admin-capability-lockdown 0.2.0
Organization control mod: withholds the http and process nouns from $ so no plugin beneath it can reach the network or spawn processes, refuses user-tier plugins by name allowlist or by the $ calls their source declares, and withholds the Bash tool (shellPolicy "deny", default) or, in "guardrail"...
Install
git clone https://github.com/davila7/claude-code-templates.git claude --plugin-dir claude-code-templates/cli-tool/components/mods/enterprise/admin-capability-lockdown
Run in a terminal. Claude Code loads the mod from that folder for the session.
Hooks into
- Tool calls