gcloud-guard
by davidho27941 · ★ 0 · updated yesterday
Holds gcloud and gsutil commands that would create, change or delete cloud resources, shows the account, project, location and the current state of the targets, and asks you to Proceed or Cancel.
Install
/plugin marketplace add davidho27941/cockpit/plugin install gcloud-guard@cockpitThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
session.startcommand.runtool.callui.render- API calls
$.clock.every$.clock.now$.command.register$.env.get$.fs.read$.fs.stat$.process.run$.state.get$.state.set$.ui.close$.ui.invalidate$.ui.open$.ui.resolve$.ui.toast- Draws
PaneAbovePrompt- Can see
Bash calls- Reach
- level 2 of 3 other: $.state.getother: $.state.setruns processesreads filesreads env varsdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/davidho27941/cockpit
- Path in repo
plugins/gcloud-guard- Source commit
f056844the exact code the scan read- Author
- @davidho27941
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
More from davidho27941/cockpit
auto-handover
davidho27941/cockpit
When context usage reaches your threshold, writes a handover note over the cached conversation prefix, compacts automatically, and hands the note to the compacted conversation and to the next session in the same project
blast-radius
davidho27941/cockpit
Holds risky shell commands (rm -rf, git reset --hard, git clean, force push, migrations) and shows what they would change, with Proceed and Cancel buttons.
cache-keeper
davidho27941/cockpit
Keeps the prompt cache warm while a session idles: every 50 minutes (configurable) one tiny request over the conversation prefix, so the entry does not lapse after an hour
opsx-board
davidho27941/cockpit
OpenSpec board: which phase you are in (propose/apply/archive), which tasks.md task is current, and every sub agent's name, model/effort, tokens and progress
secret-guard
davidho27941/cockpit
Keeps API keys, cloud credentials and other secrets out of what is sent to the model: every text that enters the conversation is scanned and each match is replaced with a meaningful placeholder such as .