ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 MichaelP17

machine-guard

Bash 도구 호출을 가로채고 auto 모드에서도 컴퓨터를 변경하는 명령(sudo, brew install, 전역 설정 쓰기) 전에 명시적인 사용자 대화 상자를 강제하는 Claude Code 플러그인입니다. 프로젝트별 ask/block 규칙도 지원합니다.

MichaelP17@MichaelP17

MichaelP17/claude-mods/tree/main/machine-guard

번역 완료

이 mod 소개

machine-guard는 Claude가 뒤에서 컴퓨터를 바꾸지 못하게 합니다. 소프트웨어 설치, root 권한 필요, 이미지 다운로드 또는 전역 설정 편집을 하는 명령을 실행하기 전에 명령과 차단된 이유를 보여 주는 대화 상자가 나타납니다. auto 모드에서도 대화 상자는 사용자에게 직접 표시됩니다(일반 권한 요청은 auto 모드의 자체 검토자가 처리할 수 있음)。허용하면 한 번 실행하고, 거부하면 실행하지 않으며 Claude에게 대신 명령을 넘겨 달라고 말합니다. 직접 답을 입력해도 거부되고 그 문장이 Claude에 전달됩니다.

차단 대상: sudo, curl … | sh, brew install/upgrade/uninstall/tap/bundle, 전역 npm/pnpm/yarn/bun 설치, virtualenv 밖의 pip, pipx, uv tool, cargo install, go install, gem install, dotnet tool install -g, mise, asdf, rustup, docker pull/build/create, colima delete, podman machine init/rm, defaults write, git config --global, xcode-select --install, softwareupdate, winget, choco, scoop입니다. 통과 대상: 읽기 전용 명령, 프로젝트 의존성(npm install, npm ci), .venv 안의 pip, 서비스 시작/중지(service-radar에 맡김)입니다. 연결된 명령은 부분별로 검사하고 인용된 텍스트는 데이터로 처리하므로 grep 'brew install' log는 통과합니다. 선택 사항인 .claude/machine-guard.json에 이유와 함께 프로젝트별 ask 및 block 정규식 규칙을 추가할 수 있습니다. 설정은 필요 없으며 CLAUDE_CODE_PLUGIN_DIRS에서 mod를 제거하면 제거됩니다.

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add MichaelP17/claude-mods
claude plugin install machine-guard
원문 / README

machine-guard

Stops Claude from changing your machine behind your back. Before a command that installs software, needs root, downloads images or edits global configuration runs, a dialog shows you the command and the reason it was caught:

Claude wants to run a command that changes this machine (brew install changes installed packages):

  brew install jq

Allow it?
  ❯ Allow once
    Deny

Allow once runs it. Deny refuses it, and Claude is told to give you the command instead. Typing your own answer, such as "use mise instead", refuses it and passes your words to Claude.

The dialog is shown to you directly, also in auto mode. A regular permission "ask" would be settled by auto mode's own reviewer, which may approve it without you.

No setup needed.

What is caught

| Caught | Let through | | --- | --- | | sudo, curl … \| sh | read-only commands such as brew list, docker ps | | brew install, upgrade, uninstall, tap, bundle | project dependencies: npm install, npm ci, pnpm install | | global npm, pnpm, yarn, bun installs | pip inside a virtual environment (.venv/bin/pip) | | pip outside a virtual environment, pipx, uv tool, cargo install, go install, gem install, dotnet tool install -g | starting and stopping services: colima start, docker compose up, docker run, brew services start, launchctl load | | mise install and use, asdf, rustup | git config without --global | | docker pull, build, create, docker compose pull, build | | | colima delete, podman machine init and rm, launchctl enable | | | defaults write, writing git config --global, xcode-select --install, softwareupdate, winget, choco, scoop | |

Chained commands are checked part by part: in cd app && brew install jq the second part is caught. Text inside quotes is data, so searching for install commands — grep 'brew install\|cargo install' log — is let through.

Starting a service changes nothing permanent and is left to service-radar, which keeps track of what Claude started and offers to stop it. Use an ask rule (below) where starting something should still be confirmed.

Per-project rules

An optional .claude/machine-guard.json in a project adds rules for that project. match is a regular expression tested against each part of a command.

{
  "ask": [
    { "match": "^dotnet (run|watch)\\b", "reason": "Starts a local instance without data" }
  ],
  "block": [
    { "match": "^rm -rf\\b", "reason": "Never delete recursively in this project" }
  ]
}

| Level | Effect | | --- | --- | | built in | the dialog for the commands in the table above, in every project | | ask | the dialog with reason shown, also for commands the built-in rules let through | | block | refused without a dialog; Claude receives reason |

A command caught by a built-in rule and an ask rule shows one dialog with both reasons.

Limits

The guard recognises commands, not intentions. An installer it does not know, a script such as bash install.sh that installs internally, or a file Claude writes outside the project with its Write tool are not caught. Keep an instruction in your CLAUDE.md that Claude must not install anything unasked; the guard is the safety net under it.

Heredoc bodies are data for the program they are fed to, so text that python3, cat or tee writes into a file is not checked — documentation that mentions brew install causes no dialog. A heredoc fed to a shell (bash <<EOF, cat <<EOF | sh) is still checked line by line.

Uninstall

Remove the mod from CLAUDE_CODE_PLUGIN_DIRS. Project files .claude/machine-guard.json are ignored without it.

비슷한 프로젝트