Guardrails
341 mods. Block, rewrite or audit tool calls before they run.
- pocket-pet 0.6.2 바탕화면에 사는 픽셀 펫 클로: Claude가 생각하고, 도구를 쓰고, 허락을 기다리고, 일을 마칠 때마다 반응합니다. 마우스로 끌어 옮길 수 있습니다 0
- gcloud-guard 0.1.0 Holds gcloud and gsutil commands that would create, change or delete cloud resources, shows the account, project, location and the current state of the targets, and asks you to Proceed or Cancel. 0
- secret-guard 0.1.0 Keeps API keys, cloud credentials and other secrets out of what is sent to the model: every text that enters the conversation is scanned and each match is replaced with a meaningful placeholder such as <google api key>. 0
- guard 0.1.0 Blocks destructive shell commands and access to secret files before they run, anywhere in a compound command 0
- cs-radio 0.1.0 Counter-Strike 1.6 radio calls for Claude Code: 'Fire in the hole' on deploys, 'Bomb has been defused' when a long turn lands. /radio to toggle. 0
- query-guard 0.2.3 Asks before Claude runs destructive or slow-looking SQL through a DB CLI: DELETE, UPDATE without WHERE, DROP, TRUNCATE, full scans and cartesian joins. 0
- autopilot 0.2.3 Works through a GOALS.md goal tree turn after turn, with locked checks, its own check verdicts, lessons that carry over, safety guards and a progress band 0
- ghost-proc-guard 0.1.0 Stops Claude from starting a second copy of your dev servers on the next free port (monorepos and worktrees included), tracks the servers it starts, and stops leftovers from a /procs pane. 0
- delete-guard 1.0.0 Holds recursive deletes (rm -rf, Remove-Item -Recurse, rmdir /s, git clean -f), shows what would go, and offers move-to-trash with /undo-delete, delete, or refuse. Leaves a receipt. 0
- house-rules 0.1.0 Quietly enforces Paddy's writing rules: no em dashes in chat, files or outbound messages, and a nudge when replies run long. 0
- dependency-bouncer 0.2.0 Vets npm and PyPI packages before they install: blocks hallucinated, typosquatted and brand-new install-script packages, flags risky ones 0
- safety-guard 0.1.0 Blocks destructive shell commands and access to secret files (.env, SSH keys, cloud credentials). 0
- blast-radius 0.1.0 Holds risky Bash commands, shows what they would change, and waits for Proceed or Cancel. 0
- claw-guard 1.0.0 Claw mod: asks for your OK before any connector action that sends, deletes, pays, publishes or shares (fails closed, also when nobody is there to answer), and flags prompt-injection text inside emails, pages and files. 0
- auto-handoff 0.3.0 Hands the conversation off once the context passes a threshold (40% of windows over 200k tokens, 50% of smaller ones): a dedicated turn writes the handoff and the durable knowledge it names into an OKF bundle at .auto-handoff/, then the context is cleared and the work continues from the handoff 0
- dieta 0.1.0 Evita que el contexto se infle: frena lecturas de archivos enormes y recorta salidas gigantes de comandos 0
- subagentes 0.2.0 Los subagentes usan Sonnet por defecto; Claude recibe la regla para elegir Opus o Fable cuando toca 0
- auth-guard 0.1.0 Spots an expired CLI login in tool output and offers a Login button that signs in and retries. 0
- secret-guard 0.1.2 Stops Claude from writing API keys, private keys and other secrets into your files 0
- shell-guard 0.1.0 Windows shell guard: fixes backslash drive paths in Bash, blocks quote-eating node -e / heredoc patterns, and catches PowerShell/Bash syntax sent to the wrong shell 0
- ding-dong 0.1.0 回合跑超過一分鐘才結束時,發一則可愛的 macOS 通知叫你回來;/ding 可以預覽 0
- secret-guard 0.1.0 金鑰守門:遮蔽 prompt 和工具輸出裡的 API key,並擋下讀寫 .env、私鑰這類檔案;/guard 看狀態 0
- blast-radius 0.1.0 Holds destructive shell commands, shows what they would delete or overwrite, and asks Proceed or Cancel. 0
- session-journal 0.1.0 Writes a markdown log of every prompt, changed file and command to .claude/journal, with a /standup summary. 0
- secret-guard 0.1.0 Blocks reads of .env files and printing of API keys, with a red warning above the prompt. 0
- house-style 0.1.0 Enforces the no-em-dash rule: a system prompt section, a reminder to the model after a write that adds one, a toast when a reply uses one 0
- zsh-safe 0.1.0 Quotes glob flags zsh would expand (--include=*.ts) and keeps a grep that finds nothing from failing the command 0
- remote-guard 0.1.0 Asks before a destructive command runs on another machine over ssh (restarts, deletes, kills, reboots) 0
- dock 0.1.0 Container stacks per worktree: a pixel-art pane of every compose stack with its memory and worktree, orphans whose worktree is gone, and a guard that asks before booting another stack when memory headroom is low. 0
- tool-oneline 0.1.0 Folds tool calls in the scrollback into one line per call, or one line per run of calls, with no result block 0