ShriD5/claude-mods/tree/main/main-guard
main-guard
보호된 브랜치나 프로덕션 환경에 있을 때 빨간 경고 밴드를 표시하고, 그곳에서 force-push와 reset --hard 같은 되돌릴 수 없는 git 작업을 막는 Claude Code 플러그인입니다.
이 mod 소개
main-guard는 위험한 상황에서 Claude Code를 사용할 때 안전 계층을 추가합니다. 현재 git 브랜치가 보호 대상이거나(기본값은 main, master, production, release*), 프로덕션 환경 변수(NODE_ENV, RAILS_ENV, APP_ENV, ENVIRONMENT)가 prod/production으로 설정되어 있거나, .prod 마커 파일이 있으면 프롬프트 위에 빨간 밴드를 표시합니다.
Bash 도구를 호출할 때마다 git 명령을 분석하고(&&, 파이프, git -C, 환경 변수 접두사, bash -c 처리), 보호된 브랜치에서는 git push --force/-f/--force-with-lease/+refspec, git push --delete/:branch/--mirror, git reset --hard를 거부합니다. main으로 보내는 일반 git push에는 확인을 요청합니다. 거부된 호출은 셸에 도달하지 않으며 Claude에는 이유와 브랜치 push, PR 열기, git switch -c 사용 같은 더 안전한 대안이 전달됩니다.
claude --plugin-dir ./main-guard로 설치하거나 저장소를 마켓플레이스에 추가한 뒤 /plugin을 사용하세요. 옵션에는 protectedBranches(쉼표로 구분하며 * 와일드카드 지원)와 confirmPushes(기본값 true)가 있습니다. 이는 agent용 안전벨트이지 보안 경계가 아닙니다. 실행 중 git 호출을 만드는 명령(eval, 스크립트 파일)은 검사하지 않습니다.
설치
먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.
claude plugin marketplace add ShriD5/claude-mods claude plugin install main-guard
원문 / README
main-guard
Puts a red band above the prompt whenever you are somewhere you can hurt production, and stops Claude from doing the irreversible git things there.
⚠ on main · NODE_ENV=production force-push and reset --hard are blocked
The band comes up when any of these is true:
- the current git branch is protected (
main,master,production,release*by default) NODE_ENV,RAILS_ENV,APP_ENVorENVIRONMENTisprod/production- a
.prodmarker file sits in the working directory or the repo root
On every Bash call Claude makes, main-guard reads the git commands out of it (through &&, pipes, git -C dir, env prefixes and bash -c "...") and:
| command | on a protected branch |
| --- | --- |
| git push --force / -f / --force-with-lease / +refspec | denied |
| git push --delete / :branch, git push --mirror | denied |
| git reset --hard | denied |
| plain git push (to main, HEAD:main, or while on main) | asks you first: "Push straight to main?" |
A denied call never reaches the shell; Claude gets the reason and a better route (push a branch, open a PR, git switch -c rescue before resetting). If there is nobody to ask (a -p run), the plain push is denied with the same advice.
Install
claude --plugin-dir ./main-guard
or add this repo as a marketplace and install it with /plugin.
Options
| option | default | what it does |
| --- | --- | --- |
| protectedBranches | main, master, production, release* | Comma-separated; * matches anything, so release* covers release/2.1. |
| confirmPushes | true | Off: plain pushes to a protected branch are refused outright instead of asking. |
How it works
A tool.call hook on Bash parses the command and answers { deny } or asks with $.ui.ask before calling next; the band is an AbovePrompt render of state refreshed on session.start, after every Bash call and every 15 s on $.clock.every.
This is a seatbelt for an agent, not a security boundary: a command that builds a git call at run time (eval, a script file) is not read.
