ClaudeMods
☰
EN
● 0 online · Views 0 times
SponsorsSubmit a project
GitHub repositories · by ABDUAZIZX

script-gate

A Claude Code mod that blocks Claude from running scripts piped straight from the internet, including download-and-execute pipes, encoded PowerShell, and LOLBin downloaders, allowing safe patterns like curl -o and git clone.

Translated

About this mod

script-gate is a Claude Code mod (v2.1.287+) hooking the Bash tool to intercept dangerous download-and-execute patterns: curl|sh, wget|bash, iwr|iex, command substitution downloads, encoded PowerShell, LOLBin downloaders (certutil, bitsadmin, mshta, regsvr32), and Python exec of remote code. Safe patterns like curl -o file, curl|jq, git clone, npm install, and local script execution are permitted. Unlike CLAUDE.md rules, the hook runs inside Claude Code so the command never reaches the shell regardless of conversation context. Install via /plugin marketplace add ABDUAZIZX/script-gate and /plugin install script-gate@script-gate, or run with claude --plugin-dir for a single session. MIT licensed.

Installation

Check the author's README for the marketplace and plugin name first. Commands may change as the repository evolves.

claude plugin marketplace add ABDUAZIZX/script-gate
claude plugin install script-gate
Original text / README

script-gate 🧱

A Claude Code mod (v2.1.287+) that stops Claude from running scripts straight from the internet.

Mod لـ Claude Code يمنع Claude من تشغيل أي سكربت يُنزَّل من الإنترنت ويُنفَّذ مباشرة — أسلوب شائع في نشر البرمجيات الخبيثة. يوقف الأمر قبل التنفيذ، ويوجّه Claude إلى الطريقة الآمنة: نزّل الملف، اعرضه على المستخدم، ولا تشغّله إلا بموافقته.

Why a mod and not just instructions?

A rule in CLAUDE.md is advice: the user can talk Claude out of it, and a malicious README or web page can try to. A mod runs inside Claude Code itself — the command never reaches the shell, whatever the conversation says.

In our test, Claude first refused because of a CLAUDE.md rule. After an explicit "I approve, run it", it tried — and script-gate blocked it. Claude then switched on its own to downloading the file without running it.

What it blocks (Bash tool)

| Pattern | Example | |---|---| | Download piped into a shell/interpreter | curl … \| sh, wget -qO- … \| bash, iwr … \| iex | | Download inside command/process substitution | bash -c "$(curl …)", bash <(curl …) | | PowerShell iex on remote content | iex (New-Object Net.WebClient).DownloadString(…) | | Encoded PowerShell | powershell -EncodedCommand … | | Windows LOLBins used as downloaders | certutil -urlcache, bitsadmin /transfer, mshta http…, regsvr32 /i:http… | | Python executing downloaded code | exec(urlopen(…).read()) |

Allowed: curl -o file, curl … | jq, iwr … -OutFile, git clone, npm install, running a local ./install.sh.

On a block it shows a 🧱 toast and a counter in the status line.

Install

/plugin marketplace add ABDUAZIZX/script-gate
/plugin install script-gate@script-gate

Or for one session:

git clone https://github.com/ABDUAZIZX/script-gate
claude --plugin-dir ./script-gate

Test

claude plugin validate .
claude plugin test .

Test samples are assembled from pieces so antivirus scanners don't flag the test file itself (Windows Defender killed a shell command containing them during development — they are real attack patterns).

Limits

  • Pattern-based: a determined attacker can obfuscate further. This is a safety net, not a sandbox.
  • It guards the model's Bash calls, not commands you type yourself with !.
  • Mods are an early-access API and may change between releases. Read any mod's code before installing it.

Also see env-guard — blocks Claude from reading .env secrets.

MIT License

Similar projects