fetchguard
v0.1.2v0.1.2: DISCLOSES A PROTECTION GAP — doc-only, no logic change, and the gap is NOT closed by this version. Through 0.1.1 this crate was explicitly one half of a pair: it scans WHAT web-tool output says, and `taintguard` tracked WHERE content came from, downgrading write-class tools for the rest of a turn that had read something external. taintguard was removed from the repository on 2026-08-24 by user ruling. Its half is gone and was not reassigned, so: external-file `Read` (a path outside the project) now produces NO provenance signal and NO content scan, and nothing restricts the turn afterwards; and this crate's own enforcement is only an `additionalContext` warning — it downgrades and denies nothing. The prose that said the Read surface was "deferred to taintguard's provenance gate" (`gate.rs`'s fail-closed contract and `WEB_TOOLS`'s docstring) said the surface was covered elsewhere, which is now false; both, plus README.ja.md and the `scan`/`main` module docs, now state the surface is covered by nothing. Recorded as an open gap so it is visible rather than silently inherited. Runtime content-level injection scanner: a PostToolUse hook (matcher WebFetch|WebSearch) that scans the tool_response text for planted prompt-injection phrasings (concealment / verification-bypass / instruction-override / egress) and, on a hit or an undecidable response, injects additionalContext telling the model the flagged span is untrusted DATA whose embedded directives must NOT be followed.
By yukineko0 GitHub starsUpdated yesterday
Directory evidence
- Runtimes
- Claude Code
- Parsed components
- 0 skill or MCP entries
- Source updated
- Sep 23, 2026
- Manifest status
- Canonical path parsed
The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →
Install fetchguard for Claude Code
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install fetchguard@agent-plugin-marketplacePaste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.
The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.
Get the source manually
git clone https://github.com/yukineko/claude-harnessesClone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is crates/fetchguard/.
Plugin files
└── .claude-plugin/plugin.json
Plugin manifests1
{
"name": "fetchguard",
"version": "0.1.2",
"description": "v0.1.2: DISCLOSES A PROTECTION GAP — doc-only, no logic change, and the gap is NOT closed by this version. Through 0.1.1 this crate was explicitly one half of a pair: it scans WHAT web-tool output says, and `taintguard` tracked WHERE content came from, downgrading write-class tools for the rest of a turn that had read something external. taintguard was removed from the repository on 2026-08-24 by user ruling. Its half is gone and was not reassigned, so: external-file `Read` (a path outside the project) now produces NO provenance signal and NO content scan, and nothing restricts the turn afterwards; and this crate's own enforcement is only an `additionalContext` warning — it downgrades and denies nothing. The prose that said the Read surface was \"deferred to taintguard's provenance gate\" (`gate.rs`'s fail-closed contract and `WEB_TOOLS`'s docstring) said the surface was covered elsewhere, which is now false; both, plus README.ja.md and the `scan`/`main` module docs, now state the surface is covered by nothing. Recorded as an open gap so it is visible rather than silently inherited. Runtime content-level injection scanner: a PostToolUse hook (matcher WebFetch|WebSearch) that scans the tool_response text for planted prompt-injection phrasings (concealment / verification-bypass / instruction-override / egress) and, on a hit or an undecidable response, injects additionalContext telling the model the flagged span is untrusted DATA whose embedded directives must NOT be followed.",
"author": {
"name": "yukineko"
},
"keywords": [
"security",
"hooks",
"prompt-injection",
"rust"
]
}For maintainers
If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.
[fetchguard on Agent Plugins Marketplace](https://pluginsmp.com/plugins/fetchguard)