CC Safety Net

A guard for coding agents: blocks destructive Git and file system commands and attempts to read sensitive files before they run

Plugin

Low risk

We rate an entry low when it mostly gives the agent instructions and reference material.

Why this level

  • It only inspects and blocks commands and sends nothing outside
All reasons and checks

kenryu42/cc-safety-net

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/cc-safety-net

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add kenryu42/cc-safety-net
/plugin install cc-safety-net@cc-safety-net-dev

Checked against the repository on Sep 25, 2026, commit 6d9b39b.

Text for your agent

Install the guard: npx -y cc-safety-net@latest install. For rules and policy open the GUI: npx cc-safety-net gui.

Other ways from the author
npx -y cc-safety-net@latest install

The installer wires the guard into detected agents.

This is third-party code. Review the repository files before installing.

What it does

CC Safety Net hooks into a coding agent and checks a command before it runs. It stops dangerous Git and file system operations and attempts to read sensitive files such as keys and settings. Rules are configurable: some blocks can be turned off, allow and deny paths can be added, and there is a policy GUI. The installer supports more than a dozen coding agents and picks the right integration for each.

Who it is for. For developers and devops engineers who give a coding agent terminal access and want a safety net.

Good fit when

  • The agent runs commands in your repository
  • You need to block dangerous commands and secret reads
  • You want unified safety rules across several agents

Not a fit when

  • The agent does not run commands at all
  • You need full audit and monitoring rather than on-the-fly blocking

Example request

Install CC Safety Net into my Claude Code and enable blocking of dangerous Git commands

Limitations

It guards against accidental destructive actions, not a full sandbox: it reduces risk but does not replace least privilege and backups. Compatibility with specific agent versions is listed in the README.

How to disable. Run npx -y cc-safety-net uninstall or remove the plugin through your agent's tools.

Security check

  • It only inspects and blocks commands and sends nothing outside

README in short

The README describes CC Safety Net as a pre-execution check for coding agents. Installation uses npx with an install command, plus update and uninstall, and commands status, doctor, explain and logs. Rules are configured in a policy GUI and via a rule add command. It lists supported agents and notes on OpenCode integration.

FAQ

Can I disable individual rules?

Yes, some blocks can be turned off in the policy screen, and you can add allow and deny paths. A few core rules cannot be turned off.

Which agents does it support?

A set of coding agents including Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI and OpenCode; the full list is in the README.

Editors’ pick

A code security audit skill by Cloudflare: the agent runs recon, coverage-led hunting and independent verification of findings, then produces a structured repor

SkillMedium riskNo VPN needed22.6KRepository stars
Editors’ pick

NVIDIA's open stack for running OpenClaw, Hermes and LangChain Deep Agents in OpenShell sandboxes with network policy and managed inference

CLIHigh risk22.6KRepository stars
Editors’ pick

Security scanner for agent skills and MCP servers: finds prompt injection, data exfiltration and supply chain risks before install

CLIMedium riskNo VPN needed18.5KRepository stars
Official

Static code analysis with rules that look like source code, plus a built-in MCP server for AI agents

CLIMedium risk16.8KRepository stars
Foxx AICC Safety Net

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.