Guardrails
341 mods. Block, rewrite or audit tool calls before they run.
- url-allowlist 1.1.1 Restricts WebFetch to the domains you allow. 1
- scope-lock 1.1.1 /scope locks Claude to the files you name; edits outside the scope are blocked. 1
- loop-breaker 1.1.1 Stops Claude when it repeats the same failing command three times and suggests a different approach. 1
- edit-limit 1.1.1 Asks for confirmation when a single turn tries to modify more than N files. 1
- agent-presets 1.0.2 Ready-made subagents for focused jobs: debugger, test writer, doc writer and migrator. 1
- why-log 1.0.1 Records why each file was changed; /why shows the reasoning behind any file's edits. 1
- skill-tracker 1.0.1 Tracks which languages and tools you've worked with each week. 1
- license-checker 1.1.1 Warns when a dependency with a copyleft license (GPL, AGPL) lands in a permissively licensed project. 1
- tracker-guard 1.1.1 Blocks adding analytics and tracking SDKs that haven't been approved. 1
- copyright-guard 1.1.1 Flags pasted code that carries someone else's license or copyright header. 1
- leak-hint 1.1.1 Flags event listeners, intervals and subscriptions created without cleanup. 1
- net-retry 1.1.1 Automatically retries commands that failed because of a temporary network error. 1
- disk-guard 1.1.1 Warns when the disk is nearly full before builds, installs and docker pulls. 1
- regression-guard 1.1.1 Remembers which tests passed at the start of the session and warns if any of them now fail. 1
- watch-mode-guard 1.1.1 Blocks watch-mode and never-ending commands run in the foreground, where they'd hang the turn. 1
- guardian 1.0.2 One security policy for every guard mod — permissive, standard or strict — plus a project safety score. 1
- smart-compact 0.2.6 mod + skill The agent compacts its own context between tasks, with a focus it writes for the compactor, and carries on by itself 1
- safety-net 0.1.0 Blocks destructive tool calls before they run (force pushes, rm -rf outside the project, DROP TABLE, terraform destroy, writes to .env and keys, ...) and explains why. 1
- ping 0.1.0 Plays a chime and shows a toast when a long turn finishes (or Claude is waiting on your approval), so you can walk away. 1
- pre-pr-claims-check 0.1.0 Refuses gh pr create and gh pr edit while the PR's title, its body or the branch's added Markdown lines hold a file:line citation, a placeholder or a count spelled out in words, listing each one. 1
- env-guard 0.1.0 Asks you before Claude reads a .env or key file, and refuses when no one is there to answer. 1
- bash-quoting-rescue 0.1.0 Before a shell command runs, parses it with the shell's own parser and refuses one that does not parse, such as an unclosed quote or heredoc, so none of it runs. 1
- chrome-tab-self-heal 0.1.0 When a Claude in Chrome tool says its tab is gone, tells Claude to fetch the current tab IDs before trying again. 1
- blast-guard 0.1.0 Holds risky shell commands for a yes/no with a dry-run report, blocks Python heredocs carrying backslash escapes, and caps concurrent subagents at 4. 1
- delete-guard 0.3.0 Stops Claude before it deletes or overwrites files: a side panel lists every folder and file at stake, with Cancel and Allow buttons 1
- processes 0.1.0 Sidebar section listing the background and detached processes Claude starts, with their ports and a kill button 1
- pm-guard 0.1.0 Steers npm/npx/yarn to the package manager the repo's lockfile names (bun or pnpm), bun where there is none 0
- varredura-push 1.0.0 Antes de git push ou publicação pelo gh, procura chave, token e senha nos commits que vão subir (gitleaks, com regras de reserva) e barra o envio se achar 0
- memory-guards Refuses the footgun commands Claude's memory notes warn about, with the reason and the safe alternative 0
- jev-coding 0.1.0 Remind the agent to run jev_decide at decision points and classify its edits with Jev before it stops 0