
English · 简体中文 · 日本語
https://github.com/user-attachments/assets/55887071-c722-4ed3-85c8-2ed00ba96b01
CC Safety Net (Coding CLI Safety Net) blocks destructive commands and access to secrets such as SSH keys and .env files before the tool call runs. It parses what the command does. Wrapping the command or reordering flags does not hide it. A broken config file never blocks anything.
[!NOTE]
Full documentation → covers installation, configuration, reference material, guides, and the security model. This README is the short version.
Supported coding CLIs
CC Safety Net supports the coding agent CLIs below on Windows, macOS, and Linux. Automated tests cover the analyzer and some Windows integrations. Windows support for the remaining CLIs is best effort and has not been tested.
Amp documents macOS, Linux, and WSL, but not native Windows.
Features
-
Blocks destructive commands. git reset --hard, git push --force, rm -rf on dangerous targets, find -delete, and PowerShell Remove-Item. The hook still blocks the same command inside bash -c or python -c. A sandbox still allows git reset --hard inside your project. See vs Sandboxing.
-
Blocks secret access. SSH keys, .env files, ~/.aws, and the credential files coding CLIs keep. The rules cover the shell and the agent's read, edit, write, and search tools. Blocking a CLI's own settings files is optional. It stays off until you turn it on.
-
Customize the rules in a GUI. Run npx cc-safety-net gui and open Policy. Turn individual block and secret rules off. Add paths to allow or deny. You cannot turn off the rules that catch wiping / or ~.
-
Adds blocks through rulebooks. Official packs for Terraform, AWS, gcloud, and Azure, or JSON you write yourself. A rulebook can only add blocks. It cannot turn built-in protection off. The packs live in cc-safety-net/rulebooks. Install a pack with:
npx -y cc-safety-net rule add --only terraform aws --global
See Official Rulebooks.
-
Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions pick up the same rules. If a project file tries to loosen a member's stricter settings, status and doctor report it. policy apply asks for confirmation in a terminal. Copying the folder is not enough. The hook still has to be installed. See Team Setup and Cloud Environments.
-
Embeds in your own tools. Install the npm package and call checkCommand to get allow or deny from your own code. No hook required. See Library API.
Full rule catalogs: Blocked Commands · Allowed Commands · Secret Protection.
Quick start
You need Node.js 18 or higher.
To install into the coding CLIs on this machine, run:
npx -y cc-safety-net@latest install
To update every installed integration:
npx -y cc-safety-net@latest update
Keep the @latest qualifier. A bare cc-safety-net spec can run an older copy from the npx cache. To uninstall, run npx -y cc-safety-net uninstall. npm install -g cc-safety-net also installs the ccsn alias.
OpenCode integration supports v1.18.29+ and v2.0.6+. Run npx -y cc-safety-net@latest install --opencode; the installer selects the host's plugin commands. See OpenCode compatibility for v2 shell configuration and host limitations.
OpenClaw integration requires OpenClaw 2026.8.1+. The installer accepts the plugin's declared capabilities for you, and older OpenClaw releases reject that option.
Safety presets
To set a preset, run npx cc-safety-net gui and open Policy.
| Preset | Effect |
|---|
| Standard | Blocks recognizable destructive Git and filesystem commands. Allows metadata-only checks of built-in sensitive paths while continuing to block content access. Recommended for normal coding. |
| Strict | Standard, plus blocks dynamic or unparseable commands the analyzer cannot verify safely. Also blocks metadata-only discovery of built-in sensitive paths. Occasional false positives on advanced shell. |
| Paranoid | Strict, plus blocks rm -rf inside your project and interpreter one-liners. Expect friction; for untrusted agents or high-stakes repos. |
Linked-worktree mode relaxes only local discard. Git discards inside a temp-root repository unrelated to the workspace are allowed like temp deletes (local discards only when that repository is a linked worktree), as is git worktree remove --force of an existing temp-root directory unrelated to the workspace. See Modes.
To allow one file name you manage at any depth under a folder, add an entry such as "~/code/**/.env.local" to secret_protection.allow_paths in your user policy. Other env variants stay blocked. The folder before **/ is required and cannot be your home directory or a folder above it, so home credentials such as ~/.ssh and ~/.npmrc stay protected. Only a folder, **/, and an exact file name are supported; configured deny paths and Coding CLI protections still win. Many frameworks keep local secrets in .env.local, so allow it only if that matches how you use it.
Diagnostics
# Summarize what is being enforced right now
npx cc-safety-net status
# Verify your installation and run a self-test
npx cc-safety-net doctor
# Trace how a command is analyzed step-by-step
npx cc-safety-net explain "git reset --hard"
# Browse recorded denials from the audit trail (add --all to include allowed commands)
npx cc-safety-net logs
# Review what was blocked and edit your policy in a local web GUI
npx cc-safety-net gui
doctor, explain, and logs support --json for machine-readable output. The audit trail stays on your machine. It records command decisions, but it does not record command output or prompts.
Details: CLI Commands · Explain Trace · Audit Log · Dashboard · Configuration Recovery.
Limitations
CC Safety Net denies a tool call before it runs. It does not set filesystem permissions, watch network egress, or contain a process.
The policy and secret-path extractors are mostly POSIX. For PowerShell they resolve a home prefix ($HOME, $env:USERPROFILE, $env:HOME, or ~) joined to a literal suffix with \ or /. The same check applies to Get-Content, Set-Content, Add-Content, Copy-Item, Move-Item, Remove-Item, and their aliases. Get-Content $HOME\.ssh\id_rsa is denied. A path built by concatenation, a subexpression, or Join-Path is not.
Policy-file protection matches exact paths. It does not emulate commands. Use OS permissions or a sandbox when you need that.