subagent-read-only-guard
Enforces read-only subagents. A PreToolUse hook denies Edit, Write, MultiEdit, NotebookEdit and PowerShell, and any Bash or Monitor command that is not read-only, when the call comes from a subagent (detected by the agent_id field Claude Code adds only inside subagents; tested on Claude Code 2.1.296
- 0
- Installs
- —
- Rating
- —
- Success rate
- 1
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 e9158b7e665ef431… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
subagent-read-only-guard.json
{
"description": "Enforces read-only subagents. A PreToolUse hook denies Edit, Write, MultiEdit, NotebookEdit and PowerShell, and any Bash or Monitor command that is not read-only, when the call comes from a subagent (detected by the agent_id field Claude Code adds only inside subagents; tested on Claude Code 2.1.296). Shell commands pass only when every command is a bare program from a short read-only allowlist (ls, cat, grep, rg, find, jq, sort, sed -n 'N,Mp', cd, git log/diff/status/show/blame/branch/tag and similar) without the options that make it write or run other programs, including abbreviated long options. Redirection to files, command substitution, shell expansion ($VAR, {a,b}), subshells, env-var prefixes, git -c and anything the guard cannot classify are denied, including its own errors. The main conversation is never affected. Not covered: MCP tools, and git diff/blame running diff or textconv drivers already configured in the repo. Reading secrets (.env, printenv) is still allowed, so pair it with env-file-protection. Pairs with the hooks/subagents-explore-only setting, which tells subagents up front that they are exploration-only.",
"supportingFiles": [
{
"source": "subagent-read-only-guard.py",
"destination": ".claude/hooks/subagent-read-only-guard.py",
"executable": true
}
],
"hooks": {
"PreToolUse": [
{
"matcher": "Edit|Write|MultiEdit|NotebookEdit|PowerShell|Bash|Monitor",
"hooks": [
{
"type": "command",
"command": "python3 .claude/hooks/subagent-read-only-guard.py"
}
]
}
]
}
}
Files
1- subagent-read-only-guard.json
b8c61e625f1.6 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from davila7/claude-code-templates8
Automatically loads AGENTS.md configuration file content at session start to ensure Claude Code follows project-specific agent behavior. Only loads if AGENTS.md exists, otherwise passes empty context. Supports the universal AGENTS.md standard for cross-platform AI assistant compatibility. — Hooks: S
AI-powered bash command security guard. Before any Bash command runs, a lightweight Claude subagent evaluates it for destructive or irreversible patterns — recursive deletes, force pushes to protected branches, database drops, and credential exposure — and blocks execution with a clear explanation i
Automatically stage modified files with git add after editing. Helps maintain a clean git workflow by staging changes as they're made. — Hooks: PostToolUse (Edit|MultiEdit|Write)
Create automatic backup of files before any Edit operation for safety. This hook creates a timestamped backup copy (filename.backup.timestamp) of any existing file before Claude modifies it. Provides a safety net to recover previous versions if needed. Only backs up existing files, includes error su
Automatically trigger build processes when source files change. Detects common build tools and runs appropriate build commands. — Hooks: PostToolUse (Edit)
Log every file mutation to CSV for demo prep. Records timestamp, tool, file path, action, and details for Edit, MultiEdit, Write, and Bash operations. Output: .claude/critical_log_changes.csv — Hooks: PostToolUse (Edit, Write, MultiEdit, Bash)
Track file changes in a simple log. Records which files were modified and when for easy tracking of Claude Code activity. — Hooks: PostToolUse (Edit|MultiEdit, Write)
Log all Claude Code commands to a file for audit and debugging purposes. Simple logging that records tool usage with timestamps. — Hooks: PreToolUse (*)