Agent Plugins Marketplace
← All plugins

zsh-wordsplit-guard

v0.1.1

Denies a Bash command looping over a bare expansion (`for x in $var`): the Bash tool runs zsh, where parameter expansion is not word-split, so the loop silently runs once over the whole string instead of per element. A glob or a path around the expansion (`for f in $D/*.log`) is left alone. The deny message names the splitting forms to use instead. Opt out per call with `[nosplit]` in the description, or session-wide with ALLOW_ZSH_NOSPLIT=1.

Claude Code

By Filippo Merante Caparrotta1 GitHub starsUpdated 1 hour ago

Directory evidence

Runtimes
Claude Code
Parsed components
0 skill or MCP entries
Source updated
Sep 28, 2026
Manifest status
Canonical path parsed

The directory validates manifest shape and source location. It does not execute the plugin or provide a security endorsement. Review the indexing methodology →

Install zsh-wordsplit-guard for Claude Code

Installs for the current user
claude plugin marketplace add IchenDEV/agent-plugin-mkt
claude plugin marketplace update agent-plugin-marketplace
claude plugin install zsh-wordsplit-guard@agent-plugin-marketplace

Paste and run these commands in a terminal with Claude Code. They add and refresh the PluginsMP catalog, then install this plugin.

The installer fetches third-party code from the source repository shown on this page. This directory validates manifest structure and source location, but does not perform a security audit; review the manifest, components, and source before installing.

Get the source manually
git clone https://github.com/filippolmt/skills

Clone the source repository, then follow its setup instructions to add the plugin to a compatible client. The plugin root is plugins/zsh-wordsplit-guard/.

Plugin files

plugins/zsh-wordsplit-guard/
└── .claude-plugin/plugin.json

Plugin manifests1

plugins/zsh-wordsplit-guard/.claude-plugin/plugin.json
{
  "name": "zsh-wordsplit-guard",
  "description": "Denies a Bash command looping over a bare expansion (`for x in $var`): the Bash tool runs zsh, where parameter expansion is not word-split, so the loop silently runs once over the whole string instead of per element. A glob or a path around the expansion (`for f in $D/*.log`) is left alone. The deny message names the splitting forms to use instead. Opt out per call with `[nosplit]` in the description, or session-wide with ALLOW_ZSH_NOSPLIT=1.",
  "version": "0.1.1",
  "author": {
    "name": "Filippo Merante Caparrotta"
  }
}

If you maintain this plugin, link to this source-backed listing from your README so users can review its manifest and indexed components.

[zsh-wordsplit-guard on Agent Plugins Marketplace](https://pluginsmp.com/plugins/zsh-wordsplit-guard)