{"slug":"ccguard","title":"ccguard","description":"Security guard hook for Claude Code. Evaluates every tool call (Bash, Edit, Write, Read, MCP) against 864 pattern-matching rules to block dangerous commands, data exfiltration, and supply chain attacks. Zero external dependencies, written in Zig. Supports three decision levels: allow, deny (hard block), and ask (user confirmation prompt). Protects against reverse shells, pipe-to-interpreter execution, credential leakage, cloud metadata access, environment variable injection, and more.","developer":null,"category":null,"reported_installs":null,"active":true,"first_seen_at":"2026-10-03T22:13:33.942Z","last_seen_at":"2026-10-07T12:00:01.506Z","last_changed_at":"2026-10-03T22:13:33.942Z","platform":"claude","sources":["Community"],"works_with":["Claude Code"],"marketplace_url":null,"repository_url":"https://github.com/soyukke/ccguard.git","web_data":{},"github_data":{},"catalog_sources":{"community":[{"name":"ccguard","source":{"sha":"e093ef5b805325732829de04201a9eab4a50abb5","url":"https://github.com/soyukke/ccguard.git","source":"url"},"homepage":"https://github.com/soyukke/ccguard","description":"Security guard hook for Claude Code. Evaluates every tool call (Bash, Edit, Write, Read, MCP) against 864 pattern-matching rules to block dangerous commands, data exfiltration, and supply chain attacks. Zero external dependencies, written in Zig. Supports three decision levels: allow, deny (hard block), and ask (user confirmation prompt). Protects against reverse shells, pipe-to-interpreter execution, credential leakage, cloud metadata access, environment variable injection, and more."}]}}