ShriD5/claude-mods/tree/main/main-guard
main-guard
一個 Claude Code 外掛:位於受保護分支或正式環境時顯示紅色警告橫條,並在這些環境中阻擋 force-push、reset --hard 等不可逆的 git 操作。
關於這個 mod
main-guard 為 Claude Code 在高風險情境下的工作增加一層安全防護。當目前的 git 分支受到保護(預設包括 main、master、production、release*)、正式環境變數(NODE_ENV、RAILS_ENV、APP_ENV、ENVIRONMENT)設為 prod/production,或存在 .prod 標記檔時,它會在提示列上方顯示紅色橫條。
每次呼叫 Bash 工具時,它都會解析 git 命令(處理 &&、管線、git -C、環境變數前綴與 bash -c),並執行以下規則:在受保護分支上拒絕 git push --force/-f/--force-with-lease/+refspec、git push --delete/:branch/--mirror 以及 git reset --hard;對直接 git push 到 main 的操作要求確認。被拒絕的呼叫不會進入 shell,Claude 會收到原因以及更安全的替代方案,例如推送分支、開啟 PR,或使用 git switch -c。
透過 claude --plugin-dir ./main-guard 安裝,或把儲存庫加入市集後使用 /plugin 安裝。選項包括 protectedBranches(以逗號分隔,支援 * 萬用字元)與 confirmPushes(預設 true)。請注意,它是 agent 的安全帶,不是安全邊界:在執行階段建立 git 呼叫的命令(eval、指令檔)不會被檢查。
安裝
請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。
claude plugin marketplace add ShriD5/claude-mods claude plugin install main-guard
原文 / README
main-guard
Puts a red band above the prompt whenever you are somewhere you can hurt production, and stops Claude from doing the irreversible git things there.
⚠ on main · NODE_ENV=production force-push and reset --hard are blocked
The band comes up when any of these is true:
- the current git branch is protected (
main,master,production,release*by default) NODE_ENV,RAILS_ENV,APP_ENVorENVIRONMENTisprod/production- a
.prodmarker file sits in the working directory or the repo root
On every Bash call Claude makes, main-guard reads the git commands out of it (through &&, pipes, git -C dir, env prefixes and bash -c "...") and:
| command | on a protected branch |
| --- | --- |
| git push --force / -f / --force-with-lease / +refspec | denied |
| git push --delete / :branch, git push --mirror | denied |
| git reset --hard | denied |
| plain git push (to main, HEAD:main, or while on main) | asks you first: "Push straight to main?" |
A denied call never reaches the shell; Claude gets the reason and a better route (push a branch, open a PR, git switch -c rescue before resetting). If there is nobody to ask (a -p run), the plain push is denied with the same advice.
Install
claude --plugin-dir ./main-guard
or add this repo as a marketplace and install it with /plugin.
Options
| option | default | what it does |
| --- | --- | --- |
| protectedBranches | main, master, production, release* | Comma-separated; * matches anything, so release* covers release/2.1. |
| confirmPushes | true | Off: plain pushes to a protected branch are refused outright instead of asking. |
How it works
A tool.call hook on Bash parses the command and answers { deny } or asks with $.ui.ask before calling next; the band is an AbovePrompt render of state refreshed on session.start, after every Bash call and every 15 s on $.clock.every.
This is a seatbelt for an agent, not a security boundary: a command that builds a git call at run time (eval, a script file) is not read.
