml. 1
- cron-guard 0.5.1 Asks before scheduled jobs or services are wiped or stopped: crontab -r, crontab replaced from stdin or a file, launchctl unload or bootout, systemctl stop, disable or mask. 1
- curl-pipe-guard 0.5.1 Asks before a download is piped into a shell or interpreter (curl | sh, wget -O- | bash, bash <(curl ...)). 1
- env-exfil-guard 0.5.1 Asks before a command prints your environment, echoes a secret variable or sends local data to a remote host. 1
- subagent-limits 0.3.1 mod + skill Keeps subagents small: tells the main agent how to size and split work, asks a growing subagent to checkpoint, and refuses its tools past a hard limit so a fresh agent takes over 1
- secret-guard 0.3.2 Hides secrets in tool results before Claude reads them: the secret values of every .env and .env.* from your session's folder up to the drive root, and anything that looks like a secret (KEY=VALUE under a secret name, passwords in URLs, private keys, JWTs, AWS keys, Kubernetes Secrets); tells Cla... 1
- env-guard 1.1.1 Protects .env files, SSH keys and credential stores from being read or modified. 1
- rm-rf-guard 1.1.1 Blocks catastrophic shell commands like rm -rf /, mkfs, dd to disks and chmod -R 777. 1