ClaudeMods
☰
KO
● 0 명 접속 중 · 조회 0 회
후원프로젝트 제출
GitHub 저장소 · 작성자 amahmood561

tripwire

행동이 일어나는 순간 발동하는 교훈입니다. 일치하는 도구 호출에 연결된 알림, 질문 또는 차단입니다.

번역 완료

이 mod 소개

tripwire는 Claude Code 플러그인이며 tool.call hook 하나만 사용합니다. 각 교훈을 ‘발동해야 하는 행동’에 따라 색인화하고 agent가 일치하는 도구 호출을 보내려는 순간 교훈을 발동합니다.

심각도는 세 가지입니다. remind는 정상 실행하고 결과에 교훈을 덧붙이며, ask는 먼저 질문하고 답이 없으면 거부하고, block은 호출을 거부하면서 이유를 알려 줍니다. 여러 개가 동시에 일치하면 가장 엄격한 것을 적용하고 모든 교훈을 표시합니다.

각 tripwire는 JSON으로 정의하며 tool(도구 이름 regex), pattern(입력 regex), field(선택 사항인 단일 필드), unless(선택 사항이며 일치하면 조용히 있음), redact(일치한 문자열을 재현하지 않음, 비밀 키에 사용), source(교훈의 출처)를 포함합니다. 비밀 유출, commit 서명, schema 변경, 메일 전송 스크립트, 배포 검증, wrangler KV 원격 작업, Apps Script 리디렉션, Google Sheets 수식 주입 등을 다루는 실제 오류 예시 열두 개가 기본으로 들어 있습니다. ~/.claude/tripwires.json에 직접 추가할 수 있으며, 형식이 잘못된 항목은 치명적인 오류 없이 건너뜁니다.

/tripwires 명령으로 모든 규칙, 발동 횟수와 시간, 손상된 항목을 나열할 수 있습니다. git clone 후 claude --plugin-dir로 로드하거나 폴더를 ~/.claude/settings.json의 env 영역(CLAUDE_CODE_PLUGIN_DIRS)에 넣어 모든 세션에서 적용할 수 있습니다. 설계는 권고가 작업을 우연히 중단하지 않도록 하고, ask는 실패하면 거부하며, 비밀 키는 절대 재현하지 않는 데 초점을 둡니다. 메모리 기능과 함께 사용하면 노트는 ‘왜’를, tripwire는 ‘언제’를 보존합니다. claude plugin validate . 및 claude plugin test .로 테스트할 수 있습니다(총 13개 테스트).

설치

먼저 작성자의 README에서 marketplace와 플러그인 이름을 확인하세요. 저장소 구조에 따라 명령어가 달라질 수 있습니다.

claude plugin marketplace add amahmood561/tripwire
claude plugin install tripwire
원문 / README

tripwire

Lessons that fire at the moment of action.

Agent memory is usually read once, at the start of a session, and then hoped for. Three hours later the agent is about to repeat a mistake it has a note about, and the note is nowhere near the decision.

tripwire indexes each lesson by the action that should trigger it. When a coding agent is about to make a matching tool call, the lesson fires right there:

agent runs:  npx wrangler deploy
             │
             ▼  tripwire matches
⚡ TRIPWIRE [deploy-verify-content] (remind): After this deploy, verify on CONTENT,
   not the status code: curl the live URL and grep for text that only the new version
   contains.  (learned: false 'deployed' claims, twice)

It's a Claude Code mod: a plugin with one tool.call hook.

How it works: see ARCHITECTURE.md for the design, request flow, failure model and testing.

Three severities

| Severity | What happens | |---|---| | remind | The call runs. The lesson is attached to its result, so the agent reads it right then. | | ask | You're asked first. No answer (dismissed, or no one to ask) means no. | | block | The call is refused and the agent is told why, and not to work around it. |

When several tripwires match, the strictest one wins and every lesson is shown.

A tripwire

{
  "id": "kv-list-needs-remote",
  "tool": "^Bash$",
  "field": "command",
  "pattern": "wrangler kv key (list|get)",
  "unless": "--remote",
  "severity": "remind",
  "lesson": "Without --remote, wrangler reads the LOCAL dev store and returns []. A working form looks broken.",
  "source": "half an hour lost on a client site"
}

| Field | | |---|---| | tool | Regex on the tool name: ^Bash$, ^(Edit\|Write)$, claude-in-chrome__navigate$ | | pattern | Regex (case-insensitive) on the tool input | | field | Optional. Test one input field (command, file_path, url). Default: every string in the input | | unless | Optional. If this also matches, stay quiet (e.g. --dry-run) | | redact | Never echo the matched text. Use it for tripwires that match secrets | | source | Where the lesson was learned, so it can be checked later |

Built-in tripwires

Twelve real mistakes, each with where it was learned, in hooks/tripwires.ts:

  • block: a secret (Stripe, Supabase, AWS, Resend, GitHub, JWT) in a command's text, never echoed back · Claude attribution in a commit · assets.directory pointed at the repo root
  • ask: an unwrapped schema or data change (update, drop, alter) · scripts that email real people
  • remind: verify deploys on content · wrangler kv without --remote · Apps Script redirects need GET · only commit when asked · Google Sheets formula injection · Gmail compose swallows the first keystrokes · a paused free-tier Supabase project

Add your own in ~/.claude/tripwires.json: an array, or { "tripwires": [...] }. Broken entries are skipped, never fatal, and listed by /tripwires.

Commands

/tripwires lists every tripwire, how often each fired and when, plus any broken entries.

Install

git clone https://github.com/amahmood561/tripwire ~/tripwire
claude --plugin-dir ~/tripwire          # one session

To load it in every session, add the folder to the env block of ~/.claude/settings.json:

{ "env": { "CLAUDE_CODE_PLUGIN_DIRS": "~/tripwire" } }

Design notes

  • Advice must never stop work by accident. A malformed tripwire file is skipped, not fatal. Only an explicit block or a declined ask stops a call.
  • ask fails closed. A dismissed question, or a session with no one to ask, is treated as "no".
  • Secrets are never repeated. A redact tripwire reports [redacted], never the match.
  • It pairs with memory, not instead of it. Notes hold the why; tripwires hold the when. A lesson that keeps firing and keeps being ignored should be promoted to block; one that never fires in months can be retired.

Test

claude plugin validate .
claude plugin test .      # 13 tests: every built-in fires on its mistake and stays quiet on the fix

동명의 다른 작품

비슷한 프로젝트