Agent Plugins Marketplace
← All plugins

guardrails

v0.40.1

Fifteen safety guards that block secret/credential writes, hardcoded machine-specific paths, git hook-bypass attempts, irreversible git operations (force-push, reset --hard, worktree-wide checkout/restore discards), Bash file-write workarounds that circumvent Write/Edit hooks, Windows drive-root /tmp writes (POSIX /tmp, C:\tmp, \tmp), an EXPORTED MSYS_NO_PATHCONV / MSYS2_ARG_CONV_EXCL that unconverts a later path argument on Windows, a Bash recursive `rm` whose target normalizes to a filesystem root (`/`, the MSYS-translated bare backslash, `~`, `$HOME`, a drive root such as `C:\` or `/c`, a WSL or cygdrive mount root), that carries `--no-preserve-root`, that names an empty or bare-variable operand, or that resolves outside the session's git tree, temp directories and scratchpad (Bash only; PowerShell `Remove-Item -Recurse` is not covered), multi-line `git commit -m` messages (an actual-newline `-m` mangles across shells; single-line `-m` passes), commit subjects and gh pr create titles that violate the repo's tracked team convention (when one is declared in .claude/source-control.md), (advisory) hallucinated CLI flags, (advisory) /plugin:skill references that do not resolve, (advisory) markdown citing a repo path the repo's own history shows was removed, (advisory, opt-in) un-throttled Workflow fan-out that risks burst 529s, and (advisory, opt-in) direct gh pr create calls bypassing this marketplace's own pull-request skill. Each guard is independently toggleable.

Claude Code1 Skill

By Melodic SoftwareLicense: MIT20 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Claude Code
Parsed components
1 skill or MCP entry
Source updated
Sep 28, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install guardrails for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install guardrails-4@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/melodic-software/claude-code-plugins

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/guardrails/.

Plugin files

plugins/guardrails/
├── .claude-plugin/plugin.json
└── skills/setup/SKILL.md

Included Skills1

setupskills/setup/SKILL.md

Verify the guardrails hooks' runtime prerequisites and per-guard toggle state for this machine. Use when: 'set up guardrails', 'configure guardrails', 'is guardrails working', 'which guards are on', a guard failed open with a jq notice, after tuning guard toggles, or 'install the commit-msg hook' / 'enforce the commit convention for every committer', or 'install the pre-commit content hook' / 'enforce secrets and hardcoded-path checks on every commit'. Actions: check (read-only verification, default) | apply (resolve what check found) | apply install-commit-msg (opt-in: install the tool-agnostic commit-msg convention hook into this repo's personal .git/hooks) | apply install-pre-commit-content (opt-in: install the write-path-independent secret/hardcoded-path pre-commit hook into this repo's personal .git/hooks). Re-runnable and safe.

Plugin manifests1

plugins/guardrails/.claude-plugin/plugin.json
{
  "$schema": "https://json.schemastore.org/claude-code-plugin-manifest.json",
  "name": "guardrails",
  "description": "Fifteen safety guards that block secret/credential writes, hardcoded machine-specific paths, git hook-bypass attempts, irreversible git operations (force-push, reset --hard, worktree-wide checkout/restore discards), Bash file-write workarounds that circumvent Write/Edit hooks, Windows drive-root /tmp writes (POSIX /tmp, C:\\tmp, \\tmp), an EXPORTED MSYS_NO_PATHCONV / MSYS2_ARG_CONV_EXCL that unconverts a later path argument on Windows, a Bash recursive `rm` whose target normalizes to a filesystem root (`/`, the MSYS-translated bare backslash, `~`, `$HOME`, a drive root such as `C:\\` or `/c`, a WSL or cygdrive mount root), that carries `--no-preserve-root`, that names an empty or bare-variable operand, or that resolves outside the session's git tree, temp directories and scratchpad (Bash only; PowerShell `Remove-Item -Recurse` is not covered), multi-line `git commit -m` messages (an actual-newline `-m` mangles across shells; single-line `-m` passes), commit subjects and gh pr create titles that violate the repo's tracked team convention (when one is declared in .claude/source-control.md), (advisory) hallucinated CLI flags, (advisory) /plugin:skill references that do not resolve, (advisory) markdown citing a repo path the repo's own history shows was removed, (advisory, opt-in) un-throttled Workflow fan-out that risks burst 529s, and (advisory, opt-in) direct gh pr create calls bypassing this marketplace's own pull-request skill. Each guard is independently toggleable.",
  "author": {
    "name": "Melodic Software",
    "email": "[email protected]"
  },
  "license": "MIT",
  "keywords": [
    "guard",
    "security",
    "secrets",
    "hooks",
    "pretooluse",
    "git",
    "hardcoded-paths",
    "cli-flags",
    "pull-request"
  ],
  "userConfig": {
    "secret_pattern_detection_enabled": {
      "type": "boolean",
      "title": "secret-pattern-detection guard",
      "description": "Block writes containing high-confidence secret/credential patterns",
      "default": true
    },
    "hardcoded_path_check_enabled": {
      "type": "boolean",
      "title": "hardcoded-path-check guard",
      "description": "Block writes containing hardcoded machine-specific paths",
      "default": true
    },
    "block_no_verify_enabled": {
      "type": "boolean",
      "title": "block-no-verify guard",
      "description": "Block git hook-bypass attempts (--no-verify, core.hooksPath=, hook-manager env-var disables for a configurable set: lefthook/husky/pre-commit/simple-git-hooks by default)",
      "default": true
    },
    "block_dangerous_git_enabled": {
      "type": "boolean",
      "title": "block-dangerous-git guard",
      "description": "Block irreversible git operations (push --force, reset --hard, clean -f, worktree-wide checkout/restore discards, and push --force-with-lease when it leases against a value git resolves at push time, meaning either no expected value, or an expectation that is not an object id of the repository's own hash width)",
      "default": true
    },
    "block_hook_bypass_enabled": {
      "type": "boolean",
      "title": "block-hook-bypass guard",
      "description": "Block Bash file-write workarounds that circumvent Write/Edit hook gates",
      "default": true
    },
    "block_windows_drive_tmp_enabled": {
      "type": "boolean",
      "title": "block-windows-drive-tmp guard",
      "description": "Block writes whose target is a Windows drive-root temp path (/tmp, C:\\tmp, \\tmp, /c/tmp) that resolves to <drive>:\\tmp instead of %TEMP%, in both Bash/PowerShell commands and Write/Edit/MultiEdit/NotebookEdit file paths. One switch covers both lanes. On Git for Windows, a Bash-tool /tmp that cygpath/mount shows is the usertemp mount of %TEMP% is not blocked; /c/tmp, C:\\tmp, drive-root \\tmp, PowerShell /tmp, and the file-path lane still are. curl -o/--output and wget -O/--output-document destinations are judged the same way as cp/mv",
      "default": true
    },
    "block_exported_msys_pathconv_enabled": {
      "type": "boolean",
      "title": "block-exported-msys-pathconv guard",
      "description": "Block a leaking MSYS path-conversion suppressor on Windows: an EXPORTED MSYS_NO_PATHCONV / MSYS2_ARG_CONV_EXCL, or a prefix on a child shell (MSYS_NO_PATHCONV=1 bash -c ...). Either switches off conversion for later commands, letting an unconverted /d/... reach git as <current-drive>:\\d\\...; a prefix on a non-shell command word and a bare assignment are not matched",
      "default": true
    },
    "block_root_delete_target_enabled": {
      "type": "boolean",
      "title": "block-root-delete-target guard",
      "description": "Block a Bash recursive `rm` whose target normalizes to a filesystem root: `/` and `/*`, the MSYS-translated bare backslash (`rm -rf \"\\\\\"` and a dangling `rm -rf \\`, the shape that cost a whole volume in anthropics/claude-code#92593), `~`, a literal `$HOME` / `${HOME}`, a drive root (`C:\\`, `c:/`, `C:`), an MSYS, WSL or cygdrive drive root (`/c`, `/mnt/c`, `/cygdrive/c`), and a UNC share root (`//server/share`). A recursive `rm` carrying `--no-preserve-root` is refused whatever it targets, and long options are matched on any unambiguous prefix as coreutils reads them. The command word is resolved through a launcher and its operand-taking options (`sudo -u bob rm`), and a child shell's operand is re-parsed (`bash -c '...'`). Quoted prose that merely names such a command is not matched, because the command word of that segment is not `rm`. It also refuses an empty operand (`rm -rf \"\"`), a bare variable operand (`$X`, `\"$X/\"`, `\"$X\"/*`, `$X$Y`, any `${...}` form but `\"${X:?}/\"`), and, when the payload carries a cwd, a target that resolves outside the payload cwd's git toplevel and is not strictly under a temp root or the session scratchpad (`rm -rf ../../..`, `rm -rf ~/Documents/x`, `cd / && rm -rf *`, `rm -rf /c/Users/*/.claude`, a `link/` that points outside). Braces are expanded and each alternative judged (`rm -rf {/c,x}`), a glob before the last component is expanded and each match judged as a literal path, and a relative path after a cd it can read but not follow (a relative cd while CDPATH is set, a glob target with no match or several) is refused. The judgment is bounded (512 targets, 256 glob entries, 25 seconds of wall time) and refuses past a bound. A target it cannot place (an expansion other than HOME, a relative path after a non-literal cd) is left alone. PowerShell `Remove-Item -Recurse` is not covered (issue #4516)",
      "default": true
    },
    "block_noncanonical_commit_enabled": {
      "type": "boolean",
      "title": "block-noncanonical-commit guard",
      "description": "Block `git commit -m` when the message actually contains a newline (multi-line `-m` mangles across shells, so pipe it via `-F -` instead; single-line `-m` passes); --amend, -C/-c, --fixup/--squash, -F <path>, and an in-progress merge/rebase are exempt",
      "default": true
    },
    "block_convention_gate_enabled": {
      "type": "boolean",
      "title": "block-convention-violation guard",
      "description": "Block a commit subject or `gh pr create --title` that violates the team-tracked convention pattern in .claude/source-control.md (no tracked pattern = no enforcement; same exemptions as block-noncanonical-commit)",
      "default": true
    },
    "cli_flag_verify_enabled": {
      "type": "boolean",
      "title": "cli-flag-verify guard",
      "description": "Advise on hallucinated CLI flags written to files (never blocks)",
      "default": true
    },
    "skill_reference_verify_enabled": {
      "type": "boolean",
      "title": "skill-reference-verify guard",
      "description": "Advise when markdown cites a /plugin:skill reference this repo owns but cannot resolve (never blocks)",
      "default": true
    },
    "stale_path_verify_enabled": {
      "type": "boolean",
      "title": "stale-path-verify guard",
      "description": "Advise when markdown cites a repo-relative path this repo's own history shows was removed and that is gone from the working tree (never blocks)",
      "default": true
    },
    "workflow_resilience_check_enabled": {
      "type": "boolean",
      "title": "workflow-resilience-check guard",
      "description": "Advise on un-throttled Workflow fan-out (never blocks). Default off since 0.20.0: a behavioral-class prose injector, config-disabled per the instruction-economy evidence gate (#2021). Set true to opt back in",
      "default": false
    },
    "flag_commit_pr_skill_bypass_enabled": {
      "type": "boolean",
      "title": "flag-commit-pr-skill-bypass guard",
      "description": "Advise when a direct gh pr create bypasses the source-control pull-request skill (never blocks). Default off since 0.20.0: a behavioral-class prose injector, config-disabled per the instruction-economy evidence gate (#2021). Set true to opt back in",
      "default": false
    },
    "cli_flag_verify_bins": {
      "type": "string",
      "title": "cli-flag-verify binaries",
      "description": "Comma-separated binaries cli-flag-verify scans; empty uses the built-in default set",
      "default": ""
    },
    "cli_flag_verify_skip_bins": {
      "type": "string",
      "title": "cli-flag-verify skip list",
      "description": "Comma-separated binaries cli-flag-verify must never scan",
      "default": ""
    },
    "block_dangerous_git_allow": {
      "type": "string",
      "title": "block-dangerous-git allow-list",
      "description": "Comma-separated forms block-dangerous-git permits: push-force, push-lease-unsafe, reset-hard, clean-force, checkout-dot, restore-dot, checkout-force, plus PowerShell fail-closed sink shapes ps-unparsable-dynamic-invocation, ps-unparsable-launcher, ps-unparsable-special-construct, ps-unparsable-herestring-unbalanced, ps-unparsable-herestring-subexpr (a command still unreadable after five granted sink rounds is refused whatever the list holds); empty blocks all",
      "default": ""
    },
    "block_noncanonical_commit_allow": {
      "type": "string",
      "title": "block-noncanonical-commit allow-list",
      "description": "Comma-separated form tokens to allow (currently: message-flag, which permits `-m` even when the message contains a newline)",
      "default": ""
    },
    "block_no_verify_hook_manager_prefixes": {
      "type": "string",
      "title": "block-no-verify hook-manager prefixes",
      "description": "Comma-separated hook-manager env-var name prefixes block-no-verify treats as a bypass when set to 0/false (e.g. lefthook,husky); empty uses the built-in default set (lefthook, husky, pre_commit, simple_git_hooks)",
      "default": ""
    },
    "block_hook_bypass_scratch_roots": {
      "type": "string",
      "title": "block-hook-bypass scratch roots",
      "description": "Comma-separated ABSOLUTE directories block-hook-bypass exempts as scratch/temp write targets (e.g. /tmp/scratch,/d/jobtmp/session). This list is empty by default and ADDS TO the two roots the guard already ships exempt: the host temp trees, which the harness scratchpad sits under, and the plugin data directory (<config dir>/plugins/data), where plugins persist their reports. Each is gated on CLAUDE_PROJECT_DIR naming a project root that does not contain it. Set this to name a scratch root of your own; the kill switch, not this option, is the whole-guard lever. The memory tier (`<memory_dir>/`, default `.work/`) is deliberately NOT a shipped default: secret-pattern-detection scans a Write there, so exempting Bash redirects to it would let a secret reach disk unscanned. Matching is on the effective stdout target after lexical normalization, at a path-component boundary, so a sibling merely sharing the name prefix, a `..` escape out of a root, and a discard-then-real-file redirect all still block. A relative target is resolved against the tool call's own cwd and refused when the command carries a cd/pushd/popd. A quoted or escaped OPERAND is never exempt: the operand is marked so it survives the quote strip and the segment split as one word, and an operand carrying whitespace, `;`, `|`, `&`, `(`, `)`, a newline or a backslash escape exempts nothing. Quotes elsewhere in the command no longer matter. Symlinks are not followed for a CONFIGURED root (an operator naming a root accepts its contents); the shipped temp default resolves them before exempting",
      "default": ""
    },
    "stdin_read_timeout": {
      "type": "number",
      "title": "Hook stdin read timeout (seconds)",
      "description": "Idle bound on reading the hook payload from stdin: how long a silent pipe is tolerated before a blocking guard fails closed. Only a JSON payload the pipe closed on mid-document is allowed with a notice; a stalled pipe stays a block",
      "default": 2,
      "min": 1
    }
  },
  "version": "0.40.1"
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[guardrails on Agent Plugins Marketplace](https://pluginsmp.com/plugins/guardrails-4)