Guardrails Kit for Claude Code
PreToolUse hooks that stop an agent from force-pushing, pushing to the branch that deploys, committing a live API key, or sweeping another session's work into its commit.
➜ tree what-you-get/
- ├── ✓ Push gate: no force push, no push to protected branches, held commands such as npm publish wait for a human
- ├── ✓ Staging gate: no git add -A, git add . or git commit -a, with 99 blocked and allowed test cases
- ├── ✓ Secret gate: no live key written to a tracked file, committed, or staged through .env
- ├── ✓ Skill gate: a named skill must run before the edits or commands you choose
- ├── ✓ Session detection plus worktree.py: one worktree per session, .env copied, node_modules linked
- └── ✓ An installer that runs every self-test and live-tests the installed hooks, plus a Claude Code subagent that installs it for you
Rules in CLAUDE.md are prose, and an agent forty turns into a task drops prose. These are PreToolUse hooks: Claude Code runs them before every matching tool call, and a deny stops the call, bypass-permissions mode included.
Every gate came from a real incident on a real project, and every gate ships with a self-test that proves it blocks the bad case and lets the lookalikes through. Python 3.9+ standard library only, no pip install, no network calls. Windows, macOS and Linux. An independent kit, not made by or affiliated with Anthropic.