kenryu42/claude-code-safety-net
kenryu42/claude-code-safety-net · 1 plugin
Marketplace A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Devin CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
Install
The repo has no one-line install. Follow its README.
Plugins 1
After adding the marketplace, install one with /plugin install <name>@cc-safety-net-dev.
- 1cc-safety-netBlock destructive commands and secret access
/plugin install cc-safety-net@cc-safety-net-dev
Files
CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything. It is not a sandbox: it does not contain processes, set filesystem permissions, or watch network egress.
Note
Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.
How it works
Supported coding CLIs
CC Safety Net supports these coding agent CLIs on Windows, macOS, and Linux.
Amp Code |
Antigravity CLI |
Claude Code |
Codex |
Cursor |
DeepSeek Harness |
Devin CLI |
Factory Droid |
Gemini CLI |
GitHub Copilot CLI |
Grok Build |
Hermes Agent |
Kimi Code |
OpenClaw |
OpenCode |
Pi |
Features
- Blocks destructive commands such as
git reset --hard,git push --force, andrm -rfon dangerous targets, even insidebash -corpython -c. See Blocked Commands. - Blocks secret access to SSH keys,
.envfiles,~/.aws, and coding-CLI credentials, from the shell and from the agent's file tools. See Secret Protection. - Tunes the policy in a GUI. Run
npx cc-safety-net guito pick the Standard, Strict, or Paranoid preset and turn rules on or off. See Modes. - Adds blocks through rulebooks: official packs for Terraform, AWS, gcloud, and Azure, or your own JSON. See Official Rulebooks.
- Shares policy through git. Commit
.cc-safety-net/so clones and cloud sessions get the same rules. See Team Setup. - Embeds in your own tools. Call
checkCommandfrom Node.js without installing the hook. See Library API.
Quick start
You need Node.js 18 or higher. Install into the coding CLIs on this machine, then check that protection is working:
npx -y cc-safety-net@latest install
npx -y cc-safety-net@latest doctorUpdate with npx -y cc-safety-net@latest update and uninstall with npx -y cc-safety-net uninstall. Keep the @latest qualifier: a bare cc-safety-net spec can run an older copy from the npx cache. Per-CLI requirements are in Installation.
Development
See CONTRIBUTING.md to report a bug or request a feature.
License
MIT
{
"name": "cc-safety-net-dev",
"metadata": {
"description": "Development marketplace for cc safety net plugin",
"version": "1.0.0"
},
"owner": {
"name": "J Liew",
"email": "jliew@420024lab.com"
},
"plugins": [
{
"name": "cc-safety-net",
"description": "Block destructive commands and secret access",
"source": "./",
"author": {
"name": "J Liew",
"email": "jliew@420024lab.com"
}
}
]
}Facts
- Kind
- Marketplace
- Repo
- kenryu42/claude-code-safety-net
- Group
- Uncategorized
- Marketplace name
- cc-safety-net-dev
- Owner
- J Liew
- License
- MIT
- Language
- TypeScript
- Created
- 2025-12-25
- Forks
- 84
- Homepage
- ccsafetynet.com
- Topics
- ai-agents, ai-safety, antigravity, claude, claude-code, claude-code-plugin, cli, codex, codex-cli, coding-agent, cursor, developer-tools, dsh-plugin, guardrails, hermes-agent, hooks, openclaw, opencode, pi-extension, security
- Plugins
- 1
- 1f/prompts.chatf/prompts.chatf.k.a. Awesome ChatGPT Prompts. Share, discover, and collect prompts from the community. Free and open source — self-host for your organization with complete privacy.
- 2affaan-m/everything-claude-codeaffaan-m/everything-claude-codeThe agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond.
- 3obra/superpowersobra/superpowersAn agentic skills framework & software development methodology that works.
- 4anthropics/skillsanthropics/skillsPublic repository for Agent Skills
- 5anthropics/claude-codeanthropics/claude-codeClaude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows - all through natural language commands.
- 6nextlevelbuilder/ui-ux-pro-max-skillnextlevelbuilder/ui-ux-pro-max-skillAn AI skill that provides design intelligence for building professional UI/UX across multiple platforms.