← 开源
kenryu42

cc-safety-net

A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.

ApplicationsCodingTypeScript
在 GitHub 打开
增长势头
+224 小时新增 Star+0.1%
1.58k
Star
84
Fork
+12
本周
8
贡献者
创建于 2025-12-25 · 更新于 2026-10-06 · 今日第 3488 名
主要开发者
README

CC Safety Net

CI codecov Version License: MIT

English · 简体中文 · 日本語

https://github.com/user-attachments/assets/928dbe97-31e3-41d1-b35a-7941a701b056

CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything. It is not a sandbox: it does not contain processes, set filesystem permissions, or watch network egress.

[!NOTE] Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.

How it works

An AI coding agent tries to run a command or open a file. CC Safety Net checks what it would actually do before it runs. Safe calls such as git status run normally; dangerous ones such as git reset --hard never run, and the agent is told why.

Supported coding CLIs

CC Safety Net supports these coding agent CLIs on Windows, macOS, and Linux.

Amp Code
Amp Code

Antigravity CLI
Antigravity CLI

Claude Code
Claude Code

Codex
Codex

Cursor
Cursor

DeepSeek Harness
DeepSeek Harness

Devin CLI
Devin CLI

Factory Droid
Factory Droid

Gemini CLI
Gemini CLI

GitHub Copilot CLI
GitHub Copilot CLI

Grok Build
Grok Build

Hermes Agent
Hermes Agent

Kimi Code
Kimi Code

OpenClaw
OpenClaw

OpenCode
OpenCode

Pi
Pi

Features

  • Blocks destructive commands such as git reset --hard, git push --force, and rm -rf on dangerous targets, even inside bash -c or python -c. See Blocked Commands.
  • Blocks secret access to SSH keys, .env files, ~/.aws, and coding-CLI credentials, from the shell and from the agent's file tools. See Secret Protection.
  • Tunes the policy in a GUI. Run npx cc-safety-net gui to pick the Standard, Strict, or Paranoid preset and turn rules on or off. See Modes.
  • Adds blocks through rulebooks: official packs for Terraform, AWS, gcloud, and Azure, or your own JSON. See Official Rulebooks.
  • Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions get the same rules. See Team Setup.
  • Embeds in your own tools. Call checkCommand from Node.js without installing the hook. See Library API.

Quick start

You need Node.js 18 or higher. Install into the coding CLIs on this machine, then check that protection is working:

npx -y cc-safety-net@latest install
npx -y cc-safety-net@latest doctor

Update with npx -y cc-safety-net@latest update and uninstall with npx -y cc-safety-net uninstall. Keep the @latest qualifier: a bare cc-safety-net spec can run an older copy from the npx cache. Per-CLI requirements are in Installation.

Development

See CONTRIBUTING.md to report a bug or request a feature.

License

MIT