PlugMyPlugin
← Browse

kube-guard

andresleecom ★ 0

kube-guard is a Claude Code plugin that gates kubectl and helm commands by blast radius (read/write/destructive/high-risk) before execution, enforcing per-context policies, blocking secret dumps and dangerous operations on protected namespaces, and logging all decisions to an audit trail. It works as a PreToolUse hook with zero dependencies, catching kubectl anywhere in a command even when permissions are disabled.

Security DevOps No API key detected runs shell

Install

> /plugin marketplace add andresleecom/kube-guard
> /plugin install kube-guard

Source: https://github.com/andresleecom/kube-guard

What it's made of

3 commands · 1 skill · 2 hooks

Commands
3
Agents
0
Skills
1
MCP servers
0
Hooks
2 · PostToolUse, PreToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
node
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (andresleecom).