Guardrails
197 mods. Block, rewrite or audit tool calls before they run.
- zsh-safe 0.1.0 Lets Bash commands written for bash run under zsh: unmatched globs, leading =, and a missing timeout 16
- lemo-guard 0.2.0 限时:Claude 单轮工作超时自动中止 · 等你确认的时间不计 · 默认关闭,在「安全」页开启 / Time limit: stops Claude when a turn runs over time · time waiting for you does not count · off by default, switch on in Safety 14
- lemo-todo 0.2.0 笔记:在面板记下笔记 · 压缩后自动摘要(Haiku)默认关闭,在「安全」页开启 / Notes: keep notes in the panel · Auto summary after compaction (Haiku) is off by default, switch on in Safety 14
- lemo-journal 0.2.0 记录:面板显示每轮统计 · 日志和自动分类默认关闭,在「安全」页开启 / Journal: per-turn stats in the panel · Log and Auto tags are off by default, switch on in Safety 14
- lemo-lot 0.2.0 抽签:给 Claude 增加抽签工具 draw_lot,抽到的签显示为签文卡片 · 默认关闭,在「安全」页开启 / Lots: adds a draw_lot tool for Claude and shows drawn lots as fortune cards · off by default, switch on in Safety 14
- lemo-assistant 0.2.0 助手:只读子 agent(Haiku),写三行周报 · 点按钮才派;「Claude 可派助手」默认关闭,在「安全」页开启 / Assistant: a read-only subagent (Haiku) that writes a three-line report · sent only when you press its button; "Claude can send the assistant" is off by default, switch on in Safety 14
- collision-guard 1.0.0 Asks before Claude edits a file another open chat changed in the last 30 minutes: Proceed, Move to a worktree, or Cancel (/guard) 8
- hello-mod 0.1.0 Starter mod: logs each tool call and blocks Bash commands that contain rm -rf. 6
- self-command 0.1.0 For mod development: lets the model run a slash command in its own session, such as /reload-plugins after a plugin update, and read the output as the next prompt. 6
- ask-autopick 0.3.1 Picks the recommended option of a question that waited unanswered for a set time, so a session you left does not stop. Off until you turn it on. 6
- gemini-advisor 0.3.2 Gives the model a Gemini advisor tool it calls by itself: Gemini reads the whole conversation and the model's message and answers with a second opinion. Off until /gemini-advisor on; gemini-core holds the key, tier, model and thinking level. 6
- council 0.1.4 Asks a council of models about a hard problem, when the model calls its tool or you run /council <question>: Claude models, and Gemini models when gemini-core has a key, answer in parallel, and the model of the session writes one verdict from their answers. 6
- flaky-memory 0.4.1 Remembers which tests failed on which code, and tells the model when a failing test has both passed and failed on the same code, so it runs the test again instead of changing code. 6
- shot-inline 0.3.1 Draws each PNG or JPG the model saves or reads under its tool row: pixels in kitty and Ghostty, quadrant block cells in every other terminal. 6
- edit-loop 0.5.2 Adds a note to the fifth edit of one file in one turn, so the model re-reads the code path and states the root cause instead of trying again. 6
- ua-fallback 0.2.2 After a curl or wget an automated-client filter answered 403 or 429, gives the model the browser User-Agent to retry with, and the two cases where it must not. 6
- storage-guard 0.1.4 After an edit that keeps browser data in localStorage or sessionStorage, names each line, so the model stores the data in a cookie instead. 6
- tool-coach 0.1.1 Stops the model from repeating a tool call that just failed with the same input, until a file or command has changed something. 6
- probe-runner 0.1.0 For mod development: runs a live check of plugins in a fresh Claude Code session in tmux, types the steps one by one, collects the pane and the transcript, then deletes the temp directory, its transcripts and the inline store files. 6
- dice-tool 0.1.0 Example: registers a tool the model can call and answers it 6
- risky-mod 0.0.1 Synthetic fixture: every red flag on purpose. Never install. 6
- secret-guard 0.1.2 Keeps secrets out of the conversation: hides API keys and private keys before the model or the transcript sees them, and blocks reads of credential files and commands that print secrets 5
- compact-keeper 0.1.1 Saves each compaction's summary, with the files edited before it, to ~/.claude/handoffs so the context before /compact can be recovered 5
- loop-guard 0.1.0 Tells the model, out of the user's sight, to stop when the same call fails twice with the same error 5
- mesimon 1.0.0 mesimon's bridge into a Claude Code session it started: reports the session's events to the board, refuses writes to the board's files, serves the board's tools and carries the board's commands back. Laid and loaded by mesimon; nothing to install. 4
- prod-guard 0.1.0 Holds production deploys and database commands in a dialog that shows what would ship 4
- verify-status 0.1.0 Counts files edited since the last passing test run for the status line 4
- forged-consent-sample 0.0.1 Self-hostable, model-agnostic AI workstation and coding harness. Run any model (frontier or local) behind one OpenAI-compatible surface, run a gated coding agent over your folders, and keep a proof receipt you can re-check offline. Verified-inference loop, receipt-wrapped tool calls, composed lan... 3
- unowned-dirty 0.1.0 Warns when a git add/stash/checkout/restore/reset may sweep dirty files this session did not write (shared checkouts have several agents). A toast for the person, a note in the model's context; never blocks. Port of the pi extension of the same name. 3
- permissive-policy-sample 0.0.1 Self-hostable, model-agnostic AI workstation and coding harness. Run any model (frontier or local) behind one OpenAI-compatible surface, run a gated coding agent over your folders, and keep a proof receipt you can re-check offline. Verified-inference loop, receipt-wrapped tool calls, composed lan... 3