Guardrails
341 mods. Block, rewrite or audit tool calls before they run.
- prod-guard 1.1.1 Stops production-affecting commands (terraform apply, kubectl on prod, DROP TABLE) unless explicitly allowed. 1
- path-jail 1.1.1 Allows writes only inside the project root, resolving symlinks and .. tricks. 1
- curl-pipe-guard 1.1.1 Blocks piping downloaded scripts straight into a shell. 1
- lockfile-guard 1.1.1 Prevents hand-editing lockfiles; they must change through the package manager. 1
- recent-files 1.0.1 /recent lists the files read and edited in this session, newest first. 1
- no-skip-tests 1.1.1 Blocks Claude from silencing tests with .skip, .only, xit or skip markers. 1
- todo-tracker 1.1.1 Notices every TODO, FIXME and HACK Claude adds and lists them at turn end. 1
- no-any 1.1.1 Flags new any types, @ts-ignore and eslint-disable comments as Claude writes them. 1
- file-size-watch 1.1.1 Warns when an edited file grows past a size that hurts readability. 1
- test-first 1.1.1 A TDD mode: no production code changes until a test has been written or changed. 1
- bash-history 1.0.1 /bash-history lists recent shell commands Claude ran, with exit status and duration. 1
- web-trail 1.0.1 /sources lists every page Claude fetched or searched this session. 1
- license-header 1.0.0 Adds your license header to every new source file Claude creates. 1
- i18n-guard 1.1.1 Flags hard-coded user-facing strings in UI components. 1
- migration-guard 1.1.1 Prevents editing database migrations that already exist; write a new one instead. 1
- next-guard 1.1.1 Flags missing or needless "use client" and server-only imports leaking into client components in Next.js. 1
- venv-guard 1.1.1 Blocks pip install outside an active virtualenv so system Python stays clean. 1
- go-mod-tidy 1.0.0 Runs go mod tidy when Claude changes Go imports, so go.mod and go.sum stay in sync. 1
- strict-types 1.0.0 Adds declare(strict_types=1) to new PHP files and from __future__ import annotations to new Python files. 1
- env-example-sync 1.1.1 Keeps .env.example in sync with the environment variables your code actually reads. 1
- docker-lint 1.1.1 Flags Dockerfile smells: :latest tags, running as root, apt without cleanup, ADD instead of COPY. 1
- port-check 1.1.1 Before a dev server starts, tells you if the port is already taken and by which process. 1
- docker-prune-guard 1.1.1 Blocks docker system prune -a --volumes and volume deletion that can wipe local databases. 1
- sql-safety 1.1.1 Flags UPDATE and DELETE without WHERE in .sql files and in queries inside your code. 1
- seed-guard 1.1.1 Blocks database seed, reset and drop commands unless DATABASE_URL points at your own machine. 1
- n-plus-one-hint 1.1.1 Spots database queries inside loops, the classic N+1 problem, as Claude writes them. 1
- migration-namer 1.0.1 Gives new migrations consistent, descriptive, timestamped names. 1
- backup-before-migrate 1.1.1 Dumps your local database before every migration so a bad one is one command away from undo. 1
- a11y-guard 1.1.1 Flags accessibility misses as Claude writes UI: images without alt, unlabeled buttons, clickable divs. 1
- heavy-asset-warn 1.1.1 Warns when large images, videos or fonts are added to the project. 1