kenryu42/cc-safety-net
A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSee
ARCHETYPE
Pragmatist
A balanced, no-drama setup: some rules, some tools, nothing extreme.
Copy this rig
# review before running: this installs third-party code
$ npx degit kenryu42/cc-safety-net/.claude ./rig-cc-safety-net # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
$ npx degit kenryu42/cc-safety-net/.agents/skills/ccsn-find-simplifications .claude/skills/ccsn-find-simplifications $ npx degit kenryu42/cc-safety-net/.agents/skills/ccsn-no-comments .claude/skills/ccsn-no-comments $ npx degit kenryu42/cc-safety-net/.agents/skills/verify-cc-safety-net .claude/skills/verify-cc-safety-net $ npx degit kenryu42/cc-safety-net/.claude/skills/release-notes .claude/skills/release-notes $ npx degit kenryu42/cc-safety-net/skills/cc-safety-net .claude/skills/cc-safety-net
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Skills (5)
Similar rigs
RAIT-09/obsidian-agent-client
Bring AI agents into Obsidian via Agent Client Protocol (ACP), such as Claude Code, Codex and Gemini CLI.
Pragmatist 4.8k tok ·
lingua-realm/agent-config-ansible
基于Ansible一键同步claude code/codex/...等工具的配置
Pragmatist 2.9k tok ·
TRIDENT-KR/muster
Org-wide control plane for AI coding agent configuration — one source of truth for AGENTS.md, CLAUDE.md, skills, and MCP config
Pragmatist 19.9k tok ·
GlitterKill/sdl-mcp
Symbol Delta Ledger (SDL-MCP) is a policy-centered context budget layer for coding agents: Symbol-graph intelligence combined with precision tools. It turns sprawling codebases into compact, high-signal context that saves tokens, speeds up
Pragmatist 7.9k tok ·