quarantine
by Chris Dwyer · ★ 0 · updated 3 days ago
0
Wraps web, MCP and third-party tool output as untrusted data and defangs prompt-injection lines before the model reads them
Install
git clone https://github.com/ccdwyer/quarantineclaude --plugin-dir ./quarantineThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
session.startcommand.runtool.callsession.append- API calls
$.command.register$.env.get$.session.cwd$.state.get$.state.set$.ui.status$.ui.toast- Can see
every tool call- Reach
- level 1 of 3 other: $.state.getother: $.state.setreads env varsdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/ccdwyer/quarantine
- Path in repo
- repository root
- Author
- Chris Dwyer @ccdwyer
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.