dot-guard
by theagitist · ★ 0 · updated 2 days ago
Block git add of a whole $HOME work-tree (dot add -A/./*), which would stage your entire home directory.
Install
git clone https://github.com/theagitist/claude-modsclaude --plugin-dir ./claude-mods/dot-guardThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
tool.call- API calls
$.env.get- Can see
Bash calls- Reach
- level 1 of 3 reads env vars
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/theagitist/claude-mods
- Path in repo
dot-guard- Source commit
723bcedthe exact code the scan read- Author
- @theagitist
- License
- No license declared — ask the author before reusing code.
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
More from theagitist/claude-mods
box-status
theagitist/claude-mods
Status line: which box you're on, the out-of-band ping channel it resolves (telegram/email/none), and whether passwordless sudo is available.
emdash-watch
theagitist/claude-mods
Flag em-dashes you introduce into public-facing prose (notes, docs, READMEs, HTML); internal files (CLAUDE.md, memory) are exempt. Non-blocking note to the model.
home-path-guard
theagitist/claude-mods
Flag hardcoded user home paths (/home/ , /Users/ ) you write into files; nudge $HOME / ~ instead. Machine-local (*.local.*) files exempt. Non-blocking.
idle-ping
theagitist/claude-mods
When a turn that did real work ends, ping the user out of band (Telegram if a bot token + TELEGRAM_CHAT_ID are set, else email via CLAUDE_PING_EMAIL + a mailer).