Auto-approve compound Bash commands in Claude Code — pipes, chains, subshells parsed and checked per-segment
-
Updated
Jul 29, 2026 - Shell
Auto-approve compound Bash commands in Claude Code — pipes, chains, subshells parsed and checked per-segment
Moved to cc-safe-setup (910 hooks). This repo keeps the original 16 hooks for backward compatibility.
🐕 AI-Powered Risk Assessment for Claude Code — 7-layer pipeline, native notifications, menu bar dashboard. One line install.
Flexible and deterministic Claude Code PreToolUse handler
Runtime controls for Claude Code derived from real tool-call telemetry. Pair with cc-logger to observe failures, promote recurring patterns into rules, nudge recoverable mistakes, and block irreversible ones.
Branch-aware git permissions for Claude Code — auto-approve safe git/gh commands, pause at main and destructive ops.
A PreToolUse Bash tool hook that auto-approves read-only commands
An environment-aware Claude Code PreToolUse hook for the Railway CLI. Resolves the target environment at call time - from -e or the per-directory link - so production deploys, volume deletes, and live DB shells hard-deny while read-only troubleshooting stays prompt-free. Fails closed.
The layer a sandbox doesn't give you: a PreToolUse hook that blocks unapproved spending, account creation and fund movement before the call runs, queues them for human review, and proves it actually ran -- including whether your harness fired it for subagent tool calls. Plus a spend ceiling and loop detector.
Block irreversible AI-agent actions before they run — deterministic, fail-closed action veto for Claude Code, Codex, Cursor, and other tool-using agents.
Deterministic, LLM-free PreToolUse guardrail for Claude Code and Codex CLI. Applies local policy to shell commands and supported file operations, with deny/ask decisions and audit logs.
AI Agent Memory — Fewer prompts, smarter decisions. Remembers your trust decisions across Claude Code, Codex & MCP. Free & open source.
Compile your CLAUDE.md rules to real Claude Code hooks.
Claude Code-compatible command hooks for the OMP (Oh My Pi) coding agent
Recoverability-first runtime controls for the OpenAI Codex CLI: learn from real tool-call telemetry, nudge repeated mistakes, and block irreversible actions before they run.
One-file PreToolUse hook that stops Claude Code from running catastrophic Bash commands (rm -rf ~, force-push to main, curl|sh). Zero-dep, fails open, 38-case tested.
Guard rails for Claude Code: workspace boundaries, protected branches, production targets, lost exit status, and foreground time.
A PreToolUse hook for Kiro that allows harmless tool calls, asks about sensitive ones and blocks destructive ones.
Zero-dependency Claude Code PreToolUse hook that blocks reading credential files into agent context, without false-positives on mere mentions.
Road signs for coding agents: one measured fact at the moment of action, silence otherwise
Add a description, image, and links to the pretooluse topic page so that developers can more easily learn about it.
To associate your repository with the pretooluse topic, visit your repo's landing page and select "manage topics."