{"repo":"frmoretto/hardstop","free":true,"listed":false,"github":"https://github.com/frmoretto/hardstop","clone":"git clone https://github.com/frmoretto/hardstop.git","description":"Don't let AI destroy your hard work! HardStop is a rock-solid protection for AI-generated commands. Pre-execution safety validation for Claude Code, Claude Cowork. Catches dangerous commands before they run: whether from AI mistakes, hallucinations, prompt injection, or misunderstood instructions. Seatbelts for the agentic AI era.","language":"Python","stars":31,"topics":["agentic-ai","ai-safety","claude","claude-ai","claude-code","claude-code-hooks","claude-code-plugin","claude-code-plugin-marketplace","claude-code-plugins","claude-code-plugins-marketplace"],"license":null,"category":"mcp-servers","readme_excerpt":"🛑 Hardstop 👉 ⭐ Star on GitHub if Hardstop keeps you safe! Pre-execution safety validation for AI coding agents. Validates every shell command against 428 security patterns before execution — blocking destructive operations, credential theft, infrastructure teardown, and prompt injection. Fail-closed: blocks by default when uncertain. Ecosystem: The detection patterns are published separately as hardstop-patterns (GitHub) — reusable in any Node.js tool. Installation • How It Works • Commands • Report Issue --- ⚡️ Why Hardstop? You trust your AI, but you shouldn't trust it with rm -rf / or reading your /.aws/credentials . Hardstop sits between the LLM and your system, enforcing a strict Fail-Closed policy on dangerous operations. - 🛡️ Pattern Matching: Instant regex-based detection for known threats (fork bombs, reverse shells) - 🧠 LLM Analysis: Semantic analysis for edge cases and obfuscated attacks - ⛓️ Chain Awareness: Scans every link in a command chain ( && , , ; ) - 🔐 Secrets Protection: Blocks reading of credential files ( .ssh , .aws , .env ) (v1.3) - 🍎 macOS Coverage: Keychain, diskutil, Time Machine, Gatekeeper, SIP, LaunchDaemons (v1.3.6) - 📚 LLM Guidance: Teaches Claude how to think about safety, not just blocks --- 🚀 Quick Demo Claude tries to ruin your day? Hardstop says no. --- ⚙️ How It Works Hardstop uses a two-layer verification system for Bash commands and pattern-based protection for file reads. The 428 detection patterns (Layer 1) are published as a","default_branch":null,"files":null,"tree":[],"storefront":"/r/frmoretto","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/frmoretto/hardstop/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}