npm package discovery and stats viewer.

Discover Tips

  • General search

    [free text search, go nuts!]

  • Package details

    pkg:[package-name]

  • User packages

    @[username]

Sponsor

Optimize Toolset

I’ve always been into building performant and accessible sites, but lately I’ve been taking it extremely seriously. So much so that I’ve been building a tool to help me optimize and monitor the sites that I build to make sure that I’m making an attempt to offer the best experience to those who visit them. If you’re into performant, accessible and SEO friendly sites, you might like it too! You can check it out at Optimize Toolset.

About

Hi, 👋, I’m Ryan Hefner  and I built this site for me, and you! The goal of this site was to provide an easy way for me to check the stats on my npm packages, both for prioritizing issues and updates, and to give me a little kick in the pants to keep up on stuff.

As I was building it, I realized that I was actually using the tool to build the tool, and figured I might as well put this out there and hopefully others will find it to be a fast and useful way to search and browse npm packages as I have.

If you’re interested in other things I’m working on, follow me on Twitter or check out the open source projects I’ve been publishing on GitHub.

I am also working on a Twitter bot for this site to tweet the most popular, newest, random packages from npm. Please follow that account now and it will start sending out packages soon–ish.

Open Software & Tools

This site wouldn’t be possible without the immense generosity and tireless efforts from the people who make contributions to the world and share their work via open source initiatives. Thank you 🙏

© 2026 – Pkg Stats / Ryan Hefner

pi-safety-net

v1.0.8

Published

Fail-open fork of cc-safety-net — blocks destructive git/filesystem commands, but defaults to fail-OPEN on broken/legacy config so the shell never bricks.

Readme

CI codecov Version Codex Claude Code Copilot CLI Gemini CLI Kimi Code OpenCode Pi License: MIT

CC Safety Net

A PreToolUse hook that intercepts and blocks destructive git and filesystem commands before AI coding agents run them. CC Safety Net parses command semantics — so flag reordering, shell wrappers, and interpreter one-liners can't bypass it.

[!NOTE] Full documentation → — installation, configuration, reference, guides, and the security model live on the docs site.

Why this exists

We learned the hard way that instructions aren't enough to keep AI agents in check. After an agent silently wiped hours of progress with a single rm -rf ~/ or git checkout --, it became clear that soft rules in a CLAUDE.md or AGENTS.md file cannot replace hard technical constraints. CC Safety Net is that constraint: it intercepts every Bash tool call and blocks destructive commands before they reach the shell. See What Is CC Safety Net for the full background.

Supported agents

CC Safety Net works across seven coding agent CLIs: Claude Code, Codex, Gemini CLI, GitHub Copilot CLI, Kimi Code, OpenCode, and Pi. Each integration is documented at Architecture.

Supported platforms

CC Safety Net runs on Windows, macOS, and Linux. It detects the host OS to apply correct behavior — case-insensitive path comparison on Windows, both / and \ path separators, and cmd.exe/PowerShell command resolution via COMSPEC/PATHEXT.

Prerequisites

  • Node.js 18 or higher.

Quick start

Codex Installation

  1. Enable Codex plugin hooks in ~/.codex/config.toml:
[features]
plugin_hooks = true
  1. Add the marketplace:
codex plugin marketplace add kenryu42/cc-marketplace
  1. Start Codex.
  2. In the TUI, run /plugins.
  3. Use arrow keys to select [cc-marketplace].
  4. Press Enter to install the plugin.
  5. run /hooks and select the safety-net PreToolUse hook and press t to trust it.

Claude Code Installation

/plugin marketplace add kenryu42/cc-marketplace
/plugin install safety-net@cc-marketplace
/reload-plugins

Claude Code Auto-Update

  1. Run /plugin → Select Marketplaces → Choose cc-marketplace → Enable auto-update

Gemini CLI Installation

gemini extensions install https://github.com/kenryu42/gemini-safety-net

GitHub Copilot CLI Installation

/plugin install kenryu42/copilot-safety-net

Kimi Code Installation

Install CC Safety Net into your Kimi Code config:

npx -y cc-safety-net hook install --kimi-code

Optional: run npx skill add kenryu42/cc-safety-net to add the /cc-safety-net skill for configuring custom rules.


OpenCode Installation

Install CC Safety Net with OpenCode's native plugin command:

opencode plugin -g cc-safety-net

[!NOTE] OpenCode can sometimes keep using a stale cached plugin version. See anomalyco/opencode#25293 for the current tracking issue.

To force OpenCode to reinstall cc-safety-net, remove its cached package and install the version you want:

rm -rf ~/.cache/opencode/packages/cc-safety-net@latest
opencode plugin -g -f cc-safety-net@latest

If you prefer pinning a specific version:

rm -rf ~/.cache/opencode/packages/cc-safety-net@latest
opencode plugin -g -f cc-safety-net@<version>

Restart OpenCode after updating so the plugin is loaded from the refreshed cache.


Pi Installation

Install CC Safety Net with Pi's package installer:

pi install npm:cc-safety-net

What it does

| Capability | What it catches | |---|---| | Semantic command analysis | rm -rf on destructive targets, git reset --hard, git checkout --, git push --force, git stash clear, git clean -f, find -delete, dd/mkfs/shred — by intent, not string pattern. git checkout -b feature (safe) is allowed while git checkout -- file (destructive) is blocked. | | Shell wrapper detection | Destructive commands hidden in bash -c, sh -c, and similar wrappers, recursively analyzed up to 10 levels deep. | | Interpreter one-liners | Destructive code in python -c, node -e, ruby -e, perl -e one-liners (e.g. os.system("rm -rf /")). | | Fail-closed by default | Malformed hook input, unparseable commands (in strict mode), invalid config, and broken rulebooks block rather than allow. | | Custom rules via rulebooks | Add your own blocking rules at user or project scope, pinned by SHA-256 digest when fetched from GitHub. | | Audit logging | Every blocked command logged to ~/.cc-safety-net/logs/<session_id>.jsonl with secrets auto-redacted. |

Full blocked/allowed command lists: Blocked Commands · Allowed Commands.

Why not just use a sandbox?

A workspace-writable sandbox still permits git reset --hard, git push --force, and rm -rf . inside the project directory, because the OS only sees writes to an allowed path. Sandboxing contains blast radius; CC Safety Net catches the destructive operations sandboxing permits — use both for defense-in-depth. See vs Sandboxing.

Modes

CC Safety Net has opt-in modes toggled by CC_SAFETY_NET_* environment variables (legacy SAFETY_NET_* names also accepted):

| Mode | Flag | Effect | |---|---|---| | Strict | CC_SAFETY_NET_STRICT=1 | Fail closed on unparseable commands, not just malformed input. | | Paranoid | CC_SAFETY_NET_PARANOID=1 | Stricter checks; or use CC_SAFETY_NET_PARANOID_RM=1 (block rm -rf even within cwd) and CC_SAFETY_NET_PARANOID_INTERPRETERS=1 (block interpreter one-liners). | | Worktree | CC_SAFETY_NET_WORKTREE=1 | Relax local git discards inside verified linked worktrees. |

See Modes and Environment.

Diagnostics and tracing

# Verify your installation and run a self-test
npx cc-safety-net doctor
# Trace how a command is analyzed step-by-step
npx cc-safety-net explain "git reset --hard"

Both support --json for machine-readable output. Full reference: CLI Commands · Explain Trace.

Upgrading from an older version

[!WARNING] If you previously defined custom rules in a legacy inline config (.safety-net.json or ~/.cc-safety-net/config.json), those files are no longer loaded at runtime. Commands now fail closed (stay blocked) until you migrate. Run npx -y cc-safety-net rule migrate to convert them to the rulebook layout. See the migration guide.

Full documentation

All details live on the docs site at ccsafetynet.com/docs:

| Area | Pages | |---|---| | Get started | Introduction · Installation · Quickstart | | Configuration | Modes · Environment · Custom Rules · Status Line | | Reference | Blocked Commands · Allowed Commands · Audit Log · CLI Commands · Explain Trace · Glossary | | Guides | How It Works · Architecture · Analysis Engine · Design Principles · Security Model · vs Sandboxing · Known Limitations · Troubleshooting | | Project | Contributing · Security Policy |

Development

See CONTRIBUTING.md for details on how to contribute to this project.

License

MIT

Fork: Fail-Open Default

This is a fail-open fork of kenryu42/cc-safety-net.

The upstream package defaults to fail-closed: when the rule config is missing, legacy, or unparseable, it blocks every command (bricking the shell/agent). This fork flips the default to fail-open — a broken rulebook runs with no custom rules so commands are allowed through, instead of bricking the agent.

| Mode | Trigger | Behavior | |------|---------|---------| | fail-open (default) | policy errors / legacy config / analysis exception | allow commands through, no custom rules applied | | fail-closed (CC_SAFETY_NET_STRICT=1) | same triggers | block every command except repair (rule sync / rule migrate) |

Set CC_SAFETY_NET_STRICT=1 to restore the upstream fail-closed behavior.

Install (pi)

// settings.json
{
  "packages": ["pi-safety-net"]
}

Attribution

This package is a fork of kenryu42/cc-safety-net.

Forked and maintained by buihongduc132.