Sponsor Suno AI Music arrow_forward
Skill

Cc Safety Net (cc-safety-net)

Configure CC Safety Net rulebooks for user, project, or shareable GitHub scope.

Type
Skill
GitHub stars
1.6k
License
MIT
Repo last updated
Sep 26, 2026
Source file
README.md

What Cc Safety Net (cc-safety-net) is

Cc Safety Net (cc-safety-net) is a skill published in the kenryu42/cc-safety-net repository on GitHub, which has about 1.6k stars. The repository describes itself as: “A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.”

A skill is a folder with a SKILL.md file: frontmatter with a name and a description, followed by instructions Claude follows. Claude loads a skill automatically when a task matches its description, and you can also run it directly with a slash and its name.

Skills work in Claude Code and in Claude Cowork, which makes Cc Safety Net a portable way to give Claude the same method everywhere.

How to install Cc Safety Net (cc-safety-net)

Claude Code

  1. Download the cc-safety-net folder from the repository.
  2. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project.
  3. Claude loads it automatically when a task matches; you can also run it with / and its name.

Claude Cowork

  1. Zip the skill folder so SKILL.md sits at the top level of the folder.
  2. Open Customize → Skills, click +, then upload the ZIP.
  3. Start a task that matches the description, or call it by name with /.

New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.

Inside the source file

An excerpt from README.md, shared under the repository's MIT license. Read the full file on GitHub.

English · 简体中文 · 日本語

https://github.com/user-attachments/assets/55887071-c722-4ed3-85c8-2ed00ba96b01

CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything.

> [!NOTE] > Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.

Supported coding CLIs

CC Safety Net supports the coding agent CLIs below on Windows, macOS, and Linux. Automated tests cover the analyzer and some Windows integrations. Windows support for the remaining CLIs is best effort and has not been tested.

Amp Code Antigravity CLI Claude Code Codex Cursor Gemini CLI GitHub Copilot CLI Grok Build Hermes Agent Kimi Code OpenClaw OpenCode Pi

Amp documents macOS, Linux, and WSL, but not native Windows.

Features

  • Blocks destructive commands. git reset --hard, git push --force, rm -rf on dangerous targets, find -delete, and PowerShell Remove-Item. The hook still blocks the same command inside bash -c or python -c. A sandbox still allows git reset --hard inside your project. See vs Sandboxing.
  • Blocks secret access. SSH keys, .env files, ~/.aws, and the credential files coding CLIs keep. The rules cover the shell and the agent's read, edit, write, and search tools. Blocking a CLI's own settings files is optional. It stays off until you turn it on.
  • Customize the rules in a GUI. Run npx cc-safety-net gui and open Policy. Turn individual block and secret rules off. Add paths to allow or deny. You cannot turn off the rules that catch wiping / or ~.
  • Adds blocks through rulebooks. Official packs for Terraform, AWS, gcloud, and Azure, or JSON you write yourself. A rulebook can only add blocks. It cannot turn built-in protection off. The packs live in cc-safety-net/rulebooks. Install a pack with:
  npx -y cc-safety-net rule add --only terraform aws --global

See Official Rulebooks.

  • Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions pick up the same rules. If a project file tries to loosen a member's stricter settings, status and doctor report it. policy apply asks for confirmation in a terminal. Copying the folder is not enough. The hook still has to be installed. See Team Setup and Cloud Environments.
  • Embeds in your own tools. Install the npm package and call checkCommand to get allow or deny from your own code. No hook required. See Library API.

Full rule catalogs: Blocked Commands · Allowed Commands · Secret Protection.

Quick start

You need Node.js 18 or higher.

To install into the coding CLIs on this machine, run:

npx -y cc-safety-net@latest install

To update every installed integration:

npx -y cc-safety-net@latest update

Keep the @latest qualifier. A bare cc-safety-net spec can run an older copy from the npx cache. To uninstall, run npx -y cc-safety-net uninstall. npm install -g cc-safety-net also installs the ccsn alias.

OpenCode integration supports v1.18.29+ and v2.0.6+. Run npx -y cc-safety-net@latest install --opencode; the installer selects the host's plugin commands. See OpenCode compatibility for v2 shell configuration and host limitations.

OpenClaw integration requires OpenClaw 2026.8.1+. The installer accepts the plugin's declared capabilities for you, and older OpenClaw releases reject that option.

Before you install

  • Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
  • Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
  • Try it in a test project or a copy of your files before pointing it at real work.
  • Pin the version you tested, and review changes before updating.
  • Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.

FAQ

What is Cc Safety Net (cc-safety-net)?

Cc Safety Net (cc-safety-net) is a skill for Claude Code and Claude Cowork from the kenryu42/cc-safety-net repository on GitHub. Configure CC Safety Net rulebooks for user, project, or shareable GitHub scope.

How do I install Cc Safety Net (cc-safety-net) in Claude Code?

Download the cc-safety-net folder from the repository. Save it as ~/.claude/skills/<skill-name>/SKILL.md for all projects, or .claude/skills/<skill-name>/SKILL.md for one project. Claude loads it automatically when a task matches; you can also run it with / and its name.

Can I use Cc Safety Net (cc-safety-net) in Claude Cowork?

Zip the skill folder so SKILL.md sits at the top level of the folder. Open Customize → Skills, click +, then upload the ZIP. Start a task that matches the description, or call it by name with /.

Is Cc Safety Net (cc-safety-net) safe to install?

It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.

Similar resources

Browse all skills, subagents, and plugins →

Listing data comes from the public GitHub repository and was last checked in September 2026. Excerpts are © their authors and shared under MIT. This directory is independent and not affiliated with Anthropic or the resource's authors.