theagitist/claude-mods/tree/main/dot-guard
dot-guard
전체 `$HOME` 작업 트리(`dot add -A`, `dot add .`, `dot add *`)를 스테이징하는 `git add`를 차단하는 Claude Code function-hook 플러그인입니다. `CLAUDE_CODE_PLUGIN_DIRS` 또는 `--plugin-dir`를 이용한 설치 방법과 사용자 지정 dotfiles 별칭을 위한 `dot-guard.wrappers` 설정을 제공합니다.
이 mod 소개
dot-guard는 theagitist/claude-mods 저장소에 있는 5개의 작은 Claude Code function-hook mod 중 하나입니다. Bash의 git add가 전체 $HOME 작업 트리를 스테이징하려 할 때(예: dot add -A, dot add ., dot add *) 호출을 거부하고 실행하는 대신 모델에 거부 이유를 반환합니다.
설치(컴퓨터별):
- 각 컴퓨터의 같은 상대 경로에 저장소를 클론합니다. 예:
git clone <remote> ~/apps/claude-mods. - Claude Code가 mod 폴더를 가리키게 합니다. 예를 들어
~/.claude/settings.json의env블록에서CLAUDE_CODE_PLUGIN_DIRS를 mod 디렉터리로 설정하거나claude --plugin-dir ~/apps/claude-mods/dot-guard로 세션마다 불러옵니다.
설정:
dot-guard.wrappers──--work-tree=$HOME으로 git을 실행하는 쉼표로 구분된 명령 이름(기본값은dot)입니다. dotfiles 별칭이 다르면 그 이름으로 설정합니다.
구조:
dot-guard/.claude-plugin/plugin.json── 플러그인 매니페스트.dot-guard/hooks/hooks.json및dot-guard/hooks/register.ts── hook 등록이며Bash의tool.call을 가로채 환경에서HOME을 읽습니다.
claude plugin validate <mod>와 claude plugin test <mod>로 검증하고 테스트합니다.
설치
먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.
claude plugin marketplace add theagitist/claude-mods claude plugin install dot-guard
원문 / README
claude-mods
Five small Claude Code mods (function-hook plugins). They run in the terminal CLI (no GUI panes), and they are written to work the same on every machine: Linux or macOS, any username, any home directory. Nothing personal is baked into the source. Per-machine values (a Telegram chat id, an email address) come from the environment, so the same checkout is safe to push publicly and hand to other people.
The mods
| Mod | What it does | How it shows |
|---|---|---|
| dot-guard | Blocks a git add that would stage your whole $HOME work-tree (dot add -A, dot add ., dot add *). One fat-finger away from committing your entire home directory. | Denies the tool call with a reason. |
| emdash-watch | Flags em-dashes the model writes into public-facing prose (.md, .html, .css, .txt, .rst). Internal files (CLAUDE.md, anything under memory/ or .claude/) are exempt. | Non-blocking note appended to the write's result, visible to the model only. |
| home-path-guard | Flags a hardcoded user home (/home/<user>, /Users/<user>) written into a file, nudging $HOME / ~. Machine-local files (*.local.*) are exempt. | Non-blocking note to the model. |
| box-status | Status line showing which box you are on, which out-of-band channel it can reach you on (telegram / email / none), and whether passwordless sudo works. | One status-line entry under the prompt. |
| idle-ping | When a turn that did real work ends, pings you out of band so you can step away. Telegram when a bot token and chat id are present, otherwise email. | Sends a message; logs to the debug sink when no channel is configured. |
Install (per machine)
Clone this repo to the same relative path on each box, for example:
git clone <your-remote> ~/apps/claude-mods
Then point Claude Code at the five folders. The cleanest cross-machine way is
CLAUDE_CODE_PLUGIN_DIRS in the env block of ~/.claude/settings.json
(which uses ~, so the one line works on every machine):
{
"env": {
"CLAUDE_CODE_PLUGIN_DIRS": "~/apps/claude-mods/dot-guard:~/apps/claude-mods/emdash-watch:~/apps/claude-mods/box-status:~/apps/claude-mods/home-path-guard:~/apps/claude-mods/idle-ping"
}
}
(On Windows the list separator is ; instead of :.)
Or load them for a single session without touching settings:
claude --plugin-dir ~/apps/claude-mods/dot-guard --plugin-dir ~/apps/claude-mods/idle-ping
Per-machine configuration (idle-ping)
idle-ping reads its target from the environment, never from source:
- Telegram (preferred when set): it reads
TELEGRAM_BOT_TOKEN(and optionallyTELEGRAM_CHAT_ID) from~/.claude/channels/telegram/.env, andTELEGRAM_CHAT_IDfrom the process environment if not in that file. Keep that file out of version control (mode600). - Email (fallback): set
CLAUDE_PING_EMAILto the recipient. The mod sends through the first mailer it finds onPATH(msmtp,sendmail,mail,mailx). - If neither is configured, it writes what it would have sent to the debug log and does nothing else.
box-status reports the same channel resolution, so a glance at the status line
tells you whether a ping would actually go out on this box.
Settings knobs
dot-guard.wrappers(defaultdot): comma-separated command names that run git with--work-tree=$HOME. Set it to your own dotfiles alias if it is notdot.idle-ping.minTools(default2): how many tool calls a turn needs before it counts as real work worth a ping. Raise it to ping less often.
Developing
Each mod is a folder with .claude-plugin/plugin.json, hooks/hooks.json, and
hooks/register.ts. Check and test one with:
claude plugin validate <mod>
claude plugin test <mod>
