Cc Safety Net (cc-safety-net)
Configure CC Safety Net rulebooks for user, project, or shareable GitHub scope.
- Type
- Skill
- Repository
- kenryu42/cc-safety-net
- GitHub stars
- 1.6k
- License
- MIT
- Repo last updated
- Sep 26, 2026
- Source file
- README.md
What Cc Safety Net (cc-safety-net) is
Cc Safety Net (cc-safety-net) is a skill published in the kenryu42/cc-safety-net repository on GitHub, which has about 1.6k stars. The repository describes itself as: “A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.”
A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.
Skills work in Claude Code and in Claude Cowork, which makes Cc Safety Net a portable way to give Claude the same method everywhere.
How to install Cc Safety Net (cc-safety-net)
Claude Code
- Download the cc-safety-net folder from the repository.
- Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
- Claude loads it automatically when a task matches; you can also run it with / and its name.
Claude Cowork
- Zip the skill folder so SKILL.md sits at the top level of the folder.
- Open Customize → Skills, click +, then upload the ZIP.
- Start a task that matches the description, or call it by name with /.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from README.md, shared under the repository's MIT license. Read the full file on GitHub.
English · 简体中文 · 日本語
https://github.com/user-attachments/assets/55887071-c722-4ed3-85c8-2ed00ba96b01
CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything.
> [!NOTE] > Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.
Supported coding CLIs
CC Safety Net supports the coding agent CLIs below on Windows, macOS, and Linux. Automated tests cover the analyzer and some Windows integrations. Windows support for the remaining CLIs is best effort and has not been tested.
Amp Code Antigravity CLI Claude Code Codex Cursor Gemini CLI GitHub Copilot CLI Grok Build Hermes Agent Kimi Code OpenClaw OpenCode Pi
Amp documents macOS, Linux, and WSL, but not native Windows.
Features
- Blocks destructive commands. git reset --hard, git push --force, rm -rf on dangerous targets, find -delete, and PowerShell Remove-Item. The hook still blocks the same command inside bash -c or python -c. A sandbox still allows git reset --hard inside your project. See vs Sandboxing.
- Blocks secret access. SSH keys, .env files, ~/.aws, and the credential files coding CLIs keep. The rules cover the shell and the agent's read, edit, write, and search tools. Blocking a CLI's own settings files is optional. It stays off until you turn it on.
- Customize the rules in a GUI. Run npx cc-safety-net gui and open Policy. Turn individual block and secret rules off. Add paths to allow or deny. You cannot turn off the rules that catch wiping / or ~.
- Adds blocks through rulebooks. Official packs for Terraform, AWS, gcloud, and Azure, or JSON you write yourself. A rulebook can only add blocks. It cannot turn built-in protection off. The packs live in cc-safety-net/rulebooks. Install a pack with:
npx -y cc-safety-net rule add --only terraform aws --globalSee Official Rulebooks.
- Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions pick up the same rules. If a project file tries to loosen a member's stricter settings, status and doctor report it. policy apply asks for confirmation in a terminal. Copying the folder is not enough. The hook still has to be installed. See Team Setup and Cloud Environments.
- Embeds in your own tools. Install the npm package and call checkCommand to get allow or deny from your own code. No hook required. See Library API.
Full rule catalogs: Blocked Commands · Allowed Commands · Secret Protection.
Quick start
You need Node.js 18 or higher.
To install into the coding CLIs on this machine, run:
npx -y cc-safety-net@latest installTo update every installed integration:
npx -y cc-safety-net@latest updateKeep the @latest qualifier. A bare cc-safety-net spec can run an older copy from the npx cache. To uninstall, run npx -y cc-safety-net uninstall. npm install -g cc-safety-net also installs the ccsn alias.
OpenCode integration supports v1.18.29+ and v2.0.6+. Run npx -y cc-safety-net@latest install --opencode; the installer selects the host's plugin commands. See OpenCode compatibility for v2 shell configuration and host limitations.
OpenClaw integration requires OpenClaw 2026.8.1+. The installer accepts the plugin's declared capabilities for you, and older OpenClaw releases reject that option.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Cc Safety Net (cc-safety-net)?
Cc Safety Net (cc-safety-net) is a skill for Claude Code and Claude Cowork from the kenryu42/cc-safety-net repository on GitHub. Configure CC Safety Net rulebooks for user, project, or shareable GitHub scope.
How do I install Cc Safety Net (cc-safety-net) in Claude Code?
Download the cc-safety-net folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.
Can I use Cc Safety Net (cc-safety-net) in Claude Cowork?
Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.
Is Cc Safety Net (cc-safety-net) safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- Cc Safety Net Block destructive commands and secret access Plugin · kenryu42/cc-safety-net
- cc-safety-net — TypeScript Style Guide with Good/Bad Pairs The clearest way to express code conventions to an agent: every rule (inline single-use vars, no unnecessary destructuring, early returns… CLAUDE.md Example · kenryu42/cc-safety-net
- A11y Audit Audit a UI or design against WCAG 2.2 AA/AAA and ARIA patterns, returning criterion-referenced findings with severity and specific fixes. Use when the user wants an accessibility check, contrast verification, keyboard/screen-reader review, or wants to confirm a component meets POUR. Skill · plugin87/ux-ui-agent-skills
- Agent Communication AI DevKit · Exchange information with active Codex, Claude Code, and other AI agents using ai-devkit agent list, detail, and send. Use… Skill · codeaholicguy/ai-devkit
- 360 Feedback Template Design a 360-degree feedback survey or write a structured 360 feedback report. Use when asked to build a 360 feedback process, write 360… Skill · mohitagw15856/pm-claude-skills
- React Native Brownfield Migration Provides an incremental adoption strategy to migrate native iOS or Android apps to React Native or Expo using… Skill · callstackincubator/agent-skills
- Wiki LLM-compiled knowledge base manager for Codex. Use it to initialize, ingest, import source collections, collect catalogs, track inventory… Skill · nvk/llm-wiki
- A3 Problem Analysis Toyota A3 problem analysis template covering 7 stages: background, current state, goals, root cause analysis, countermeasures… Skill · NeoLabHQ/context-engineering-kit