Is Claude Code safe to use at work?

Claude Code is as safe as the permissions and rules around it. It can run shell commands, edit files and push to git, so unguarded it can do real damage or leak a secret. Made safe means: a fail-closed checkpoint that blocks destructive actions before they run, protection for keys and secret files, and a record you can show — and starting on test systems. Scopebond is one open-source way to add all three.

The checklist

Add the checkpoint

npx @scopebond/hook@latest init
npx @scopebond/hook@latest rules enforce safe-shell   # rules record until you turn them on
scopebond-hook log      # what happened
scopebond-hook verify   # check it offline

On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.

What this does not do

A guardrail reduces risk; it does not make an agent infallible. Scopebond governs actions routed through the agent's tools, records evidence, and fails closed — it does not read your code, guarantee an external outcome, or make a compliance judgement. Treat the alpha as controlled test use.

Alternatives

FAQ

Can Claude Code delete files or push to main?

It can run shell commands and git, so yes unless you guard it. A fail-closed checkpoint blocks destructive programs and force-pushes to protected branches before they run.

How do I stop it leaking secrets?

Protect .env and key files from reads, and scrub secrets from any record. Scopebond scrubs secrets from every record; its secret-file rule records reads until you turn it on, then blocks them.

Is it safe out of the box?

Safer with guardrails than without. Add a checkpoint and a record, and start on test systems.

Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/conformance.test.mjs).