amahmood561/tripwire
この mod について
tripwire は Claude Code のプラグインで、tool.call hook を 1 つだけ持ちます。各教訓を「発動すべき動作」に対応付けて索引化し、agent が一致するツール呼び出しを出そうとした瞬間に教訓を発動します。
重大度は 3 種類です。remind は通常どおり実行して教訓を結果に追加し、ask は先に質問して回答がなければ拒否し、block は呼び出しを拒否して理由を伝えます。同時に複数が一致した場合は最も厳しいものを採用し、すべての教訓を表示します。
各 tripwire は JSON で定義され、tool(ツール名の regex)、pattern(入力の regex)、field(任意の単一フィールド)、unless(任意。一致すると黙る)、redact(一致した文字列を再現しない。秘密情報向け)、source(教訓の出所)を含みます。秘密情報の漏えい、commit 署名、schema 変更、メール送信スクリプト、デプロイ検証、wrangler KV のリモート操作、Apps Script のリダイレクト、Google Sheets の数式インジェクションなど、実際の失敗例を 十二個内蔵しています。~/.claude/tripwires.json に自分で追加できます。形式が正しくない項目は致命的にせずスキップします。
/tripwires コマンドで全ルール、発動回数と時刻、壊れた項目を一覧できます。インストールは git clone のあと claude --plugin-dir で読み込む方法と、フォルダーを ~/.claude/settings.json の env セクション(CLAUDE_CODE_PLUGIN_DIRS)に追加してすべてのセッションで有効にする方法があります。意図しない作業の中断を避けること、ask は失敗時に拒否すること、秘密情報を決して再現しないことを重視しています。記憶機構とも組み合わせられ、ノートは「なぜ」、tripwire は「いつ」を残します。claude plugin validate . と claude plugin test . でテストできます(合計 13 項目)。
インストール
まず作者の README で marketplace とプラグイン名を確認してください。コマンドはリポジトリの構成によって変わる場合があります。
claude plugin marketplace add amahmood561/tripwire claude plugin install tripwire
原文 / README
tripwire
Lessons that fire at the moment of action.
Agent memory is usually read once, at the start of a session, and then hoped for. Three hours later the agent is about to repeat a mistake it has a note about, and the note is nowhere near the decision.
tripwire indexes each lesson by the action that should trigger it. When a coding agent is
about to make a matching tool call, the lesson fires right there:
agent runs: npx wrangler deploy
│
▼ tripwire matches
⚡ TRIPWIRE [deploy-verify-content] (remind): After this deploy, verify on CONTENT,
not the status code: curl the live URL and grep for text that only the new version
contains. (learned: false 'deployed' claims, twice)
It's a Claude Code mod: a plugin with one tool.call hook.
How it works: see ARCHITECTURE.md for the design, request flow, failure model and testing.
Three severities
| Severity | What happens |
|---|---|
| remind | The call runs. The lesson is attached to its result, so the agent reads it right then. |
| ask | You're asked first. No answer (dismissed, or no one to ask) means no. |
| block | The call is refused and the agent is told why, and not to work around it. |
When several tripwires match, the strictest one wins and every lesson is shown.
A tripwire
{
"id": "kv-list-needs-remote",
"tool": "^Bash$",
"field": "command",
"pattern": "wrangler kv key (list|get)",
"unless": "--remote",
"severity": "remind",
"lesson": "Without --remote, wrangler reads the LOCAL dev store and returns []. A working form looks broken.",
"source": "half an hour lost on a client site"
}
| Field | |
|---|---|
| tool | Regex on the tool name: ^Bash$, ^(Edit\|Write)$, claude-in-chrome__navigate$ |
| pattern | Regex (case-insensitive) on the tool input |
| field | Optional. Test one input field (command, file_path, url). Default: every string in the input |
| unless | Optional. If this also matches, stay quiet (e.g. --dry-run) |
| redact | Never echo the matched text. Use it for tripwires that match secrets |
| source | Where the lesson was learned, so it can be checked later |
Built-in tripwires
Twelve real mistakes, each with where it was learned, in hooks/tripwires.ts:
- block: a secret (Stripe, Supabase, AWS, Resend, GitHub, JWT) in a command's text, never echoed back · Claude attribution in a commit ·
assets.directorypointed at the repo root - ask: an unwrapped schema or data change (
update,drop,alter) · scripts that email real people - remind: verify deploys on content ·
wrangler kvwithout--remote· Apps Script redirects need GET · only commit when asked · Google Sheets formula injection · Gmail compose swallows the first keystrokes · a paused free-tier Supabase project
Add your own in ~/.claude/tripwires.json: an array, or { "tripwires": [...] }. Broken entries
are skipped, never fatal, and listed by /tripwires.
Commands
/tripwires lists every tripwire, how often each fired and when, plus any broken entries.
Install
git clone https://github.com/amahmood561/tripwire ~/tripwire
claude --plugin-dir ~/tripwire # one session
To load it in every session, add the folder to the env block of ~/.claude/settings.json:
{ "env": { "CLAUDE_CODE_PLUGIN_DIRS": "~/tripwire" } }
Design notes
- Advice must never stop work by accident. A malformed tripwire file is skipped, not fatal.
Only an explicit
blockor a declinedaskstops a call. askfails closed. A dismissed question, or a session with no one to ask, is treated as "no".- Secrets are never repeated. A
redacttripwire reports[redacted], never the match. - It pairs with memory, not instead of it. Notes hold the why; tripwires hold the
when. A lesson that keeps firing and keeps being ignored should be promoted to
block; one that never fires in months can be retired.
Test
claude plugin validate .
claude plugin test . # 13 tests: every built-in fires on its mistake and stays quiet on the fix
