Plugin
railguard
Railguard is a safer, context-aware alternative to --dangerously-skip-permissions for Claude Code. Instead of choosing between approving every command manually or giving Claude unrestricted access, Railguard sits in the middle. It intercepts every tool call — Bash, Write, Edit, Read — and makes policy-based decisions: allow safe commands instantly, block dangerous ones automatically, and ask for human approval when it's not sure. Out of the box, Railguard comes with 29 default rules covering destructive operations like terraform destroy, rm -rf, DROP TABLE, and git force-push. It detects evasion attempts (base64 encoding, chr() construction, variable substitution, shell wrapping), restricts file access with path fencing (blocking ~/.ssh, ~/.aws, /etc), snapshots every file write for one-click rollback, and logs every decision to a structured audit trail. Everything is customizable through a simple railguard.yaml file in your project directory.
- Analysed
- Last observed
What the code does
- Runs shell commands Code that starts system commands on the machine it runs on.
- Runs hooks automatically Hooks that execute without being called explicitly.
- Has an install script A script that runs when the package is installed.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
5 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment