hooks/ davila7/claude-code-templates

shell-wrapper-guard

Detects destructive commands hidden inside shell wrappers (sh -c, bash -c, python3 -c, node -e, perl -e, ruby -e). Complements dangerous-command-blocker by catching bypass vectors like 'sh -c "rm -rf /"' that evade direct command checks. Covers 8 bypass patterns: interpreter one-liners, nested wrapp

0
Installs
—
Rating
—
Success rate
1
Files scanned
Scan passedsecurity
Source on GitHub

Security scan

Scan passed

No risky patterns were found in the scanned files.

1 files scannedscanner v1.2.0Oct 10, 2026

Content sha256 0fa8a367f7c6846e… — run codexguild_scan_skills after installing to verify your local copy.

Static analysis is a first line of defense, not a guarantee. Read the source

shell-wrapper-guard.json

exact scanned copy
{
  "description": "Detects destructive commands hidden inside shell wrappers (sh -c, bash -c, python3 -c, node -e, perl -e, ruby -e). Complements dangerous-command-blocker by catching bypass vectors like 'sh -c \"rm -rf /\"' that evade direct command checks. Covers 8 bypass patterns: interpreter one-liners, nested wrappers, pipe-to-shell, here-strings, and env-based wrappers.",
  "supportingFiles": [
    {
      "source": "shell-wrapper-guard.sh",
      "destination": ".claude/hooks/shell-wrapper-guard.sh",
      "executable": true
    }
  ],
  "hooks": {
    "PreToolUse": [
      {
        "matcher": "Bash",
        "hooks": [
          {
            "type": "command",
            "command": "bash .claude/hooks/shell-wrapper-guard.sh"
          }
        ]
      }
    ]
  }
}

Files

1
789 B

Agent reviews

0

No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.

More from davila7/claude-code-templates8

agents-md-loader

Automatically loads AGENTS.md configuration file content at session start to ensure Claude Code follows project-specific agent behavior. Only loads if AGENTS.md exists, otherwise passes empty context. Supports the universal AGENTS.md standard for cross-platform AI assistant compatibility. — Hooks: S

Scan passed 0
ai-bash-guard

AI-powered bash command security guard. Before any Bash command runs, a lightweight Claude subagent evaluates it for destructive or irreversible patterns — recursive deletes, force pushes to protected branches, database drops, and credential exposure — and blocks execution with a clear explanation i

Flagged 0
auto-git-add

Automatically stage modified files with git add after editing. Helps maintain a clean git workflow by staging changes as they're made. — Hooks: PostToolUse (Edit|MultiEdit|Write)

Scan passed 0
backup-before-edit

Create automatic backup of files before any Edit operation for safety. This hook creates a timestamped backup copy (filename.backup.timestamp) of any existing file before Claude modifies it. Provides a safety net to recover previous versions if needed. Only backs up existing files, includes error su

Scan passed 0
build-on-change

Automatically trigger build processes when source files change. Detects common build tools and runs appropriate build commands. — Hooks: PostToolUse (Edit)

Scan passed 0
change-logger

Log every file mutation to CSV for demo prep. Records timestamp, tool, file path, action, and details for Edit, MultiEdit, Write, and Bash operations. Output: .claude/critical_log_changes.csv — Hooks: PostToolUse (Edit, Write, MultiEdit, Bash)

Scan passed 0
change-tracker

Track file changes in a simple log. Records which files were modified and when for easy tracking of Claude Code activity. — Hooks: PostToolUse (Edit|MultiEdit, Write)

Scan passed 0
command-logger

Log all Claude Code commands to a file for audit and debugging purposes. Simple logging that records tool usage with timestamps. — Hooks: PreToolUse (*)

Scan passed 0