bash-guardrails

by Rui He · ★ 0 · updated yesterday

ToastsGuardswarnings

0

Tool-call guard rules (parser-based). On by default: blocks malformed bash and find rooted at /. Opt-in: Monitor, find without -xdev, pgrep/pkill pitfalls, until-grep loops, sudo, run0 confirmation

install bash-guardrails

Install

git clone https://github.com/ruihe774/cc-bash-guardrails
claude --plugin-dir ./cc-bash-guardrails

Then run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.

View source on GitHub

What it hooks into

From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.

Events
tool.call
API calls
$.ui.ask$.ui.toast
Can see
Monitor|Bash calls
Reach
level 0 of 3 draws

Origin

How it got here
Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
Repository
github.com/ruihe774/cc-bash-guardrails
Path in repo
repository root
Author
Rui He @ruihe774
License
Unlicense
First published
Last pushed
First listed here

Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.