admin-capability-lockdown
v0.2.0Organization control mod: withholds the http and process nouns from $ so no plugin beneath it can reach the network or spawn processes, refuses user-tier plugins by name allowlist or by the $ calls their source declares, and withholds the Bash tool (shellPolicy "deny", default) or, in "guardrail" mode, denies well-known network clients as a bypassable speed bump. Hooks engine.create, plugin.register and tool.call; seat it in the managed prepend tier.
By claude-code-templatesLicense: MIT31.6k GitHub starsUpdated 5 hours ago
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 0 skill or MCP entries
- Source updated
- Sep 24, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install admin-capability-lockdown for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install admin-capability-lockdown@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/davila7/claude-code-templatesClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is cli-tool/components/mods/enterprise/admin-capability-lockdown/.
Plugin files
└── .claude-plugin/plugin.json
Plugin manifests1
{
"name": "admin-capability-lockdown",
"version": "0.2.0",
"description": "Organization control mod: withholds the http and process nouns from $ so no plugin beneath it can reach the network or spawn processes, refuses user-tier plugins by name allowlist or by the $ calls their source declares, and withholds the Bash tool (shellPolicy \"deny\", default) or, in \"guardrail\" mode, denies well-known network clients as a bypassable speed bump. Hooks engine.create, plugin.register and tool.call; seat it in the managed prepend tier.",
"author": {
"name": "claude-code-templates",
"url": "https://www.aitmpl.com"
},
"repository": "https://github.com/davila7/claude-code-templates",
"license": "MIT",
"keywords": [
"mod",
"function-hooks",
"enterprise"
],
"userConfig": {
"allowedPlugins": {
"type": "string",
"title": "Allowed plugins",
"description": "Comma-separated plugin names that may register; empty allows any name",
"default": ""
},
"refuseCalls": {
"type": "string",
"title": "Refused $ calls",
"description": "Comma-separated $ calls (or noun prefixes ending in a dot) a user plugin may not make; default: http. and process.",
"default": ""
},
"shellPolicy": {
"type": "string",
"title": "Shell policy",
"description": "deny withholds the Bash tool; guardrail denies known network clients (bypassable); allow leaves Bash alone",
"default": "deny",
"options": [
"deny",
"guardrail",
"allow"
]
}
}
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[admin-capability-lockdown on Agent Plugins Marketplace](https://pluginsmp.com/plugins/admin-capability-lockdown)