Show HN: Guardrails for Claude Code: blocks rm -RF, reports what loaded Developer ahmed-alstaty released a Claude Code plugin called Guardrails that blocks destructive shell commands such as recursive removal of /, ~, $HOME, ., .., *, the project directory, or anything outside it, and reports at session start which instruction files, rules, skills, hooks and plugins Claude actually loaded. The plugin enforces its rules through dependency-free python3 (3.8 or newer) scripts using PreToolUse and SessionStart hooks, tokenizes every Bash command to judge each simple command separately, and also denies edits to secrets paths including .env, *.pem, *.key, id_rsa*, credentials.json and .aws/credentials. It installs via the repository's own marketplace, alstaty, with the commands /plugin marketplace add ahmed-alstaty/guardrails-plugin and /plugin install guardrails@alstaty. A Claude Code plugin that puts hard limits around what Claude can do in your project, tells you what Claude actually loads at session start, and lints your CLAUDE.md files against Anthropic's own guidance. Three features, all enforced with plain python3 scripts and no dependencies: 1. Enforcement hooks PreToolUse : destructive shell commands and edits to secrets or protected paths are denied before the tool runs. Deployment and infrastructure files require your approval. 2. Session start report SessionStart : a compact OK / WARN / SKIPPED checklist of instruction files, rules, skills, hooks and plugins, with warnings for the mistakes the docs warn about. 3. Skills : /guardrails:guardrails-lint , /guardrails:guardrails-status and /guardrails:guardrails-test . The repository is its own marketplace alstaty , so it takes two commands in a Claude Code session: /plugin marketplace add ahmed-alstaty/guardrails-plugin /plugin install guardrails@alstaty Or from your shell: claude plugin marketplace add ahmed-alstaty/guardrails-plugin claude plugin install guardrails@alstaty add --scope project to enable it for the whole repo From a local checkout, replace the GitHub shorthand with the path: claude plugin marketplace add ./guardrails-plugin . To try it for one session without installing: claude --plugin-dir ./guardrails-plugin . Requirements: Claude Code with plugin support and python3 3.8 or newer on PATH . No pip packages. Every Bash command is tokenized quotes, escapes, && , || , ; , | , $ , backticks, bash -c , eval , sudo / env / xargs wrappers and each simple command is judged on its own, so true && rm -rf / is caught and rm build/old.log is not. | Category | Denied | Asks for approval | Allowed | |---|---|---|---| | rm / shred / unlink | recursive removal of / , ~ , $HOME , . , .. , , the project directory, anything outside it, an unexpanded $VAR/ , --no-preserve-root , protected or secrets paths | non-recursive rm of a file outside the project; xargs rm -r ; find with -delete and no filter | files and directories inside the project rm -rf build , rm -rf node modules | | git | push --force / -f / +ref / --mirror to main or master current branch is detected when no refspec is given ; pushing a deletion of main / master ; reset --hard ; clean -fd / -fx ; branch -D ; checkout -- . , checkout . , restore . ; filter-branch , filter-repo | push --force with an unknown branch; --force-with-lease to main; checkout --