About this project
CC Safety Net (Coding CLI Safety Net) is a security tool that intercepts tool calls from AI coding agents before they execute. It parses the command to identify destructive operations (e.g., `git reset --hard`, `git push --force`, `rm -rf` on dangerous targets, `find -delete`, PowerShell `Remove-Item`) and blocks access to sensitive files like SSH keys, `.env` files, and cloud credentials. It works across Windows, macOS, and Linux, and supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
Key features include:
- **Command analysis**: Parses commands to detect destructive intent, even when wrapped in `bash -c` or `python -c`.
- **Secret protection**: Blocks access to SSH keys, `.env`, `~/.aws`, and credential files used by coding CLIs.
- **Customizable policy**: A GUI (`npx cc-safety-net gui`) lets users toggle individual rules, add allow/deny paths, and set safety presets (Standard, Strict, Paranoid).
- **Rulebooks**: Official packs for Terraform, AWS, gcloud, and Azure, or custom JSON rulebooks, can add blocks without disabling built-in protections.
- **Team sharing**: Policy can be committed to git (`.cc-safety-net/`) for consistent enforcement across clones and cloud sessions.
- **Library API**: Node.js developers can call `checkCommand` to integrate safety checks into their own tools.
- **Diagnostics**: Commands like `status`, `doctor`, `explain`, `logs`, and `gui` provide visibility and troubleshooting.
Limitations: It does not set filesystem permissions, monitor network egress, or contain processes. Policy-file protection matches exact paths and does not emulate commands. Codex has a specific limitation with `write_stdin` events.
Installation is via `npx -y cc-safety-net@latest install`, and updates via `npx -y cc-safety-net@latest update`. Requires Node.js 18+.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.