A one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!
cc-safety-net
A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
Plugin facts
Screenshots
About this plugin
A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
Install this DSH plugin
Copy the command below and run it in your DeepSeek Harness terminal.
dsh plugin add github:kenryu42/cc-safety-net Plugins run with the permissions of your dsh process and may execute code at install time. Review the source repository and its license before installing. Pin the commit hash for reproducible installs. Plugin safety →
More about this plugin
SSH keys, .env files, /.aws, and the credential files coding CLIs keep. The rules cover the shell and the agent's read, edit, write, and search tools. Blocking a CLI's own settings files is optional. It stays off until you turn it on. - Customize the rules in a GUI. Run npx cc-safety-net gui and open Policy. Turn individual block and secret rules off. Add paths to allow or deny. You cannot turn off the rules that catch wiping / or . - Adds blocks through rulebooks. Official packs for Terraform, AWS, gcloud, and Azure, or JSON you write yourself. A rulebook can only add blocks. It cannot turn built-in protection off. The packs live in cc-safety-net/rulebooks. Install a pack with:
See Official Rulebooks. - Shares policy through git. Commit .cc-safety-net/ so clones and cloud sessions pick up the same rules. If a project file tries to loosen a member's stricter settings, status and doctor report it. policy apply asks for confirmation in a terminal. Copying the folder is not enough. The hook still has to be installed. See Team Setup and Cloud Environments. - Embeds in your…
Related guides
Learn how to choose, install, and use ui enhancements plugins.
About this plugin: cc-safety-net
What is cc-safety-net?
cc-safety-net is a ui enhancements plugin maintained by kenryu42. A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports Amp Code, Antigravity CLI, Claude Code, Codex, Cursor, DeepSeek Harness, Gemini CLI, GitHub Copilot CLI, Grok Build, Hermes Agent, Kimi Code, OpenClaw, OpenCode, and Pi.
How do I install cc-safety-net?
Run dsh plugin add github:kenryu42/cc-safety-net in your DeepSeek Harness terminal. The dsh CLI resolves the plugin from GitHub and installs it into your active profile. For reproducible installs, pin a commit hash: dsh plugin add github:kenryu42/cc-safety-net#commit.
Is cc-safety-net free?
cc-safety-net is a community open-source project released under the MIT license. You can inspect its source and install it for free.
Related plugins
A one-of-a-kind resume builder that keeps your privacy in mind. Completely secure, customizable, portable, open-source and free forever. Try it out today!