protected-paths-guard 0.2.0
Denies Edit, Write and NotebookEdit calls on sensitive paths (.env files, lockfiles, CI workflows, git internals, private keys) with a glob allowlist override. A tool.call hook with an array matcher.
Install
git clone https://github.com/davila7/claude-code-templates.git claude --plugin-dir claude-code-templates/cli-tool/components/mods/security/protected-paths-guard
Run in a terminal. Claude Code loads the mod from that folder for the session.
Hooks into
- Tool calls