Plugin
ccguard
Security guard hook for Claude Code. Evaluates every tool call (Bash, Edit, Write, Read, MCP) against 864 pattern-matching rules to block dangerous commands, data exfiltration, and supply chain attacks. Zero external dependencies, written in Zig. Supports three decision levels: allow, deny (hard block), and ask (user confirmation prompt). Protects against reverse shells, pipe-to-interpreter execution, credential leakage, cloud metadata access, environment variable injection, and more.
- Analysed
- Last observed
What the code does
- Runs hooks automatically Hooks that execute without being called explicitly.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
2 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment