CC Safety Net 🤖 Agent Open source
Pre-execution guard that blocks destructive commands and secret access for coding agents
- GitHub stars
- 1.6k
- Stars this week
- +11
- Forks
- 84
- Licence
- MIT
- Last push
- 2026-10-02
- Maintainer
- kenryu42
npx -y cc-safety-net@latest installThird-party subagents & agents run with your permissions. Read the source before installing, and prefer pinned versions.
Works with
About CC Safety Net
What it does
CC Safety Net is a pre-execution guard for AI coding agents. Before a tool call runs, it inspects the command and blocks destructive operations and access to secrets. It parses what a command actually does, so wrapping it in bash -c or python -c, reordering flags, or otherwise disguising it does not slip past the check. It denies the call rather than sandboxing the process, and a broken config file never silently disables protection.
What is inside
Built-in rules block destructive Git and filesystem commands (git reset --hard, git push --force, rm -rf on dangerous targets, find -delete, PowerShell Remove-Item) and reads or writes to SSH keys, .env files, ~/.aws, and stored CLI credentials. Three presets (Standard, Strict, Paranoid) trade coverage against false positives, and a local web GUI lets you toggle individual rules, add allow or deny paths, and review what was blocked. Official rulebooks for Terraform, AWS, gcloud, and Azure add further blocks; a rulebook can only add restrictions, never remove built-in ones. Diagnostics include status, doctor, explain, and an on-machine audit log. A library API (checkCommand) lets you embed the analyzer in your own tools.
Works with
Claude Code, Codex, Gemini CLI, Cursor, GitHub Copilot CLI, OpenCode, Amp, and Google Antigravity, plus several other CLIs, on Windows, macOS, and Linux (some integrations are best-effort on Windows).
How to install
npx -y cc-safety-net@latest install
Maintenance and safety
MIT licensed and actively maintained, with CI and coverage badges. Requires Node.js 18 or higher. The audit trail records command decisions locally but not command output or prompts. It denies calls only; it does not set filesystem permissions, watch network egress, or contain a process, and its path matching is mostly POSIX.
Who should use it
Anyone running autonomous or semi-autonomous coding agents who wants a safety net against accidental data loss and secret exposure.
Pros
- Parses command intent so wrapping or flag reordering does not evade it
- Works across many CLIs with presets, a GUI, and a local audit log
Cons
- Denies calls only; does not sandbox, set permissions, or watch network egress
- Path matching is mostly POSIX, with limited PowerShell coverage
Similar subagents & agents
All agent workflows & frameworks →Spec Kit 🤖 AgentFree
GitHub's toolkit for spec-driven development with AI coding agents
Task Master 🤖 AgentFree
AI task management that turns a PRD into tasks your coding agent works through
Fast Agent 🤖 AgentOpen source
Python framework for building, orchestrating and evaluating MCP-native AI agents
OpenSpec 🤖 AgentFree
Lightweight spec-driven development: agree on changes before the agent codes
BMAD Method 🤖 AgentFree
Agile AI-driven development with analyst, PM, architect, developer and UX agents
Claude Squad 🤖 AgentFree
Manage multiple terminal agents in parallel in separate workspaces