View source on GitHub
What’s in the Box
Thestrict-mode/ plugin bundles:
- Hooks (
hooks/hooks.json) - PreToolUse hook that validates commands against a whitelist - Skill (
skills/strict-mode/SKILL.md) - Documentation about what’s allowed - Plugin manifest (
.claude-plugin/plugin.json) - Standard Claude Code plugin format
How It Works
Whitelisted Commands
Only these commands are allowed (all read-only operations): File Operations:ls, cat, head, tail, file
Search & Filter: grep, find, wc
System Info: pwd, whoami, date, uname, df, du, stat
Utilities: echo, which, env, printenv, history, tree
Everything else is blocked by default.
Run It
- Option 1: Load via API
- Option 2: Launch via Badge
Use the companion
load-plugin example:The Hook
The magic happens inhooks/hooks.json:
PreToolUse- Runs before the terminal tool executesmatcher: "terminal"- Only applies to shell commands- Inline POSIX-sh script (run via
/bin/sh -c; kept inline rather than abash -c '...'wrapper or an external.shfile — see the note in the command-blacklist README for why):- Extracts the command name from the JSON input
- Checks if it’s in the hardcoded whitelist
- Returns
exit 0(allow) orexit 2(block, with a{"decision":"deny",...}reason)
Whitelist vs. Blacklist
Whitelist = “Only these few things are allowed”
Blacklist = “Everything is allowed except these specific things”
When to Use Each Approach
Use Whitelist (Strict Mode) When:
- 🎓 Educational - Teaching safe command usage
- 🔍 Analysis only - Reading/inspecting systems
- 🛡️ Maximum security - Untrusted users or agents
- 📊 Auditing - Examining existing systems
- 🧪 Sandboxes - Limiting experimental environments
Use Blacklist (Safety Guardian) When:
- 🚀 Development - Need full tooling access
- 🔧 General protection - Block obvious dangers
- ⚡ Productivity - Don’t want to pre-approve everything
- 🏗️ Building - Need to install, compile, deploy
- 🎯 Specific risks - Known dangerous patterns to block
Extending the Whitelist
To allow additional commands, edit theallowed list in hooks/hooks.json
(add the command name, space-separated):
git clone), you’ll need to whitelist the main command (git) and handle subcommand validation separately if needed.
Security Considerations
✅ Strengths:- Completely locks down command execution
- Easy to audit (small whitelist)
- Can’t be bypassed by clever command variations
- Works well for truly untrusted agents
- Very restrictive (might frustrate users)
- Requires updating the list as needs evolve
- Doesn’t prevent reading sensitive files (allows
cat /etc/passwd) - Simple command extraction (not full shell parsing)
- Combining with file path restrictions
- Adding argument validation (not just command name)
- Logging all blocked attempts
- Using a proper JSON parser instead of grep
Plugin Structure
- OpenHands Cloud plugin launcher
- Claude Desktop plugin marketplace
- Any system supporting the
.claude-pluginspec
Real-World Use Cases
- Code review agents - Only allow read operations on source code
- Security auditing - Inspect systems without modification
- Student environments - Safe learning sandbox
- Public demos - Allow exploration without damage
- CI/CD read-only steps - Verify without changing artifacts
Progressive Enhancement
Start strict, then gradually expand:- Day 1: Only allow
ls,cat,grep(ultra-strict) - Week 1: Add
find,wc,head,tail(more inspection tools) - Month 1: Add
gitfor version control (read-only) - As needed: Carefully evaluate and add new commands
Related
OpenHands Hooks Guide
Full hook documentation
Plugin System
How plugins work
load-plugin
Programmatic plugin loading
launch-plugin-badge
No-code plugin launcher
command-blacklist
Blacklist approach (opposite strategy)

