ClaudeMods
☰
ZH-TW
● 0 人在線上 · 瀏覽 0 次
贊助提交作品
GitHub 儲存庫 · 發布者 amahmood561

tripwire

在行動發生的瞬間觸發的教訓:附加到符合工具呼叫上的提醒、問題或阻擋。

已翻譯

關於這個 mod

tripwire 是一個 Claude Code 外掛,只有一個 tool.call hook。它按照「應該觸發它的動作」為每條教訓建立索引;當 agent 即將發出符合的工具呼叫時,教訓會當場觸發。

三種嚴重性:remind(照常執行,教訓附加在結果上)、ask(先詢問,沒有回答就視為拒絕)、block(拒絕呼叫並告知原因)。同時命中多條時以最嚴格者為準,並顯示所有教訓。

每條 tripwire 都用 JSON 定義,包含 tool(工具名稱 regex)、pattern(輸入 regex)、field(可選,指定單一欄位)、unless(可選,符合時保持安靜)、redact(不重現命中的文字,用於密鑰)和 source(教訓來源)。內建 十二條真實錯誤範例,涵蓋密鑰外洩、commit 簽署、schema 變更、寄信腳本、部署驗證、wrangler KV 遠端操作、Apps Script 重導、Google Sheets 公式注入等。可以在 ~/.claude/tripwires.json 中自行新增;格式錯誤的條目會被跳過,不會造成致命錯誤。

透過 /tripwires 指令可以列出所有規則、觸發次數和時間,以及損壞的條目。安裝方式是先 git clone,再用 claude --plugin-dir 載入;也可以把資料夾加入 ~/.claude/settings.json 的 env 區塊(CLAUDE_CODE_PLUGIN_DIRS),讓它在每個工作階段生效。設計上強調建議不應意外中斷工作、ask 採取失敗即拒絕、密鑰絕不重現,並與記憶機制搭配:筆記保留「為什麼」,tripwire 保留「何時」。可以用 claude plugin validate . 和 claude plugin test . 進行測試(共 13 項測試)。

安裝

請先查看作者 README,確認 marketplace 與外掛名稱;指令可能隨儲存庫結構而變動。

claude plugin marketplace add amahmood561/tripwire
claude plugin install tripwire
原文 / README

tripwire

Lessons that fire at the moment of action.

Agent memory is usually read once, at the start of a session, and then hoped for. Three hours later the agent is about to repeat a mistake it has a note about, and the note is nowhere near the decision.

tripwire indexes each lesson by the action that should trigger it. When a coding agent is about to make a matching tool call, the lesson fires right there:

agent runs:  npx wrangler deploy
             │
             ▼  tripwire matches
⚡ TRIPWIRE [deploy-verify-content] (remind): After this deploy, verify on CONTENT,
   not the status code: curl the live URL and grep for text that only the new version
   contains.  (learned: false 'deployed' claims, twice)

It's a Claude Code mod: a plugin with one tool.call hook.

How it works: see ARCHITECTURE.md for the design, request flow, failure model and testing.

Three severities

| Severity | What happens | |---|---| | remind | The call runs. The lesson is attached to its result, so the agent reads it right then. | | ask | You're asked first. No answer (dismissed, or no one to ask) means no. | | block | The call is refused and the agent is told why, and not to work around it. |

When several tripwires match, the strictest one wins and every lesson is shown.

A tripwire

{
  "id": "kv-list-needs-remote",
  "tool": "^Bash$",
  "field": "command",
  "pattern": "wrangler kv key (list|get)",
  "unless": "--remote",
  "severity": "remind",
  "lesson": "Without --remote, wrangler reads the LOCAL dev store and returns []. A working form looks broken.",
  "source": "half an hour lost on a client site"
}

| Field | | |---|---| | tool | Regex on the tool name: ^Bash$, ^(Edit\|Write)$, claude-in-chrome__navigate$ | | pattern | Regex (case-insensitive) on the tool input | | field | Optional. Test one input field (command, file_path, url). Default: every string in the input | | unless | Optional. If this also matches, stay quiet (e.g. --dry-run) | | redact | Never echo the matched text. Use it for tripwires that match secrets | | source | Where the lesson was learned, so it can be checked later |

Built-in tripwires

Twelve real mistakes, each with where it was learned, in hooks/tripwires.ts:

  • block: a secret (Stripe, Supabase, AWS, Resend, GitHub, JWT) in a command's text, never echoed back · Claude attribution in a commit · assets.directory pointed at the repo root
  • ask: an unwrapped schema or data change (update, drop, alter) · scripts that email real people
  • remind: verify deploys on content · wrangler kv without --remote · Apps Script redirects need GET · only commit when asked · Google Sheets formula injection · Gmail compose swallows the first keystrokes · a paused free-tier Supabase project

Add your own in ~/.claude/tripwires.json: an array, or { "tripwires": [...] }. Broken entries are skipped, never fatal, and listed by /tripwires.

Commands

/tripwires lists every tripwire, how often each fired and when, plus any broken entries.

Install

git clone https://github.com/amahmood561/tripwire ~/tripwire
claude --plugin-dir ~/tripwire          # one session

To load it in every session, add the folder to the env block of ~/.claude/settings.json:

{ "env": { "CLAUDE_CODE_PLUGIN_DIRS": "~/tripwire" } }

Design notes

  • Advice must never stop work by accident. A malformed tripwire file is skipped, not fatal. Only an explicit block or a declined ask stops a call.
  • ask fails closed. A dismissed question, or a session with no one to ask, is treated as "no".
  • Secrets are never repeated. A redact tripwire reports [redacted], never the match.
  • It pairs with memory, not instead of it. Notes hold the why; tripwires hold the when. A lesson that keeps firing and keeps being ignored should be promoted to block; one that never fires in months can be retired.

Test

claude plugin validate .
claude plugin test .      # 13 tests: every built-in fires on its mistake and stays quiet on the fix

更多類似作品