ClaudeMods
☰
ZH-CN
● 0 人在线 · 浏览 0 次
赞助提交作品
GitHub 仓库 · 发布者 ShriD5

main-guard

一个 Claude Code 插件:当你位于受保护分支或生产环境时显示红色警告条,并在这些环境中阻止 force-push、reset --hard 等不可逆的 git 操作。

已翻译

关于这个 mod

main-guard 为 Claude Code 在高风险环境中的工作增加了一层安全保护。当当前 git 分支受保护(默认包括 main、master、production、release*),生产环境变量(NODE_ENV、RAILS_ENV、APP_ENV、ENVIRONMENT)被设置为 prod/production,或存在 .prod 标记文件时,它会在提示符上方显示红色横条。

每次调用 Bash 工具时,它都会解析 git 命令(处理 &&、管道、git -C、环境变量前缀和 bash -c),并执行以下规则:在受保护分支上拒绝 git push --force/-f/--force-with-lease/+refspec、git push --delete/:branch/--mirror 以及 git reset --hard;对直接 git push 到 main 的操作要求确认。被拒绝的调用不会进入 shell,Claude 会收到原因以及更安全的替代方案,例如推送分支、开启 PR,或使用 git switch -c。

通过 claude --plugin-dir ./main-guard 安装,或者把仓库加入市场后使用 /plugin 安装。选项包括 protectedBranches(逗号分隔,支持 * 通配符)和 confirmPushes(默认 true)。请注意,它是 agent 的安全带,不是安全边界:在运行时构造 git 调用的命令(eval、脚本文件)不会被检查。

安装

请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。

claude plugin marketplace add ShriD5/claude-mods
claude plugin install main-guard
原文 / README

main-guard

Puts a red band above the prompt whenever you are somewhere you can hurt production, and stops Claude from doing the irreversible git things there.

 ⚠ on main · NODE_ENV=production   force-push and reset --hard are blocked

The band comes up when any of these is true:

  • the current git branch is protected (main, master, production, release* by default)
  • NODE_ENV, RAILS_ENV, APP_ENV or ENVIRONMENT is prod / production
  • a .prod marker file sits in the working directory or the repo root

On every Bash call Claude makes, main-guard reads the git commands out of it (through &&, pipes, git -C dir, env prefixes and bash -c "...") and:

| command | on a protected branch | | --- | --- | | git push --force / -f / --force-with-lease / +refspec | denied | | git push --delete / :branch, git push --mirror | denied | | git reset --hard | denied | | plain git push (to main, HEAD:main, or while on main) | asks you first: "Push straight to main?" |

A denied call never reaches the shell; Claude gets the reason and a better route (push a branch, open a PR, git switch -c rescue before resetting). If there is nobody to ask (a -p run), the plain push is denied with the same advice.

Install

claude --plugin-dir ./main-guard

or add this repo as a marketplace and install it with /plugin.

Options

| option | default | what it does | | --- | --- | --- | | protectedBranches | main, master, production, release* | Comma-separated; * matches anything, so release* covers release/2.1. | | confirmPushes | true | Off: plain pushes to a protected branch are refused outright instead of asking. |

How it works

A tool.call hook on Bash parses the command and answers { deny } or asks with $.ui.ask before calling next; the band is an AbovePrompt render of state refreshed on session.start, after every Bash call and every 15 s on $.clock.every.

This is a seatbelt for an agent, not a security boundary: a command that builds a git call at run time (eval, a script file) is not read.

更多类似作品