PlugMyPlugin
← Browse

workspace-guard

karlkfi ★ 3

workspace-guard is a PreToolUse hook that guards shell commands and file tools in Claude Code by parsing arguments and prompting for confirmation only when a path resolves outside the project root. It allows in-repo reads to run silently while catching out-of-workspace access patterns like `/etc/passwd` reads, sibling checkout writes, and unanchored process kills.

Security DevOps No API key detected runs shell

Install

> /plugin marketplace add karlkfi/claude-bouncer/tree/HEAD/plugins/workspace-guard
> /plugin install workspace-guard

Source: https://github.com/karlkfi/claude-bouncer/tree/HEAD/plugins/workspace-guard

What it's made of

1 command · 1 skill · 6 hooks

Commands
1
Agents
0
Skills
1
MCP servers
0
Hooks
6 · PostToolUse, PreToolUse

What it needs & plugs into

API keys
none
Paid services
none detected
External tools
run-python-hook.cmd
Talks to
nothing external detected

Analyzed . Facts extracted from the plugin's files. Prose generated by claude-haiku-4-5-20251001.

Is this your plugin?

Claim it to keep the card accurate and enter the weekly contest. Requires signing in as the GitHub owner (karlkfi).