ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 ABDUAZIZX

script-gate

인터넷에서 직접 파이프로 전달된 스크립트를 Claude가 실행하지 못하게 하는 Claude Code 모드입니다. 다운로드 후 실행 파이프, 인코딩된 PowerShell, LOLBin 다운로더를 막고 curl -o와 git clone 같은 안전한 형식은 허용합니다.

번역 완료

이 mod 소개

script-gate는 Bash 도구에 훅을 걸어 위험한 다운로드 후 실행 패턴을 가로채는 Claude Code 모드(v2.1.287+)입니다. curl|sh, wget|bash, iwr|iex, 명령 치환 다운로드, 인코딩된 PowerShell, LOLBin 다운로더(certutil, bitsadmin, mshta, regsvr32), Python의 원격 코드 실행을 차단합니다. curl -o file, curl|jq, git clone, npm install, 로컬 스크립트 실행 같은 안전한 형식은 허용합니다. CLAUDE.md 규칙과 달리 훅이 Claude Code 안에서 실행되므로 대화 맥락과 관계없이 명령이 셸에 도달하지 않습니다. /plugin marketplace add ABDUAZIZX/script-gate와 /plugin install script-gate@script-gate로 설치하거나 claude --plugin-dir로 한 세션에 실행하세요. MIT 라이선스입니다.

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add ABDUAZIZX/script-gate
claude plugin install script-gate
원문 / README

script-gate 🧱

A Claude Code mod (v2.1.287+) that stops Claude from running scripts straight from the internet.

Mod لـ Claude Code يمنع Claude من تشغيل أي سكربت يُنزَّل من الإنترنت ويُنفَّذ مباشرة — أسلوب شائع في نشر البرمجيات الخبيثة. يوقف الأمر قبل التنفيذ، ويوجّه Claude إلى الطريقة الآمنة: نزّل الملف، اعرضه على المستخدم، ولا تشغّله إلا بموافقته.

Why a mod and not just instructions?

A rule in CLAUDE.md is advice: the user can talk Claude out of it, and a malicious README or web page can try to. A mod runs inside Claude Code itself — the command never reaches the shell, whatever the conversation says.

In our test, Claude first refused because of a CLAUDE.md rule. After an explicit "I approve, run it", it tried — and script-gate blocked it. Claude then switched on its own to downloading the file without running it.

What it blocks (Bash tool)

| Pattern | Example | |---|---| | Download piped into a shell/interpreter | curl … \| sh, wget -qO- … \| bash, iwr … \| iex | | Download inside command/process substitution | bash -c "$(curl …)", bash <(curl …) | | PowerShell iex on remote content | iex (New-Object Net.WebClient).DownloadString(…) | | Encoded PowerShell | powershell -EncodedCommand … | | Windows LOLBins used as downloaders | certutil -urlcache, bitsadmin /transfer, mshta http…, regsvr32 /i:http… | | Python executing downloaded code | exec(urlopen(…).read()) |

Allowed: curl -o file, curl … | jq, iwr … -OutFile, git clone, npm install, running a local ./install.sh.

On a block it shows a 🧱 toast and a counter in the status line.

Install

/plugin marketplace add ABDUAZIZX/script-gate
/plugin install script-gate@script-gate

Or for one session:

git clone https://github.com/ABDUAZIZX/script-gate
claude --plugin-dir ./script-gate

Test

claude plugin validate .
claude plugin test .

Test samples are assembled from pieces so antivirus scanners don't flag the test file itself (Windows Defender killed a shell command containing them during development — they are real attack patterns).

Limits

  • Pattern-based: a determined attacker can obfuscate further. This is a safety net, not a sandbox.
  • It guards the model's Bash calls, not commands you type yourself with !.
  • Mods are an early-access API and may change between releases. Read any mod's code before installing it.

Also see env-guard — blocks Claude from reading .env secrets.

MIT License

비슷한 프로젝트