ShriD5/claude-mods/tree/main/main-guard
main-guard
保護されたブランチや本番環境にいるときに赤い警告バンドを表示し、その環境では force-push や reset --hard など不可逆な git 操作を阻止する Claude Code プラグイン。
この mod について
main-guard は、リスクのある状況で Claude Code を使うときに安全層を追加します。現在の git ブランチが保護対象(デフォルトでは main、master、production、release*)、本番環境変数(NODE_ENV、RAILS_ENV、APP_ENV、ENVIRONMENT)が prod/production に設定されている、または .prod マーカーファイルが存在すると、プロンプトの上に赤いバンドを表示します。
Bash ツールを呼び出すたびに git コマンドを解析し(&&、パイプ、git -C、環境変数のプレフィックス、bash -c に対応)、保護されたブランチでは git push --force/-f/--force-with-lease/+refspec、git push --delete/:branch/--mirror、git reset --hard を拒否します。通常の git push で main に送る場合は確認を求めます。拒否された呼び出しは shell に届かず、Claude には理由と、ブランチを push する、PR を開く、git switch -c を使うといった安全な代替案が返ります。
claude --plugin-dir ./main-guard でインストールするか、リポジトリをマーケットプレイスに追加して /plugin を使います。オプションには protectedBranches(カンマ区切り、* ワイルドカード対応)と confirmPushes(デフォルト true)があります。これは agent のシートベルトであってセキュリティ境界ではありません。実行時に git 呼び出しを組み立てるコマンド(eval、スクリプトファイル)は検査されません。
インストール
まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。
claude plugin marketplace add ShriD5/claude-mods claude plugin install main-guard
原文 / README
main-guard
Puts a red band above the prompt whenever you are somewhere you can hurt production, and stops Claude from doing the irreversible git things there.
⚠ on main · NODE_ENV=production force-push and reset --hard are blocked
The band comes up when any of these is true:
- the current git branch is protected (
main,master,production,release*by default) NODE_ENV,RAILS_ENV,APP_ENVorENVIRONMENTisprod/production- a
.prodmarker file sits in the working directory or the repo root
On every Bash call Claude makes, main-guard reads the git commands out of it (through &&, pipes, git -C dir, env prefixes and bash -c "...") and:
| command | on a protected branch |
| --- | --- |
| git push --force / -f / --force-with-lease / +refspec | denied |
| git push --delete / :branch, git push --mirror | denied |
| git reset --hard | denied |
| plain git push (to main, HEAD:main, or while on main) | asks you first: "Push straight to main?" |
A denied call never reaches the shell; Claude gets the reason and a better route (push a branch, open a PR, git switch -c rescue before resetting). If there is nobody to ask (a -p run), the plain push is denied with the same advice.
Install
claude --plugin-dir ./main-guard
or add this repo as a marketplace and install it with /plugin.
Options
| option | default | what it does |
| --- | --- | --- |
| protectedBranches | main, master, production, release* | Comma-separated; * matches anything, so release* covers release/2.1. |
| confirmPushes | true | Off: plain pushes to a protected branch are refused outright instead of asking. |
How it works
A tool.call hook on Bash parses the command and answers { deny } or asks with $.ui.ask before calling next; the band is an AbovePrompt render of state refreshed on session.start, after every Bash call and every 15 s on $.clock.every.
This is a seatbelt for an agent, not a security boundary: a command that builds a git call at run time (eval, a script file) is not read.
