Guardrails
208 mods. Block, rewrite or audit tool calls before they run.
- session-relaunch 0.3.2 /relaunch restarts this Claude Code session in a new terminal tab with --resume <id>, so MCP servers added since it started are loaded. 0
- pocket-pet 0.6.2 바탕화면에 사는 픽셀 펫 클로: Claude가 생각하고, 도구를 쓰고, 허락을 기다리고, 일을 마칠 때마다 반응합니다. 마우스로 끌어 옮길 수 있습니다 0
- gcloud-guard 0.1.0 Holds gcloud and gsutil commands that would create, change or delete cloud resources, shows the account, project, location and the current state of the targets, and asks you to Proceed or Cancel. 0
- secret-guard 0.1.0 Keeps API keys, cloud credentials and other secrets out of what is sent to the model: every text that enters the conversation is scanned and each match is replaced with a meaningful placeholder such as <google api key>. 0
- pit-stop 0.2.0 mod + skill Keeps subagents small: tells the main agent how to size and split work, asks a growing subagent to checkpoint, and refuses its tools past a hard limit so a fresh agent takes over 0
- guard 0.1.0 Blocks destructive shell commands and access to secret files before they run, anywhere in a compound command 0
- cs-radio 0.1.0 Counter-Strike 1.6 radio calls for Claude Code: 'Fire in the hole' on deploys, 'Bomb has been defused' when a long turn lands. /radio to toggle. 0
- bash-guard 1.0.0 A seatbelt for YOLO mode: blocks catastrophic shell commands (rm -rf ~, mkfs, dd to a disk, fork bombs) and asks before risky ones (force-push, reset --hard, DROP TABLE, curl | sh), even with permissions bypassed. 0
- injection-guard 1.0.0 Defuses prompt injection in tool output: strips invisible Unicode that hides text from you but not from the model, and flags web pages, files and command output that carry instructions aimed at Claude. 0
- slopsquat-guard 1.0.0 Stops Claude from installing hallucinated or typosquatted packages: every npm, pip, uv, poetry, cargo and gem install is checked against its registry first. Packages that don't exist are blocked; brand-new, barely used or lookalike packages ask you first. 0
- command-explainer 1.0.0 Explains a shell command in one plain-English line, with its risk, right where you approve it, so you know what you're saying yes to. 0
- query-guard 0.2.3 Asks before Claude runs destructive or slow-looking SQL through a DB CLI: DELETE, UPDATE without WHERE, DROP, TRUNCATE, full scans and cartesian joins. 0
- autopilot 0.2.0 Works through a GOALS.md goal tree turn after turn, with locked checks, its own check verdicts, lessons that carry over, safety guards and a progress band 0
- open-file-guard 0.1.0 Before Claude uses a Word, Excel or PowerPoint file you have open, asks you to close it instead of letting the write fail. 0
- ghost-proc-guard 0.1.0 Stops Claude from starting a second copy of your dev servers on the next free port (monorepos and worktrees included), tracks the servers it starts, and stops leftovers from a /procs pane. 0
- ttsr-rules 0.1.0 oh-my-pi TTSR rules: a regex rule denies the tool call that would break it, with the rule as the reason; a question rule is judged after each turn. 0
- delete-guard 1.0.0 Holds recursive deletes (rm -rf, Remove-Item -Recurse, rmdir /s, git clean -f), shows what would go, and offers move-to-trash with /undo-delete, delete, or refuse. Leaves a receipt. 0
- house-rules 0.1.0 Quietly enforces Paddy's writing rules: no em dashes in chat, files or outbound messages, and a nudge when replies run long. 0
- clawd 0.3.0 Clawd, the Claude mascot, thinks, types, runs and celebrates beside the thinking line, a little differently each turn 0
- dependency-bouncer 0.2.0 Vets npm and PyPI packages before they install: blocks hallucinated, typosquatted and brand-new install-script packages, flags risky ones 0
- safety-guard 0.1.0 Blocks destructive shell commands and access to secret files (.env, SSH keys, cloud credentials). 0
- blast-radius 0.1.0 Holds risky Bash commands, shows what they would change, and waits for Proceed or Cancel. 0
- claw-guard 1.0.0 Claw mod: asks for your OK before any connector action that sends, deletes, pays, publishes or shares (fails closed, also when nobody is there to answer), and flags prompt-injection text inside emails, pages and files. 0
- auto-handoff 0.3.0 Hands the conversation off once the context passes a threshold (40% of windows over 200k tokens, 50% of smaller ones): a dedicated turn writes the handoff and the durable knowledge it names into an OKF bundle at .auto-handoff/, then the context is cleared and the work continues from the handoff 0
- dieta 0.1.0 Evita que el contexto se infle: frena lecturas de archivos enormes y recorta salidas gigantes de comandos 0
- subagentes 0.2.0 Los subagentes usan Sonnet por defecto; Claude recibe la regla para elegir Opus o Fable cuando toca 0
- auth-guard 0.1.0 Spots an expired CLI login in tool output and offers a Login button that signs in and retries. 0
- secret-guard 0.1.1 Stops Claude from writing API keys, private keys and other secrets into your files 0
- shell-guard 0.1.0 Windows shell guard: fixes backslash drive paths in Bash, blocks quote-eating node -e / heredoc patterns, and catches PowerShell/Bash syntax sent to the wrong shell 0
- ding-dong 0.1.0 回合跑超過一分鐘才結束時,發一則可愛的 macOS 通知叫你回來;/ding 可以預覽 0