cleverfakealias/agents/tree/main/mods/repo-lock
repo-lock
잘못된 패키지 관리자를 사용하거나 저장소 밖에서 의존성을 바꾸는 작업을 차단하고, 상태 줄에 저장소·패키지 관리자·브랜치를 표시합니다.
이 mod 소개
repo-lock은 의존성 변경을 보호하는 Claude Code 모드입니다. 잘못된 패키지 관리자로 설치하거나 의존성을 편집할 때, 또는 git 저장소 밖에서 작업할 때 Bash와 PowerShell 도구 호출을 가로채 차단합니다. 현재 저장소, 감지된 패키지 관리자, 브랜치도 상태 줄에 표시합니다. 검증된 .claude-plugin/plugin.json 매니페스트와 훅 모듈(register.ts, rules.ts, shell.ts)을 포함한 Claude Code 플러그인으로 배포됩니다.
설치
먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.
claude plugin marketplace add cleverfakealias/agents claude plugin install repo-lock
원문 / README
agents — a clean starting point for agentic development
A small, language-neutral scaffold you copy into a repo so coding agents start
with sensible guardrails. It is Claude Code–native, with AGENTS.md as the
cross-tool contract that Cursor, Codex, Copilot, and others read too.
It is deliberately small. It leans on Claude Code's built-in controls where they exist, and adds one hook for the part that has to be project-specific: running your formatter and your tests.
What's in the box
scaffold/ ← copy this into your repo
├── AGENTS.md project facts, commands, conventions, security (fill in)
├── CLAUDE.md imports AGENTS.md, plus a few Claude-specific notes
├── .gitignore lines to add to yours
└── .claude/
├── settings.json permission rules and hook wiring
├── hooks/
│ ├── checks.mjs runs your formatter after edits, your tests before Claude finishes
│ └── checks.json the commands it runs (empty until you fill it in)
└── skills/zenn/ /zenn: optional spec-first workflow for larger work
providers.md notes for Cursor / Copilot / Codex / Gemini / Devin
mods/ user-level Claude Code mods (see mods/README.md)
tests/ node --test "tests/*.test.mjs": the hook, the scaffold rules, the mods
Setup
1. Copy the scaffold into your repo
cp -r /path/to/agents/scaffold/. /path/to/your-repo/
The trailing /. copies the contents, including the dot-directories. If the repo
already has a .gitignore, AGENTS.md, or CLAUDE.md, merge those by hand
instead of overwriting them. Node on PATH is the only requirement.
2. Fill in AGENTS.md
Replace each <!-- placeholder --> with the project's name, stack, and real
commands, and delete the sections you don't need.
3. Tell the checks hook what to run
Edit .claude/hooks/checks.json. Both lists are empty by default, which turns
the hook off.
{
"format": {
"py": "ruff format {file}",
"ts,tsx,js": "npx --no-install prettier --write {file}"
},
"verify": ["pytest -q"]
}
formatmaps file extensions to a command that runs after Claude edits a file of that type.{file}is the edited file's path, already quoted. If the command fails, its output goes back to Claude to fix.verifycommands run when Claude finishes a turn in which it edited files. If one fails, Claude keeps working until it passes.- Commands run from the repo root. A command whose tool isn't installed is
skipped.
CLAUDE_SKIP_CHECKS=1 claudeturns the hook off for a session.
4. Turn on the OS sandbox (optional)
On macOS, Linux, or WSL2, run /sandbox in Claude Code. It confines shell
commands to the project directory and to network hosts you approve. The secret
paths denied in settings.json apply inside the sandbox too.
How the guardrails work
| Layer | What it covers |
| :- | :- |
| deny rules | Secrets are never read or written: .env*, key files, ~/.ssh, cloud and registry credentials. .env.example stays usable. |
| ask rules | A person approves git push, git reset --hard, git clean, gh pr merge, CI workflow edits, and any command retried outside the sandbox. These prompt in every permission mode, including auto. |
| Built into Claude Code | Writes to .claude/, .git/, .mcp.json, and shell startup files are never auto-approved. rm -rf on the project, home, or root is always stopped. settings.json also disables bypass-permissions mode. |
| Checks hook | Your formatter and tests run without anyone remembering to. |
| AGENTS.md | Conventions and intent. It shapes what agents try; it enforces nothing. |
There are no allow rules: nothing is pre-approved. Claude Code already runs
read-only commands without asking, and saves your own "don't ask again" choices to
.claude/settings.local.json.
No permission mode is pinned either. Use Manual, auto, or plan as you prefer; the deny and ask rules hold in all of them.
Limits worth knowing
- Shell rules match the command as written.
Bash(git push *)catchesgit push origin mainbut notgit -C . push. The rules stop the usual form, not a determined workaround. For anything that must never happen, protect the branch on the remote. - Read rules don't see inside scripts. They cover Claude's file tools and
common shell readers such as
cat. A script that opens a file itself is only stopped by the OS sandbox. - The sandbox doesn't run on native Windows. Use WSL2 or a dev container there if you need real isolation.
*.pemand*.keyare denied wholesale. Delete those two lines fromsettings.jsonif your repo keeps non-secret files with those extensions.
Working on this repo
node --test "tests/*.test.mjs"
The tests exercise checks.mjs and enforce the scaffold's own rules (file size
limits, valid hook paths, rule syntax). Using another agent? See
providers.md.
Earlier versions (per-language standards skills, command-guard hooks, the multi-provider scaffolds) live in git history.
