guard
Publisher not specified · Claude Code
What this plugin does
PreToolUse hooks for Claude Code that deny dangerous shell, git, and credential commands before they run: `rm -rf /` shapes, `git push --force`, `python -c` / `node -e` eval, pipe-to-shell, live credentials (`gh auth token`, `aws sts get-session-token`, `op read`), `git -c core.hooksPath=…` injection, silent commit reuse (`git commit -C HEAD~1`, `--reuse-message`). Each deny names the rule and prints a one-line override (`guard allowlist allow-command …`); decisions stream to a JSONL log the optional CLI reads (`pipx install tracine-guard`, then `guard noisy --since 24h` or `guard trace `). Apache-2.0, no third-party deps. Defense in depth alongside Claude Code's own permissions — especially valuable for autonomous agent windows where no human is present to answer an ASK, so denies act as a hard floor. Not a sandbox or exfiltration boundary; see SECURITY.md.
Catalog observations
- Sources
- Community
- Works with
- Claude Code
- Reported installs
- Not provided
- First observed
- 2026-10-03 22:13 UTC
- Last observed
- 2026-10-10 00:00 UTC
Installation counts are reported by Claude Marketplace, not independently verified active users. Observation dates are not release dates. Pricing and account requirements must be checked with the publisher.
Install in Claude Code
Choose a source and review what the plugin adds before installing.
Community
/plugin marketplace add anthropics/claude-plugins-community
/plugin install guard@claude-community
Source evidence
Descriptions and compatibility labels come from the linked sources. Where both sources match, the GitHub description is used because web summaries may be shortened. We have not independently tested the declared capabilities.