Block Claude Code from dangerous commands
A hand-written hook that greps for rm -rf misses bash -c '…', $(…), an env-var prefix, or git -C. Scopebond's hook decomposes a shell command into every simple command it will run and denies the call if any segment is out of policy. The starter rules cover destructive programs, force-pushes to protected branches, and reads of key and secret files. Each starts by recording what it would block; once you turn it on it blocks — fail-closed in strict mode, before the command runs.
1. Install and turn the rules on
The starter rules cover release branches, destructive programs, and the agent's own keys, its CI config and .env secrets. They record until you turn them on; Scopebond's own protection always blocks. Edit the limits with rules.
npx @scopebond/hook@latest init
npx @scopebond/hook@latest rules enforce safe-shell # block destructive programs
npx @scopebond/hook@latest rules enforce protect-branches # block pushes to protected branches
scopebond-hook test "git push --force origin main" # denied
scopebond-hook test "rm -rf /" # denied
On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.
2. Why decomposition matters
The mapper splits a command into every simple command (a && b, $(c), bash -c '…', env-prefixes, git -C) and denies the whole call if any part is out of policy. An unparseable command is denied in strict mode rather than allowed.
3. Enforce, don't just observe
On a denied action the hook returns a deny to Claude Code (exit code 2), which blocks it even in bypass-permissions mode. On an allowed action it defers to Claude Code's own permission flow — it blocks; it never silently auto-approves.
SCOPEBOND_HOOK_STRICT=1 npx @scopebond/hook@latest init # deny anything unmapped
What this does not do
The hook checks actions the coding agent sends through it. An action taken outside the hook is not covered. For an action that must always be checked, run the Scopebond gateway in front of the tool or API. Scopebond does not classify file contents or use DLP; it decides on typed actions.
Alternatives
- Claude Code permission modes and managed settings — native allow/deny prompts; Scopebond adds decomposition, self-protection and a signed record.
- A hand-written deny hook — fine for one pattern; you own the shell-parsing edge cases.
FAQ
Can the agent get around a simple grep rule?
Yes — that is the point of decomposition. Scopebond splits a command into every simple command it runs, so a denied program hidden behind bash -c, $(…) or an env-prefix is still caught.
Does a blocked action still run?
No. A denied PreToolUse decision returns exit code 2, which Claude Code treats as a block even in bypass-permissions mode.
What happens to a command it can't parse?
In strict mode an unparseable command is denied (fail-closed); otherwise it is recorded as not evaluated so you can tighten the policy.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/shell.test.mjs).