ClaudeMods
☰
ZH-CN
● 0 人在线 · 浏览 0 次
赞助提交作品
GitHub 仓库 · 发布者 amahmood561

tripwire

在行动发生的瞬间触发的教训:附加到匹配工具调用上的提醒、问题或阻止。

已翻译

关于这个 mod

tripwire 是一个 Claude Code 插件,只有一个 tool.call hook。它按「应该触发它的动作」为每条教训建立索引;当 agent 即将发出匹配的工具调用时,教训会当场触发。

三种严重性:remind(照常执行,教训附加在结果上)、ask(先询问,没有回答就视为拒绝)、block(拒绝调用并告知原因)。同时命中多条时以最严格者为准,并显示所有教训。

每条 tripwire 都用 JSON 定义,包含 tool(工具名称 regex)、pattern(输入 regex)、field(可选,指定单一字段)、unless(可选,匹配时保持沉默)、redact(不重现命中的文字,用于密钥)和 source(教训来源)。内置 十二条真实错误示例,涵盖密钥泄露、commit 签名、schema 变更、发信脚本、部署验证、wrangler KV 远程操作、Apps Script 重定向、Google Sheets 公式注入等。可以在 ~/.claude/tripwires.json 中自行新增;格式错误的条目会被跳过,不会造成严重错误。

通过 /tripwires 命令可以列出所有规则、触发次数和时间,以及损坏的条目。安装方式是先 git clone,再用 claude --plugin-dir 加载;也可以把文件夹加入 ~/.claude/settings.json 的 env 区块(CLAUDE_CODE_PLUGIN_DIRS),让它在每个 session 生效。设计上强调建议不应意外中断工作、ask 采用失败即拒绝、绝不重现密钥,并与记忆机制配合:笔记保留「为什么」,tripwire 保留「何时」。可以用 claude plugin validate . 和 claude plugin test . 进行测试(共 13 项测试)。

安装

请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。

claude plugin marketplace add amahmood561/tripwire
claude plugin install tripwire
原文 / README

tripwire

Lessons that fire at the moment of action.

Agent memory is usually read once, at the start of a session, and then hoped for. Three hours later the agent is about to repeat a mistake it has a note about, and the note is nowhere near the decision.

tripwire indexes each lesson by the action that should trigger it. When a coding agent is about to make a matching tool call, the lesson fires right there:

agent runs:  npx wrangler deploy
             │
             ▼  tripwire matches
⚡ TRIPWIRE [deploy-verify-content] (remind): After this deploy, verify on CONTENT,
   not the status code: curl the live URL and grep for text that only the new version
   contains.  (learned: false 'deployed' claims, twice)

It's a Claude Code mod: a plugin with one tool.call hook.

How it works: see ARCHITECTURE.md for the design, request flow, failure model and testing.

Three severities

| Severity | What happens | |---|---| | remind | The call runs. The lesson is attached to its result, so the agent reads it right then. | | ask | You're asked first. No answer (dismissed, or no one to ask) means no. | | block | The call is refused and the agent is told why, and not to work around it. |

When several tripwires match, the strictest one wins and every lesson is shown.

A tripwire

{
  "id": "kv-list-needs-remote",
  "tool": "^Bash$",
  "field": "command",
  "pattern": "wrangler kv key (list|get)",
  "unless": "--remote",
  "severity": "remind",
  "lesson": "Without --remote, wrangler reads the LOCAL dev store and returns []. A working form looks broken.",
  "source": "half an hour lost on a client site"
}

| Field | | |---|---| | tool | Regex on the tool name: ^Bash$, ^(Edit\|Write)$, claude-in-chrome__navigate$ | | pattern | Regex (case-insensitive) on the tool input | | field | Optional. Test one input field (command, file_path, url). Default: every string in the input | | unless | Optional. If this also matches, stay quiet (e.g. --dry-run) | | redact | Never echo the matched text. Use it for tripwires that match secrets | | source | Where the lesson was learned, so it can be checked later |

Built-in tripwires

Twelve real mistakes, each with where it was learned, in hooks/tripwires.ts:

  • block: a secret (Stripe, Supabase, AWS, Resend, GitHub, JWT) in a command's text, never echoed back · Claude attribution in a commit · assets.directory pointed at the repo root
  • ask: an unwrapped schema or data change (update, drop, alter) · scripts that email real people
  • remind: verify deploys on content · wrangler kv without --remote · Apps Script redirects need GET · only commit when asked · Google Sheets formula injection · Gmail compose swallows the first keystrokes · a paused free-tier Supabase project

Add your own in ~/.claude/tripwires.json: an array, or { "tripwires": [...] }. Broken entries are skipped, never fatal, and listed by /tripwires.

Commands

/tripwires lists every tripwire, how often each fired and when, plus any broken entries.

Install

git clone https://github.com/amahmood561/tripwire ~/tripwire
claude --plugin-dir ~/tripwire          # one session

To load it in every session, add the folder to the env block of ~/.claude/settings.json:

{ "env": { "CLAUDE_CODE_PLUGIN_DIRS": "~/tripwire" } }

Design notes

  • Advice must never stop work by accident. A malformed tripwire file is skipped, not fatal. Only an explicit block or a declined ask stops a call.
  • ask fails closed. A dismissed question, or a session with no one to ask, is treated as "no".
  • Secrets are never repeated. A redact tripwire reports [redacted], never the match.
  • It pairs with memory, not instead of it. Notes hold the why; tripwires hold the when. A lesson that keeps firing and keeps being ignored should be promoted to block; one that never fires in months can be retired.

Test

claude plugin validate .
claude plugin test .      # 13 tests: every built-in fires on its mistake and stays quiet on the fix

更多类似作品