ClaudeMods
☰
ZH-CN
● 0 人在线 · 浏览 0 次
赞助提交作品
GitHub 仓库 · 发布者 ABDUAZIZX

script-gate

一个 Claude Code 外挂,会阻止 Claude 运行直接从互联网通过管道传入的脚本,包括下载并执行的管道、编码后的 PowerShell 和 LOLBin 下载器,同时允许 curl -o 和 git clone 等安全模式。

已翻译

关于这个 mod

script-gate 是一个 Claude Code 外挂(v2.1.287+),钩住 Bash 工具以拦截危险的下载并执行模式:curl|sh、wget|bash、iwr|iex、命令替换下载、编码后的 PowerShell、LOLBin 下载器(certutil、bitsadmin、mshta、regsvr32),以及 Python 执行远程代码。curl -o file、curl|jq、git clone、npm install 和执行本地脚本等安全模式会被允许。与 CLAUDE.md 规则不同,这个钩子运行在 Claude Code 内部,因此无论对话上下文如何,命令都不会到达 shell。通过 /plugin marketplace add ABDUAZIZX/script-gate 和 /plugin install script-gate@script-gate 安装,或使用 claude --plugin-dir 运行单个会话。MIT 许可证。

安装

请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。

claude plugin marketplace add ABDUAZIZX/script-gate
claude plugin install script-gate
原文 / README

script-gate 🧱

A Claude Code mod (v2.1.287+) that stops Claude from running scripts straight from the internet.

Mod لـ Claude Code يمنع Claude من تشغيل أي سكربت يُنزَّل من الإنترنت ويُنفَّذ مباشرة — أسلوب شائع في نشر البرمجيات الخبيثة. يوقف الأمر قبل التنفيذ، ويوجّه Claude إلى الطريقة الآمنة: نزّل الملف، اعرضه على المستخدم، ولا تشغّله إلا بموافقته.

Why a mod and not just instructions?

A rule in CLAUDE.md is advice: the user can talk Claude out of it, and a malicious README or web page can try to. A mod runs inside Claude Code itself — the command never reaches the shell, whatever the conversation says.

In our test, Claude first refused because of a CLAUDE.md rule. After an explicit "I approve, run it", it tried — and script-gate blocked it. Claude then switched on its own to downloading the file without running it.

What it blocks (Bash tool)

| Pattern | Example | |---|---| | Download piped into a shell/interpreter | curl … \| sh, wget -qO- … \| bash, iwr … \| iex | | Download inside command/process substitution | bash -c "$(curl …)", bash <(curl …) | | PowerShell iex on remote content | iex (New-Object Net.WebClient).DownloadString(…) | | Encoded PowerShell | powershell -EncodedCommand … | | Windows LOLBins used as downloaders | certutil -urlcache, bitsadmin /transfer, mshta http…, regsvr32 /i:http… | | Python executing downloaded code | exec(urlopen(…).read()) |

Allowed: curl -o file, curl … | jq, iwr … -OutFile, git clone, npm install, running a local ./install.sh.

On a block it shows a 🧱 toast and a counter in the status line.

Install

/plugin marketplace add ABDUAZIZX/script-gate
/plugin install script-gate@script-gate

Or for one session:

git clone https://github.com/ABDUAZIZX/script-gate
claude --plugin-dir ./script-gate

Test

claude plugin validate .
claude plugin test .

Test samples are assembled from pieces so antivirus scanners don't flag the test file itself (Windows Defender killed a shell command containing them during development — they are real attack patterns).

Limits

  • Pattern-based: a determined attacker can obfuscate further. This is a safety net, not a sandbox.
  • It guards the model's Bash calls, not commands you type yourself with !.
  • Mods are an early-access API and may change between releases. Read any mod's code before installing it.

Also see env-guard — blocks Claude from reading .env secrets.

MIT License

更多类似作品