Plugin
guard
PreToolUse hooks for Claude Code that deny dangerous shell, git, and credential commands before they run: `rm -rf /` shapes, `git push --force`, `python -c` / `node -e` eval, pipe-to-shell, live credentials (`gh auth token`, `aws sts get-session-token`, `op read`), `git -c core.hooksPath=…` injection, silent commit reuse (`git commit -C HEAD~1`, `--reuse-message`). Each deny names the rule and prints a one-line override (`guard allowlist allow-command …`); decisions stream to a JSONL log the optional CLI reads (`pipx install tracine-guard`, then `guard noisy --since 24h` or `guard trace <session>`). Apache-2.0, no third-party deps. Defense in depth alongside Claude Code's own permissions — especially valuable for autonomous agent windows where no human is present to answer an ASK, so denies act as a hard floor. Not a sandbox or exfiltration boundary; see SECURITY.md.
- Analysed
- Last observed
What the code does
- Runs shell commands Code that starts system commands on the machine it runs on.
- Refers to credential files Code that names files such as SSH keys or cloud credentials.
- Downloads and runs code Code that fetches a script and pipes it into a shell.
- Runs hooks automatically Hooks that execute without being called explicitly.
- Reads AI and developer logins Code that refers to AI tool credentials or publishing tokens, such as .npmrc.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
7 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment