CC Safety Net
A guard for coding agents: blocks destructive Git and file system commands and attempts to read sensitive files before they run
Low risk
We rate an entry low when it mostly gives the agent instructions and reference material.
Why this level
- It only inspects and blocks commands and sends nothing outside
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add plugins/cc-safety-netDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Run one by one in the Claude Code chat
/plugin marketplace add kenryu42/cc-safety-net
/plugin install cc-safety-net@cc-safety-net-devInstall the guard: npx -y cc-safety-net@latest install. For rules and policy open the GUI: npx cc-safety-net gui.
Other ways from the author
npx -y cc-safety-net@latest installThe installer wires the guard into detected agents.
This is third-party code. Review the repository files before installing.
What it does
CC Safety Net hooks into a coding agent and checks a command before it runs. It stops dangerous Git and file system operations and attempts to read sensitive files such as keys and settings. Rules are configurable: some blocks can be turned off, allow and deny paths can be added, and there is a policy GUI. The installer supports more than a dozen coding agents and picks the right integration for each.
Who it is for. For developers and devops engineers who give a coding agent terminal access and want a safety net.
Good fit when
- The agent runs commands in your repository
- You need to block dangerous commands and secret reads
- You want unified safety rules across several agents
Not a fit when
- The agent does not run commands at all
- You need full audit and monitoring rather than on-the-fly blocking
Example request
Install CC Safety Net into my Claude Code and enable blocking of dangerous Git commandsLimitations
It guards against accidental destructive actions, not a full sandbox: it reduces risk but does not replace least privilege and backups. Compatibility with specific agent versions is listed in the README.
How to disable. Run npx -y cc-safety-net uninstall or remove the plugin through your agent's tools.
Security check
- It only inspects and blocks commands and sends nothing outside
README in short
The README describes CC Safety Net as a pre-execution check for coding agents. Installation uses npx with an install command, plus update and uninstall, and commands status, doctor, explain and logs. Rules are configured in a policy GUI and via a rule add command. It lists supported agents and notes on OpenCode integration.
FAQ
Can I disable individual rules?
Yes, some blocks can be turned off in the policy screen, and you can add allow and deny paths. A few core rules cannot be turned off.
Which agents does it support?
A set of coding agents including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI and OpenCode; the full list is in the README.
Related
A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor
NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference
Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install
Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents