Cc Safety Net (safety-net)
Block destructive commands and secret access
- Type
- Plugin
- Repository
- kenryu42/cc-safety-net
- GitHub stars
- 1.6k
- License
- MIT
- Repo last updated
- Sep 26, 2026
- Source file
- .claude-plugin/plugin.json
- Version
- 2.4.11
- Author
- J Liew
What Cc Safety Net (safety-net) is
Cc Safety Net (safety-net) is a plugin published in the kenryu42/cc-safety-net repository on GitHub, which has about 1.6k stars. The repository describes itself as: “A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.”
A plugin is a package that bundles skills, slash commands, subagents, hooks, and MCP connectors so they install together. Plugins are plain files with a manifest at .claude-plugin/plugin.json, and they work in both Claude Code and Claude Cowork.
Installing Cc Safety Net adds everything it ships in one step. Connectors inside a plugin still need to be connected separately, and hooks and subagents only run in Cowork and Claude Code, not in regular chat.
How to install Cc Safety Net (safety-net)
Claude Code
- Add the repository as a plugin marketplace: claude plugin marketplace add kenryu42/cc-safety-net
- Install the plugin: claude plugin install cc-safety-net@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json.
- Restart the session if the new skills or commands don't appear straight away.
Claude Cowork
- Open Customize → Plugins and choose Add marketplace.
- Enter kenryu42/cc-safety-net (the owner/repo shorthand works for GitHub).
- Find Cc Safety Net in the list, click Install, then connect any connectors it needs from its Connectors tab.
New to extending Cowork? Our plugins guide and Customize guide explain how skills, plugins, and connectors fit together.
Inside the source file
An excerpt from .claude-plugin/plugin.json, shared under the repository's MIT license. Read the full file on GitHub.
English · 简体中文 · 日本語
https://github.com/user-attachments/assets/55887071-c722-4ed3-85c8-2ed00ba96b01
CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything.
> [!NOTE] > Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.
Supported coding CLIs
CC Safety Net supports the coding agent CLIs below on Windows, macOS, and Linux. Automated tests cover the analyzer and some Windows integrations. Windows support for the remaining CLIs is best effort and has not been tested.
Amp Code Antigravity CLI Claude Code Codex Cursor Gemini CLI GitHub Copilot CLI Grok Build Hermes Agent Kimi Code OpenClaw OpenCode Pi
Amp documents macOS, Linux, and WSL, but not native Windows.
Features
- Blocks destructive commands. git reset --hard, git push --force, rm -rf on dangerous targets, find -delete, and PowerShell Remove-Item. The hook still blocks the same command inside bash -c or python -c. A sandbox still allows git reset --hard inside your project. See vs Sandboxing.
- Blocks secret access. SSH keys, .env files, ~/.aws, and the credential files coding CLIs keep. The rules cover the shell and the agent's read, edit, write, and search tools. Blocking a CLI's own settings files is optional. It stays off until you turn it on.
- Customize the rules in a GUI. Run npx cc-safety-net gui and open Policy. Turn individual block and secret rules off. Add paths to allow or deny. You cannot turn off the rules that catch wiping / or ~.
- Adds blocks through rulebooks. Official packs for Terraform, AWS, gcloud, and Azure, or JSON you write yourself. A rulebook can only add blocks. It cannot turn built-in protection off. The packs live in cc-safety-net/rulebooks. Install a pack with:
npx -y cc-safety-net rule add --only terraform aws --globalSee Official Rulebooks.
- Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions pick up the same rules. If a project file tries to loosen a member's stricter settings, status and doctor report it. policy apply asks for confirmation in a terminal. Copying the folder is not enough. The hook still has to be installed. See Team Setup and Cloud Environments.
- Embeds in your own tools. Install the npm package and call checkCommand to get allow or deny from your own code. No hook required. See Library API.
Full rule catalogs: Blocked Commands · Allowed Commands · Secret Protection.
Quick start
You need Node.js 18 or higher.
To install into the coding CLIs on this machine, run:
npx -y cc-safety-net@latest installTo update every installed integration:
npx -y cc-safety-net@latest updateKeep the @latest qualifier. A bare cc-safety-net spec can run an older copy from the npx cache. To uninstall, run npx -y cc-safety-net uninstall. npm install -g cc-safety-net also installs the ccsn alias.
OpenCode integration supports v1.18.29+ and v2.0.6+. Run npx -y cc-safety-net@latest install --opencode; the installer selects the host's plugin commands. See OpenCode compatibility for v2 shell configuration and host limitations.
OpenClaw integration requires OpenClaw 2026.8.1+. The installer accepts the plugin's declared capabilities for you, and older OpenClaw releases reject that option.
Before you install
- Read the whole file first. Skills, commands, and subagents are instructions Claude will follow, so make sure they match what you want.
- Check which tools, scripts, or MCP servers it uses. Local servers and scripts run with your permissions.
- Try it in a test project or a copy of your files before pointing it at real work.
- Pin the version you tested, and review changes before updating.
- Watch for instructions that fetch web content or run shell commands; those are where prompt injection risks start. See our prompt injection guide.
FAQ
What is Cc Safety Net (safety-net)?
Cc Safety Net (safety-net) is a plugin for Claude Code and Claude Cowork from the kenryu42/cc-safety-net repository on GitHub. Block destructive commands and secret access
How do I install Cc Safety Net (safety-net) in Claude Code?
Add the repository as a plugin marketplace: claude plugin marketplace add kenryu42/cc-safety-net Install the plugin: claude plugin install cc-safety-net@<marketplace-name>, using the marketplace name from the repository's .claude-plugin/marketplace.json. Restart the session if the new skills or commands don't appear straight away.
Can I use Cc Safety Net (safety-net) in Claude Cowork?
Open Customize → Plugins and choose Add marketplace. Enter kenryu42/cc-safety-net (the owner/repo shorthand works for GitHub). Find Cc Safety Net in the list, click Install, then connect any connectors it needs from its Connectors tab.
Is Cc Safety Net (safety-net) safe to install?
It is a third-party community resource, not reviewed by Anthropic or this site. Read the source file first, check which tools and connectors it uses, and install only from sources you trust.
Similar resources
- cc-safety-net — TypeScript Style Guide with Good/Bad Pairs The clearest way to express code conventions to an agent: every rule (inline single-use vars, no unnecessary destructuring, early returns… CLAUDE.md Example · kenryu42/cc-safety-net
- Cc Safety Net Configure CC Safety Net rulebooks for user, project, or shareable GitHub scope. Skill · kenryu42/cc-safety-net
- Pm Accounting Accounting & bookkeeping skills for finance ops and small businesses: Invoice Generator, Expense Policy, Collections Email, Financial Statement Explainer, Bookkeeping Categorization, and Cash Flow Forecast. Practical money admin — drafting aids, not tax/accounting advice. Plugin · mohitagw15856/pm-claude-skills
- Ai Devkit Make AI coding agents follow a repeatable engineering workflow with memory, verification, skills, and multi-agent setup Plugin · codeaholicguy/ai-devkit
- Pm Advanced Advanced PM skills: AI Product Canvas, Multi-Source Signal Synthesiser, Experiment Designer, Design Handoff Brief. For senior PMs working on complex or AI-powered products. Plugin · mohitagw15856/pm-claude-skills
- Tech Stack Commands for setup or update of CLAUDE.md file with best practices for specific language or framework. Plugin · NeoLabHQ/context-engineering-kit
- Pm Agentops Operate AI agents and LLM features in production: prompt regression suites, model migration plans, context-engineering reviews, agent incident postmortems, and observability specs — plus the pm-ai evaluation and cost skills they build on. Plugin · mohitagw15856/pm-claude-skills
- Tdd Introduces commands for test-driven development, common anti-patterns and skills for testing using subagents. Plugin · NeoLabHQ/context-engineering-kit