command-guard
by Iain Partington · ★ 0 · updated yesterday
Refuses shell commands a project's .claude/command-guards.json rules out, for the main loop and every subagent
Install
git clone https://github.com/ipartington/claude-modsclaude --plugin-dir ./claude-mods/command-guardThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
tool.call- API calls
$.fs.read$.session.root$.ui.toast- Can see
Bash callsMonitor calls- Reach
- level 1 of 3 reads filesdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/ipartington/claude-mods
- Path in repo
command-guard- Source commit
5c6c50fthe exact code the scan read- Author
- Iain Partington @ipartington
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
More from ipartington/claude-mods
bg-task-band
ipartington/claude-mods
A band above the prompt showing running background tasks, their elapsed time and last output line
handoff-on-clear
ipartington/claude-mods
Saves a handoff when you /clear or exit, and offers it back on your next prompt
merge-followthrough
ipartington/claude-mods
Watches your PRs, and when one merges it pulls main and deletes the branch, then tells Claude
review-ledger
ipartington/claude-mods
Keeps review findings (H1, M3, L2...) per repo across sessions and ticks them off when their PR merges
tts-lite
ipartington/claude-mods
Speaks a one-line summary of each reply without starting a headless claude session