prodguard

by claude-mods-rnd · ★ 22 · updated 3 days ago

BandsStatus lineGuardsCommandsvalidates

0

PRODUCTION GUARD: ambient project/environment context + a transport-independent policy core (DashClaw evidence classifier + offlocal policy engine) enforced natively on tool.call and tool.check. Blocks, asks, or contains before the command runs. /prodguard

install prodguard

Install

git clone https://github.com/ucsandman/Agnostic-AI
claude --plugin-dir ./Agnostic-AI/labs/claude-mods/prototypes/prodguard

Then run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.

View source on GitHub

What it hooks into

From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.

Events
session.starttool.calltool.checkcommand.runui.renderturn.complete
API calls
$.command.register$.fs.exists$.fs.read$.fs.write$.session.id$.session.repo$.ui.ask$.ui.invalidate$.ui.log$.ui.resolve$.ui.status$.ui.toast
Draws
AbovePrompt
Can see
Bash|Write|Edit|NotebookEdit calls
Reach
level 2 of 3 writes filesreads filesdraws

Origin

How it got here
Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
Repository
github.com/ucsandman/Agnostic-AI
Path in repo
labs/claude-mods/prototypes/prodguard
Author
claude-mods-rnd @ucsandman
License
MIT
First published
Last pushed
First listed here

Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.

More from ucsandman/Agnostic-AI

bender

ucsandman/Agnostic-AI

REALITY BENDER: intercepts a harmless tool result and alters what Claude receives; prints REAL vs RECEIVED

★ 22GuardsAutomation

blackbox

ucsandman/Agnostic-AI

BLACK BOX RECORDER: structured per-session timeline of prompts, model steps, tool calls, subagents and denials; /blackbox prints it

★ 22GuardsCommandsPrompt

claude-runtime

ucsandman/Agnostic-AI

Shared Claude runtime adapter: normalises function-hook events into ClaudeRuntimeEvent, exposes $.runtime (emit bus, supports, judge, snapshot) to other plugins, and writes a JSONL event log

★ 22GuardsPromptAutomation

costclaw-live

ucsandman/Agnostic-AI

COSTCLAW LIVE: per-request cost, cache decay and repeated-read detection while the session runs, and it serves the Nth identical Read of an unchanged file from its own cache instead of paying for it

★ 22BandsStatus lineGuards

guardian

ucsandman/Agnostic-AI

GUARDIAN: executable policy that protects lab/demos/protected/** from Write/Edit/Bash, whatever CLAUDE.md says

★ 22ToastsGuards

harness-mods

ucsandman/Agnostic-AI

Harness Mod layer: heartbeat/canary, native usage, rewrite explanations, measured subagent accounting, supervisor routing, secret redaction. Modes per guard in ~/.claude/mods/mods-config.json (classic | shadow_mod | mod).

★ 22ToastsGuardsCommands

matrix

ucsandman/Agnostic-AI

MATRIX: freezes a harmless tool call before it runs, shows what Claude intended, asks you, then continues or denies. /matrix on|off

★ 22Status lineGuardsCommands

probe-ui

ucsandman/Agnostic-AI

Interactive UI probe: ui.render components, toast, status, log, pane, command register

★ 22PanesStatus lineReskins

probe2

ucsandman/Agnostic-AI

Interception probe: deny, rewrite, replace result, delay, throw, register tool, classify

★ 22GuardsTools & agentsAutomation

probe3

ucsandman/Agnostic-AI

Permission override, subagent visibility, agent.spawn model rewrite, turn.step routing, prompt context injection

★ 22GuardsPromptAutomation

spike-compact

ucsandman/Agnostic-AI

Spike: does $.session.compact() work from a plugin, and what does the session.compact event carry?

★ 22Automation

spike-describe

ucsandman/Agnostic-AI

Spike: does a tool.describe rewrite reach the model, does agent.offer hide a type, does prompt.suggest fire?

★ 22PromptAutomation