ABDUAZIZX/script-gate
script-gate
インターネットから直接パイプで渡されたスクリプトを Claude が実行するのを防ぐ Claude Code mod。ダウンロードして実行するパイプ、エンコード済み PowerShell、LOLBin ダウンローダーを含み、curl -o や git clone などの安全な形は許可します。
この mod について
script-gate は Bash ツールにフックする Claude Code mod(v2.1.287+)で、危険なダウンロード実行パターンを遮断します。対象は curl|sh、wget|bash、iwr|iex、コマンド置換によるダウンロード、エンコード済み PowerShell、LOLBin ダウンローダー(certutil、bitsadmin、mshta、regsvr32)、Python によるリモートコードの実行です。curl -o file、curl|jq、git clone、npm install、ローカルスクリプトの実行など安全な形は許可されます。CLAUDE.md のルールとは違い、このフックは Claude Code 内で動くため、会話の文脈に関係なくコマンドが shell に到達しません。/plugin marketplace add ABDUAZIZX/script-gate と /plugin install script-gate@script-gate でインストールするか、claude --plugin-dir で 1 セッションだけ実行します。MIT ライセンスです。
インストール
まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。
claude plugin marketplace add ABDUAZIZX/script-gate claude plugin install script-gate
原文 / README
script-gate 🧱
A Claude Code mod (v2.1.287+) that stops Claude from running scripts straight from the internet.
Mod لـ Claude Code يمنع Claude من تشغيل أي سكربت يُنزَّل من الإنترنت ويُنفَّذ مباشرة — أسلوب شائع في نشر البرمجيات الخبيثة. يوقف الأمر قبل التنفيذ، ويوجّه Claude إلى الطريقة الآمنة: نزّل الملف، اعرضه على المستخدم، ولا تشغّله إلا بموافقته.
Why a mod and not just instructions?
A rule in CLAUDE.md is advice: the user can talk Claude out of it, and a malicious README or web page can try to. A mod runs inside Claude Code itself — the command never reaches the shell, whatever the conversation says.
In our test, Claude first refused because of a CLAUDE.md rule. After an explicit "I approve, run it", it tried — and script-gate blocked it. Claude then switched on its own to downloading the file without running it.
What it blocks (Bash tool)
| Pattern | Example |
|---|---|
| Download piped into a shell/interpreter | curl … \| sh, wget -qO- … \| bash, iwr … \| iex |
| Download inside command/process substitution | bash -c "$(curl …)", bash <(curl …) |
| PowerShell iex on remote content | iex (New-Object Net.WebClient).DownloadString(…) |
| Encoded PowerShell | powershell -EncodedCommand … |
| Windows LOLBins used as downloaders | certutil -urlcache, bitsadmin /transfer, mshta http…, regsvr32 /i:http… |
| Python executing downloaded code | exec(urlopen(…).read()) |
Allowed: curl -o file, curl … | jq, iwr … -OutFile, git clone, npm install, running a local ./install.sh.
On a block it shows a 🧱 toast and a counter in the status line.
Install
/plugin marketplace add ABDUAZIZX/script-gate
/plugin install script-gate@script-gate
Or for one session:
git clone https://github.com/ABDUAZIZX/script-gate
claude --plugin-dir ./script-gate
Test
claude plugin validate .
claude plugin test .
Test samples are assembled from pieces so antivirus scanners don't flag the test file itself (Windows Defender killed a shell command containing them during development — they are real attack patterns).
Limits
- Pattern-based: a determined attacker can obfuscate further. This is a safety net, not a sandbox.
- It guards the model's Bash calls, not commands you type yourself with
!. - Mods are an early-access API and may change between releases. Read any mod's code before installing it.
Also see env-guard — blocks Claude from reading .env secrets.
MIT License
