{"repo":"dwarvesf/claude-guardrails","free":true,"listed":false,"github":"https://github.com/dwarvesf/claude-guardrails","clone":"git clone https://github.com/dwarvesf/claude-guardrails.git","description":"Hardened security configuration for Claude Code; permission deny rules, shell hooks, and prompt injection defense in full and lite variants.","language":"Shell","stars":32,"topics":["ai-safety","claude-code","developer-tools","prompt-injection","security"],"license":"MIT","category":"security-tools","readme_excerpt":"claude-guardrails Hardened security configuration for Claude Code — deny rules, hooks, and prompt injection defense out of the box. Why This Exists Claude Code can read your filesystem, run shell commands, and fetch URLs autonomously. A poisoned file in a cloned repo can hijack its behavior via prompt injection. A careless tool call can leak your SSH keys or .env secrets. These configs add defense-in-depth so you don't have to think about it on every session. Full vs Lite Lite Full --- --- --- Use when Internal/trusted projects Open source repos, untrusted codebases, production credentials Credential deny rules 21 rules (SSH, AWS, GPG, kube, Azure, .env, .pem, destructive Bash, etc.) 40 rules (adds secrets dirs, shell profiles, crypto wallets, etc.) PreToolUse hooks 4 (destructive deletes, direct push, pipe-to-shell, commit-time secret scan) 6 (adds data exfiltration, permission escalation) UserPromptSubmit inbound secret scanner Yes ( scan-secrets.sh ) Yes ( scan-secrets.sh ) PreToolUse commit-time secret scan Yes ( scan-commit.sh ) Yes ( scan-commit.sh ) PostToolUse prompt injection scanner No Yes ( prompt-injection-defender.sh ) Privacy env flags Yes (telemetry, error reports, feedback survey off) Yes CLAUDE.md security rules Yes Yes Sandbox guidance Yes — this is the enforcement layer Yes + devcontainer pointer Prereqs jq jq Quick Start The script merges into your existing /.claude/settings.json (backing it up first) and is safe to run repeatedly. Install from source (git","default_branch":null,"files":null,"tree":[],"storefront":"/r/dwarvesf","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/dwarvesf/claude-guardrails/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}