MichaelP17/claude-mods/tree/main/machine-guard
machine-guard
一个 Claude Code 插件,会拦截 Bash 工具调用,并在任何会改变机器的命令(sudo、brew install、全局配置写入)执行前强制显示明确的用户对话框,即使处于 auto 模式;同时支持按项目配置 ask/block 规则。
关于这个 mod
machine-guard 会阻止 Claude 背着你修改机器。在运行安装软件、需要 root、下载镜像或编辑全局配置的命令之前,会显示包含命令及拦截原因的对话框;即使处于 auto 模式,对话框也会直接显示给你(普通权限询问可能由 auto 模式自己的审查者处理)。允许会运行一次;拒绝会阻止它,并告诉 Claude 改为把命令交给你;输入你自己的回答也会拒绝它,并把你的文字传给 Claude。
会拦截:sudo、curl … | sh、brew install/upgrade/uninstall/tap/bundle、全局 npm/pnpm/yarn/bun 安装、虚拟环境外的 pip、pipx、uv tool、cargo install、go install、gem install、dotnet tool install -g、mise、asdf、rustup、docker pull/build/create、colima delete、podman machine init/rm、defaults write、git config --global、xcode-select --install、softwareupdate、winget、choco、scoop。放行:唯读命令、项目依赖(npm install、npm ci)、.venv 内的 pip,以及启动/停止服务(交给 service-radar)。链式命令会逐段检查;引号中的文字按数据处理,所以 grep 'brew install' log 会通过。可选的 .claude/machine-guard.json 可添加带原因的项目级 ask 与 block 正则规则。无需设置;从 CLAUDE_CODE_PLUGIN_DIRS 移除该 mod 即可卸载。
安装
请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。
claude plugin marketplace add MichaelP17/claude-mods claude plugin install machine-guard
原文 / README
machine-guard
Stops Claude from changing your machine behind your back. Before a command that installs software, needs root, downloads images or edits global configuration runs, a dialog shows you the command and the reason it was caught:
Claude wants to run a command that changes this machine (brew install changes installed packages):
brew install jq
Allow it?
❯ Allow once
Deny
Allow once runs it. Deny refuses it, and Claude is told to give you the command instead. Typing your own answer, such as "use mise instead", refuses it and passes your words to Claude.
The dialog is shown to you directly, also in auto mode. A regular permission "ask" would be settled by auto mode's own reviewer, which may approve it without you.
No setup needed.
What is caught
| Caught | Let through |
| --- | --- |
| sudo, curl … \| sh | read-only commands such as brew list, docker ps |
| brew install, upgrade, uninstall, tap, bundle | project dependencies: npm install, npm ci, pnpm install |
| global npm, pnpm, yarn, bun installs | pip inside a virtual environment (.venv/bin/pip) |
| pip outside a virtual environment, pipx, uv tool, cargo install, go install, gem install, dotnet tool install -g | starting and stopping services: colima start, docker compose up, docker run, brew services start, launchctl load |
| mise install and use, asdf, rustup | git config without --global |
| docker pull, build, create, docker compose pull, build | |
| colima delete, podman machine init and rm, launchctl enable | |
| defaults write, writing git config --global, xcode-select --install, softwareupdate, winget, choco, scoop | |
Chained commands are checked part by part: in cd app && brew install jq the second part is caught. Text inside quotes is data, so searching for install commands — grep 'brew install\|cargo install' log — is let through.
Starting a service changes nothing permanent and is left to service-radar, which keeps track of what Claude started and offers to stop it. Use an ask rule (below) where starting something should still be confirmed.
Per-project rules
An optional .claude/machine-guard.json in a project adds rules for that project. match is a regular expression tested against each part of a command.
{
"ask": [
{ "match": "^dotnet (run|watch)\\b", "reason": "Starts a local instance without data" }
],
"block": [
{ "match": "^rm -rf\\b", "reason": "Never delete recursively in this project" }
]
}
| Level | Effect |
| --- | --- |
| built in | the dialog for the commands in the table above, in every project |
| ask | the dialog with reason shown, also for commands the built-in rules let through |
| block | refused without a dialog; Claude receives reason |
A command caught by a built-in rule and an ask rule shows one dialog with both reasons.
Limits
The guard recognises commands, not intentions. An installer it does not know, a script such as bash install.sh that installs internally, or a file Claude writes outside the project with its Write tool are not caught. Keep an instruction in your CLAUDE.md that Claude must not install anything unasked; the guard is the safety net under it.
Heredoc bodies are data for the program they are fed to, so text that python3, cat or tee writes into a file is not checked — documentation that mentions brew install causes no dialog. A heredoc fed to a shell (bash <<EOF, cat <<EOF | sh) is still checked line by line.
Uninstall
Remove the mod from CLAUDE_CODE_PLUGIN_DIRS. Project files .claude/machine-guard.json are ignored without it.
