laika56/claude-code-guardrails
Three shell hooks that stop a coding agent from reporting success over a failed command. Measured: a CLAUDE.md rule was followed 13/22 times; hooks fire at the moment instead.
ARCHETYPE
Automator
Hooks on every lifecycle event: format, lint, notify, log.
Copy this rig
# review before running: this installs third-party code
$ npx degit laika56/claude-code-guardrails/.claude ./rig-claude-code-guardrails # inspect, then merge into .claude/ MCP servers are added to Claude Code at local scope; env vars are shown as YOUR_… placeholders — we never store values. Files are fetched with degit into a separate folder so you can review before merging.
This rig commits no guardrails. Here is the community baseline instead — the deny/ask rules most often found across all 7,204 rigs:
{
"permissions": {
"deny": [
"Read(./.env)",
"Read(**/.env)",
"Read(~/.ssh/**)",
"Bash(rm -rf *)",
"Read(**/*.pem)",
"Bash(rm -rf /)",
"Bash(git push --force:*)",
"Bash(sudo *)",
"Read(.env)",
"Bash(rm -rf /*)",
"Read(./.env.*)",
"Read(~/.aws/**)",
"Bash(git push --force*)",
"Bash(rm -rf:*)",
"Read(**/*.key)",
"Read(**/.env.*)",
"Bash(sudo:*)",
"Bash(git reset --hard*)",
"Bash(git reset --hard:*)",
"Read(.env.*)"
],
"ask": [
"Bash(git push:*)",
"Bash(git push *)",
"Bash(git commit:*)",
"Bash(rm *)",
"Bash(rm:*)",
"Bash(git rebase *)",
"Bash(wget *)",
"Bash(npm publish:*)",
"Bash(git commit *)",
"Bash(gh pr merge *)"
]
}
} Hooks (4)
| event | matcher | runs |
|---|---|---|
| PostToolUse | Bash | /private/tmp/claude-501/-Users-jh-Desktop-claude/b0694b4c-045b-45ab-8efc-96d52e2b194c/scratchpad/gh/claude-code-guardrails/.claude/hooks/verify-before-done.sh |
| PostToolUse | * | /private/tmp/claude-501/-Users-jh-Desktop-claude/b0694b4c-045b-45ab-8efc-96d52e2b194c/scratchpad/gh/claude-code-guardrails/.claude/hooks/loop-breaker.sh |
| PostToolUseFailure | Bash | /private/tmp/claude-501/-Users-jh-Desktop-claude/b0694b4c-045b-45ab-8efc-96d52e2b194c/scratchpad/gh/claude-code-guardrails/.claude/hooks/verify-before-done.sh |
| UserPromptSubmit | * | /private/tmp/claude-501/-Users-jh-Desktop-claude/b0694b4c-045b-45ab-8efc-96d52e2b194c/scratchpad/gh/claude-code-guardrails/.claude/hooks/quantify-claims.sh |
Similar rigs
cocoindex-io/cocoindex
Incremental engine for long horizon agents 🌟 Star if you like it!
Automator 7.3k tok ·
FailproofAI/failproofai
Observability and enforcement for AI agent harnesses. Capture every run and runtime reliability with policy enforcement.
Automator 22.9k tok ·
caliber-ai-org/ai-setup
Continuously sync your AI setups with one command. Codebase tailor suited agent skills, MCPs and config files for Claude Code, Cursor, and Codex.
Automator 3.2k tok ·
asklokesh/loki-mode
Autonomous software factory. Give it a GitHub issue, a spec or a one-line task; get back a pull request with a signed receipt anyone can re-check offline. Runs on your machine with your own keys: Claude, Codex, OpenCode.
Automator 8.2k tok ·