Auto-approve compound Bash commands in Claude Code — pipes, chains, subshells parsed and checked per-segment
-
Updated
Jul 29, 2026 - Shell
Auto-approve compound Bash commands in Claude Code — pipes, chains, subshells parsed and checked per-segment
Moved to cc-safe-setup (910 hooks). This repo keeps the original 16 hooks for backward compatibility.
🐕 AI-Powered Risk Assessment for Claude Code — 7-layer pipeline, native notifications, menu bar dashboard. One line install.
Flexible and deterministic Claude Code PreToolUse handler
Runtime controls for Claude Code derived from real tool-call telemetry. Pair with cc-logger to observe failures, promote recurring patterns into rules, nudge recoverable mistakes, and block irreversible ones.
A PreToolUse Bash tool hook that auto-approves read-only commands
An environment-aware Claude Code PreToolUse hook for the Railway CLI. Resolves the target environment at call time - from -e or the per-directory link - so production deploys, volume deletes, and live DB shells hard-deny while read-only troubleshooting stays prompt-free. Fails closed.
Branch-aware git permissions for Claude Code — auto-approve safe git/gh commands, pause at main and destructive ops.
Block irreversible AI-agent actions before they run — deterministic, fail-closed action veto for Claude Code, Codex, Cursor, and other tool-using agents.
Deterministic, LLM-free PreToolUse guardrail for Claude Code and Codex CLI. Applies local policy to shell commands and supported file operations, with deny/ask decisions and audit logs.
AI Agent Memory — Fewer prompts, smarter decisions. Remembers your trust decisions across Claude Code, Codex & MCP. Free & open source.
Compile your CLAUDE.md rules to real Claude Code hooks.
Claude Code-compatible command hooks for the OMP (Oh My Pi) coding agent
The layer a sandbox doesn't give you: a PreToolUse hook that blocks unapproved spending, account creation and fund movement before the call runs, queues them for human review, and proves it actually ran -- including whether your harness fired it for subagent tool calls. Plus a spend ceiling and loop detector.
Recoverability-first runtime controls for the OpenAI Codex CLI: learn from real tool-call telemetry, nudge repeated mistakes, and block irreversible actions before they run.
Zero-dependency Claude Code PreToolUse hook that blocks reading credential files into agent context, without false-positives on mere mentions.
One-file PreToolUse hook that stops Claude Code from running catastrophic Bash commands (rm -rf ~, force-push to main, curl|sh). Zero-dep, fails open, 38-case tested.
Deterministic call-level policy engine for AI coding agents — allow/deny/ask verdicts + tamper-evident audit chain.
Road signs for coding agents: one measured fact at the moment of action, silence otherwise
Free CLI diagnostic for your Claude Code setup. 20 checks across 6 dimensions. Get a score 0-100 with actionable fix commands.
Add a description, image, and links to the pretooluse topic page so that developers can more easily learn about it.
To associate your repository with the pretooluse topic, visit your repo's landing page and select "manage topics."