command-guard

by Iain Partington · ★ 0 · updated yesterday

ToastsGuardsvalidates

0

Refuses shell commands a project's .claude/command-guards.json rules out, for the main loop and every subagent

install command-guard

Install

git clone https://github.com/ipartington/claude-mods
claude --plugin-dir ./claude-mods/command-guard

Then run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.

View source on GitHub

What it hooks into

From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.

Events
tool.call
API calls
$.fs.read$.session.root$.ui.toast
Can see
Bash callsMonitor calls
Reach
level 1 of 3 reads filesdraws

Origin

How it got here
Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
Repository
github.com/ipartington/claude-mods
Path in repo
command-guard
Source commit
5c6c50f the exact code the scan read
Author
Iain Partington @ipartington
License
MIT
First published
Last pushed
First listed here

Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.

More from ipartington/claude-mods

bg-task-band

ipartington/claude-mods

A band above the prompt showing running background tasks, their elapsed time and last output line

★ 0BandsGuardsPrompt

handoff-on-clear

ipartington/claude-mods

Saves a handoff when you /clear or exit, and offers it back on your next prompt

★ 0BandsCommandsPrompt

merge-followthrough

ipartington/claude-mods

Watches your PRs, and when one merges it pulls main and deletes the branch, then tells Claude

★ 0BandsCommandsPrompt

review-ledger

ipartington/claude-mods

Keeps review findings (H1, M3, L2...) per repo across sessions and ticks them off when their PR merges

★ 0PanesGuardsCommands

tts-lite

ipartington/claude-mods

Speaks a one-line summary of each reply without starting a headless claude session

★ 0Status line