ClaudeMods
☰
JA
● 0 人がオンライン ・閲覧 0 回
スポンサー作品を投稿
GitHub リポジトリ · 投稿者 amahmood561

tripwire

行動の瞬間に発動する教訓。条件に一致するツール呼び出しに付いたリマインダー、質問、ブロックです。

翻訳済み

この mod について

tripwire は Claude Code のプラグインで、tool.call hook を 1 つだけ持ちます。各教訓を「発動すべき動作」に対応付けて索引化し、agent が一致するツール呼び出しを出そうとした瞬間に教訓を発動します。

重大度は 3 種類です。remind は通常どおり実行して教訓を結果に追加し、ask は先に質問して回答がなければ拒否し、block は呼び出しを拒否して理由を伝えます。同時に複数が一致した場合は最も厳しいものを採用し、すべての教訓を表示します。

各 tripwire は JSON で定義され、tool(ツール名の regex)、pattern(入力の regex)、field(任意の単一フィールド)、unless(任意。一致すると黙る)、redact(一致した文字列を再現しない。秘密情報向け)、source(教訓の出所)を含みます。秘密情報の漏えい、commit 署名、schema 変更、メール送信スクリプト、デプロイ検証、wrangler KV のリモート操作、Apps Script のリダイレクト、Google Sheets の数式インジェクションなど、実際の失敗例を 十二個内蔵しています。~/.claude/tripwires.json に自分で追加できます。形式が正しくない項目は致命的にせずスキップします。

/tripwires コマンドで全ルール、発動回数と時刻、壊れた項目を一覧できます。インストールは git clone のあと claude --plugin-dir で読み込む方法と、フォルダーを ~/.claude/settings.json の env セクション(CLAUDE_CODE_PLUGIN_DIRS)に追加してすべてのセッションで有効にする方法があります。意図しない作業の中断を避けること、ask は失敗時に拒否すること、秘密情報を決して再現しないことを重視しています。記憶機構とも組み合わせられ、ノートは「なぜ」、tripwire は「いつ」を残します。claude plugin validate . と claude plugin test . でテストできます(合計 13 項目)。

インストール

まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。

claude plugin marketplace add amahmood561/tripwire
claude plugin install tripwire
原文 / README

tripwire

Lessons that fire at the moment of action.

Agent memory is usually read once, at the start of a session, and then hoped for. Three hours later the agent is about to repeat a mistake it has a note about, and the note is nowhere near the decision.

tripwire indexes each lesson by the action that should trigger it. When a coding agent is about to make a matching tool call, the lesson fires right there:

agent runs:  npx wrangler deploy
             │
             ▼  tripwire matches
⚡ TRIPWIRE [deploy-verify-content] (remind): After this deploy, verify on CONTENT,
   not the status code: curl the live URL and grep for text that only the new version
   contains.  (learned: false 'deployed' claims, twice)

It's a Claude Code mod: a plugin with one tool.call hook.

How it works: see ARCHITECTURE.md for the design, request flow, failure model and testing.

Three severities

| Severity | What happens | |---|---| | remind | The call runs. The lesson is attached to its result, so the agent reads it right then. | | ask | You're asked first. No answer (dismissed, or no one to ask) means no. | | block | The call is refused and the agent is told why, and not to work around it. |

When several tripwires match, the strictest one wins and every lesson is shown.

A tripwire

{
  "id": "kv-list-needs-remote",
  "tool": "^Bash$",
  "field": "command",
  "pattern": "wrangler kv key (list|get)",
  "unless": "--remote",
  "severity": "remind",
  "lesson": "Without --remote, wrangler reads the LOCAL dev store and returns []. A working form looks broken.",
  "source": "half an hour lost on a client site"
}

| Field | | |---|---| | tool | Regex on the tool name: ^Bash$, ^(Edit\|Write)$, claude-in-chrome__navigate$ | | pattern | Regex (case-insensitive) on the tool input | | field | Optional. Test one input field (command, file_path, url). Default: every string in the input | | unless | Optional. If this also matches, stay quiet (e.g. --dry-run) | | redact | Never echo the matched text. Use it for tripwires that match secrets | | source | Where the lesson was learned, so it can be checked later |

Built-in tripwires

Twelve real mistakes, each with where it was learned, in hooks/tripwires.ts:

  • block: a secret (Stripe, Supabase, AWS, Resend, GitHub, JWT) in a command's text, never echoed back · Claude attribution in a commit · assets.directory pointed at the repo root
  • ask: an unwrapped schema or data change (update, drop, alter) · scripts that email real people
  • remind: verify deploys on content · wrangler kv without --remote · Apps Script redirects need GET · only commit when asked · Google Sheets formula injection · Gmail compose swallows the first keystrokes · a paused free-tier Supabase project

Add your own in ~/.claude/tripwires.json: an array, or { "tripwires": [...] }. Broken entries are skipped, never fatal, and listed by /tripwires.

Commands

/tripwires lists every tripwire, how often each fired and when, plus any broken entries.

Install

git clone https://github.com/amahmood561/tripwire ~/tripwire
claude --plugin-dir ~/tripwire          # one session

To load it in every session, add the folder to the env block of ~/.claude/settings.json:

{ "env": { "CLAUDE_CODE_PLUGIN_DIRS": "~/tripwire" } }

Design notes

  • Advice must never stop work by accident. A malformed tripwire file is skipped, not fatal. Only an explicit block or a declined ask stops a call.
  • ask fails closed. A dismissed question, or a session with no one to ask, is treated as "no".
  • Secrets are never repeated. A redact tripwire reports [redacted], never the match.
  • It pairs with memory, not instead of it. Notes hold the why; tripwires hold the when. A lesson that keeps firing and keeps being ignored should be promoted to block; one that never fires in months can be retired.

Test

claude plugin validate .
claude plugin test .      # 13 tests: every built-in fires on its mistake and stays quiet on the fix

関連作品