ShriD5/claude-mods/tree/main/main-guard
main-guard
A Claude Code plugin that shows a red warning band when you are on a protected branch or in a production environment, and blocks irreversible git operations like force-push and reset --hard there.
About this mod
main-guard adds a safety layer for Claude Code when working in risky contexts. It displays a red band above the prompt whenever the current git branch is protected (main, master, production, release* by default), a production env var (NODE_ENV, RAILS_ENV, APP_ENV, ENVIRONMENT) is set to prod/production, or a .prod marker file exists.
On every Bash tool call, it parses the git command (handling &&, pipes, git -C, env prefixes and bash -c) and: denies git push --force/-f/--force-with-lease/+refspec, git push --delete/:branch/--mirror, and git reset --hard on protected branches; and asks for confirmation on plain git push to main. Denied calls never reach the shell, and Claude receives the reason plus a safer alternative such as pushing a branch, opening a PR, or using git switch -c.
Install via claude --plugin-dir ./main-guard or by adding the repo as a marketplace and using /plugin. Options include protectedBranches (comma-separated, * wildcard) and confirmPushes (default true). Note this is a seatbelt for an agent, not a security boundary: commands that build git calls at runtime (eval, script files) are not inspected.
Installation
Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.
claude plugin marketplace add ShriD5/claude-mods claude plugin install main-guard
Original text / README
main-guard
Puts a red band above the prompt whenever you are somewhere you can hurt production, and stops Claude from doing the irreversible git things there.
⚠ on main · NODE_ENV=production force-push and reset --hard are blocked
The band comes up when any of these is true:
- the current git branch is protected (
main,master,production,release*by default) NODE_ENV,RAILS_ENV,APP_ENVorENVIRONMENTisprod/production- a
.prodmarker file sits in the working directory or the repo root
On every Bash call Claude makes, main-guard reads the git commands out of it (through &&, pipes, git -C dir, env prefixes and bash -c "...") and:
| command | on a protected branch |
| --- | --- |
| git push --force / -f / --force-with-lease / +refspec | denied |
| git push --delete / :branch, git push --mirror | denied |
| git reset --hard | denied |
| plain git push (to main, HEAD:main, or while on main) | asks you first: "Push straight to main?" |
A denied call never reaches the shell; Claude gets the reason and a better route (push a branch, open a PR, git switch -c rescue before resetting). If there is nobody to ask (a -p run), the plain push is denied with the same advice.
Install
claude --plugin-dir ./main-guard
or add this repo as a marketplace and install it with /plugin.
Options
| option | default | what it does |
| --- | --- | --- |
| protectedBranches | main, master, production, release* | Comma-separated; * matches anything, so release* covers release/2.1. |
| confirmPushes | true | Off: plain pushes to a protected branch are refused outright instead of asking. |
How it works
A tool.call hook on Bash parses the command and answers { deny } or asks with $.ui.ask before calling next; the band is an AbovePrompt render of state refreshed on session.start, after every Bash call and every 15 s on $.clock.every.
This is a seatbelt for an agent, not a security boundary: a command that builds a git call at run time (eval, a script file) is not read.
