template

Guardrails Kit for Claude Code

PreToolUse hooks that stop an agent from force-pushing, pushing to the branch that deploys, committing a live API key, or sweeping another session's work into its commit.

Get it on Gumroad, €5 Instant download

➜ tree what-you-get/

  • ├── ✓ Push gate: no force push, no push to protected branches, held commands such as npm publish wait for a human
  • ├── ✓ Staging gate: no git add -A, git add . or git commit -a, with 99 blocked and allowed test cases
  • ├── ✓ Secret gate: no live key written to a tracked file, committed, or staged through .env
  • ├── ✓ Skill gate: a named skill must run before the edits or commands you choose
  • ├── ✓ Session detection plus worktree.py: one worktree per session, .env copied, node_modules linked
  • └── ✓ An installer that runs every self-test and live-tests the installed hooks, plus a Claude Code subagent that installs it for you

Rules in CLAUDE.md are prose, and an agent forty turns into a task drops prose. These are PreToolUse hooks: Claude Code runs them before every matching tool call, and a deny stops the call, bypass-permissions mode included.

Every gate came from a real incident on a real project, and every gate ships with a self-test that proves it blocks the bad case and lets the lookalikes through. Python 3.9+ standard library only, no pip install, no network calls. Windows, macOS and Linux. An independent kit, not made by or affiliated with Anthropic.

solves this fix My fix reverted itself after an update, four times, and the grep that guarded it missed a third of the damage