# Add to your Claude Code skills
git clone https://github.com/alvintayzhenwei/guardrailsguardrails is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by alvintayzhenwei. It has 0 GitHub stars.
guardrails's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/alvintayzhenwei/guardrails" and add it to your Claude Code skills directory (see the Installation section above).
guardrails is primarily written in Shell. It is open-source under alvintayzhenwei on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh guardrails against similar tools.
No comments yet. Be the first to share your thoughts!
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
Safety hooks for Claude Code. Designed to refuse destructive shell commands, credential writes, and unreviewed external MCP calls — in any project, on macOS, Linux, or Windows.
Copy one file into your project and these checks run on every Claude Code tool call in it.
[!IMPORTANT] This is one layer of defence, not a solution, and it is not foolproof. It is pattern matching over the text of a tool call — useful against an agent making a mistake, and no substitute for backups, server-side branch protection, or reviewing what an agent does. It will not catch everything and is not intended to. If it cannot load, it fails open and your session runs unprotected — so the absence of a block never means a command was checked and approved.
Provided "as is", with no warranty and no liability, under the MIT License. Read DISCLAIMER.md before relying on it for anything you cannot afford to lose.
Don't trust it — check it. This tool asks for a hook on every tool call in
your project, so it should have to earn that. bash run-vuln-tests.sh runs 149
offline evasion attempts against the guards and tells you which ones got
through. SECURITY.md states plainly what the guards do not
defend against.
The patterns below are what the checks look for. The list is not exhaustive of destructive commands — it is exhaustive of what these checks recognise. Any spelling not listed, and anything the shell only assembles at run time, passes through.
| Check | Trigger | Patterns it refuses |
|---|---|---|
check-rm-rf.sh |
Bash, PowerShell | rm -rf in the spellings listed here — combined, separate, uppercase -R, GNU --recursive --force; find -delete; Remove-Item -Recurse -Force and its ri/rd/rmdir/del/erase aliases; rmdir /S /Q |
check-dangerous-git.sh |
Bash, PowerShell | git push, reset --hard, branch -D, clean -f, checkout ., restore, stash drop/clear, reflog expire, update-ref -d — matched through git's global options, so git -c … push is caught too |
check-production-guard.sh |
Bash, PowerShell | DROP TABLE/DATABASE/SCHEMA, TRUNCATE, DELETE/UPDATE without a row-narrowing WHERE (a tautological WHERE 1=1 does not count) |
check-macos-destructive.sh |
Bash | diskutil eraseDisk/eraseVolume/zeroDisk/secureErase/apfs deleteContainer, srm -r, launchctl bootout system/, bare defaults delete |
check-homebrew.sh |
Bash | brew uninstall --force, brew rm --force, brew cleanup --prune=all |
check-sensitive-files.sh |
any write tool | Writes to .env, .envrc, *.pem, *.key, *.p12, *.ppk, credentials, .netrc, .npmrc, .git-credentials, SSH keys — case-insensitively, since macOS and Windows filesystems are |
check-secrets-write.sh |
any write tool | Credential literals in source: password/secret assignments plus AWS, GitHub, Slack, Google, Stripe, GitLab, npm, OpenAI and Anthropic token formats, and private key blocks |
check-no-hardcoded-paths.sh |
any write tool | Machine-specific absolute paths in shared .claude/ assets |
check-mcp-guardrail.sh |
mcp__* |
Shows the outbound payload for external MCP calls before you consent |
git-hooks/pre-push |
git push (any caller) |
Pushes landing on main/master — including a bare git push whose upstream is main |
A blocking check exits 2 and returns a reason, so Claude sees why it was stopped
and can correct course. Guardrails restrain the agent, not you — every blocked
command can still be run manually.
"Any write tool" is literal: the dispatcher routes Write, Edit, MultiEdit,
NotebookEdit and anything else matching *Edit/*Write, so a newly
introduced file-mutating tool is guarded by default rather than silently
unguarded until someone adds its name.
mainThe checks above restrain Claude. This one restrains the git client itself — it
catches a push to a protected branch whichever caller runs it, unless that caller
skips hooks (see the caveat below).
bash git-hooks/install.sh # current repo
bash git-hooks/install.sh ../app # another repo
powershell git-hooks/install.ps1 # Windows
It inspects the <remote-ref> git reports for each pushed ref, which git resolves
after refspecs, HEAD and upstream tracking are expanded — so one check covers
git push origin main, git push origin HEAD:main, git push --delete origin main, and a bare git push from a branch whose upstream is main. Tags and
non-protected branches pass through untouched.
An existing pre-push hook is renamed to pre-push.local and still runs, after
the guard. If the repo sets core.hooksPath, the installer follows it there —
otherwise the hook would be a silent no-op.
This is a local safety net, not access control: git push --no-verify bypasses it
and other clones do not have it. Pair it with a server-side branch protection rule
requiring a pull request.
Copy run-hooks.sh into your project at .claude/hooks/run-hooks.sh and commit it.
On Windows, copy run-hooks.ps1 alongside it.
That is the only file your project needs to vendor. The rest of the library is resolved (and cached) automatically on first use — see Resolution order.
.claude/settings.jsonmacOS / Linux
{
"hooks": {
"PreToolUse": [{ "type": "command", "command": "bash .claude/hooks/run-hooks.sh pre" }],
"PostToolUse": [{ "type": "command", "command": "bash .claude/hooks/run-hooks.sh post" }]
}
}
Windows
{
"hooks": {
"PreToolUse": [{ "type": "command", "command": "powershell .claude/hooks/run-hooks.ps1 pre" }],
"PostToolUse": [{ "type": "command", "command": "powershell .claude/hooks/run-hooks.ps1 post" }]
}
}
Start a Claude Code session and ask it to run rm -rf /tmp/example. It should be
blocked with a [guardrail] reason.
bash in PATH. All check logic lives in .sh files — a single source of
truth across platforms. On Windows, install
Git for Windows (includes Git Bash) or enable
WSL. run-hooks.ps1 is a thin launcher that delegates to bash.PATH, used to parse the hook JSON payload.run-hooks.sh looks for the hook library in four places, in order:
$CLAUDE_GUARDRAILS_HOME — an explicit local checkout<project>/../guardrails or <project>/../claude-guardrails~/.claude/guardrails), refreshed once per TTL window$CLAUDE_GUARDRAILS_REPO into that cacheIf all four fail it exits 0 (fails open) so Claude Code is never blocked by a broken guardrail install — it prints a warning instead.
| Variable | Default | Purpose |
|---|---|---|
CLAUDE_GUARDRAILS_REPO |
https://github.com/alvintayzhenwei/guardrails.git |
Clone source. Forked this repo? Point this at your own fork, or your machines will keep pulling from upstream. |
CLAUDE_GUARDRAILS_HOME |
(unset) | Absolute path to a local checkout. Highest priority — ideal for developing the guardrails themselves. |
CLAUDE_GUARDRAILS_CACHE |
~/.claude/guardrails |
Where the auto-clone lives. |
CLAUDE_GUARDRAILS_TTL |
1440 |
Cache refresh interval, in minutes. |
PROD_HOST_PATTERN |
(unset) | Regex; when set, check-production-guard.sh also blocks commands mentioning a matching host. |
GUARDRAILS_PROTECTED_BRANCHES |
main master |
Space-separated, exact-match branch names the pre-push guard refuses. |
GUARDRAILS_ALLOW_PUSH_PROTECTED |
(unset) | Set to 1 for one deliberate push to a protected branch: GUARDRAILS_ALLOW_PUSH_PROTECTED=1 git push. |
Create .claude/hooks-skip.json in your project root and name the checks to skip:
{ "skip": ["check-production-guard", "check-no-hardcoded-paths"] }
check-mcp-guardrail.sh and the auto-classifier (mcp-classify.js) both read
.claude/hooks/mcp-registry.json inside your project. This file is not created
automatically — create it once per project by copying the starter:
mkdir -p .claude/hooks
cp examples/mcp-registry.json .claude/hooks/mcp-registry.json
Without it, post-tool-use.sh skips auto-classification entirely and every
mcp__* tool is treated as external, so every MCP call raises the consent banner —
including purely local ones.
| Field | Purpose |
|---|---|
local |
Prefix → {name, reason} for MCPs that run as local processes (no consent banner) |
external |
Prefix → {name, reason} for MCPs that call out to a networ |