ClaudeMods
☰
ZH-TW
● 0 人在線上 · 瀏覽 0 次
贊助提交作品
GitHub 儲存庫 · 發布者 MichaelP17

machine-guard

一個 Claude Code 外掛,會攔截 Bash 工具呼叫,並在任何會變更電腦的命令(sudo、brew install、全域設定寫入)執行前強制顯示明確的使用者對話框,即使在 auto 模式也一樣;同時支援每個專案的 ask/block 規則。

MichaelP17@MichaelP17

MichaelP17/claude-mods/tree/main/machine-guard

已翻譯

關於這個 mod

machine-guard 會阻止 Claude 背著你修改電腦。在執行安裝軟體、需要 root、下載映像檔或編輯全域設定的命令之前,會顯示包含命令與攔截原因的對話框;即使在 auto 模式,對話框也會直接顯示給你(一般權限詢問可能由 auto 模式自己的審查者處理)。允許會執行一次;拒絕會阻止它,並告訴 Claude 改為把命令交給你;輸入自己的回答也會拒絕它,並把你的文字傳給 Claude。

會攔截:sudo、curl … | sh、brew install/upgrade/uninstall/tap/bundle、全域 npm/pnpm/yarn/bun 安裝、虛擬環境外的 pip、pipx、uv tool、cargo install、go install、gem install、dotnet tool install -g、mise、asdf、rustup、docker pull/build/create、colima delete、podman machine init/rm、defaults write、git config --global、xcode-select --install、softwareupdate、winget、choco、scoop。放行:唯讀命令、專案相依套件(npm install、npm ci)、.venv 內的 pip,以及啟動/停止服務(交給 service-radar)。鏈式命令會逐段檢查;引號中的文字會視為資料,所以 grep 'brew install' log 會通過。選用的 .claude/machine-guard.json 可加入帶有原因的專案級 ask 與 block 正規表示式規則。不需要設定;從 CLAUDE_CODE_PLUGIN_DIRS 移除這個 mod 即可解除安裝。

安裝

請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。

claude plugin marketplace add MichaelP17/claude-mods
claude plugin install machine-guard
原文 / README

machine-guard

Stops Claude from changing your machine behind your back. Before a command that installs software, needs root, downloads images or edits global configuration runs, a dialog shows you the command and the reason it was caught:

Claude wants to run a command that changes this machine (brew install changes installed packages):

  brew install jq

Allow it?
  ❯ Allow once
    Deny

Allow once runs it. Deny refuses it, and Claude is told to give you the command instead. Typing your own answer, such as "use mise instead", refuses it and passes your words to Claude.

The dialog is shown to you directly, also in auto mode. A regular permission "ask" would be settled by auto mode's own reviewer, which may approve it without you.

No setup needed.

What is caught

| Caught | Let through | | --- | --- | | sudo, curl … \| sh | read-only commands such as brew list, docker ps | | brew install, upgrade, uninstall, tap, bundle | project dependencies: npm install, npm ci, pnpm install | | global npm, pnpm, yarn, bun installs | pip inside a virtual environment (.venv/bin/pip) | | pip outside a virtual environment, pipx, uv tool, cargo install, go install, gem install, dotnet tool install -g | starting and stopping services: colima start, docker compose up, docker run, brew services start, launchctl load | | mise install and use, asdf, rustup | git config without --global | | docker pull, build, create, docker compose pull, build | | | colima delete, podman machine init and rm, launchctl enable | | | defaults write, writing git config --global, xcode-select --install, softwareupdate, winget, choco, scoop | |

Chained commands are checked part by part: in cd app && brew install jq the second part is caught. Text inside quotes is data, so searching for install commands — grep 'brew install\|cargo install' log — is let through.

Starting a service changes nothing permanent and is left to service-radar, which keeps track of what Claude started and offers to stop it. Use an ask rule (below) where starting something should still be confirmed.

Per-project rules

An optional .claude/machine-guard.json in a project adds rules for that project. match is a regular expression tested against each part of a command.

{
  "ask": [
    { "match": "^dotnet (run|watch)\\b", "reason": "Starts a local instance without data" }
  ],
  "block": [
    { "match": "^rm -rf\\b", "reason": "Never delete recursively in this project" }
  ]
}

| Level | Effect | | --- | --- | | built in | the dialog for the commands in the table above, in every project | | ask | the dialog with reason shown, also for commands the built-in rules let through | | block | refused without a dialog; Claude receives reason |

A command caught by a built-in rule and an ask rule shows one dialog with both reasons.

Limits

The guard recognises commands, not intentions. An installer it does not know, a script such as bash install.sh that installs internally, or a file Claude writes outside the project with its Write tool are not caught. Keep an instruction in your CLAUDE.md that Claude must not install anything unasked; the guard is the safety net under it.

Heredoc bodies are data for the program they are fed to, so text that python3, cat or tee writes into a file is not checked — documentation that mentions brew install causes no dialog. A heredoc fed to a shell (bash <<EOF, cat <<EOF | sh) is still checked line by line.

Uninstall

Remove the mod from CLAUDE_CODE_PLUGIN_DIRS. Project files .claude/machine-guard.json are ignored without it.

更多類似作品