SLOPSHOPPER

protect-env-files

Sample mod: denies edits to .env files

newguard
A shopper browsing a rack in a slop shop
README

protect-env-files

Sample mod. Denies Edit tool calls on .env files (.env, .env.local, ...), so secrets are never rewritten by the model.

Use

claude --plugin-dir packages/protect-env-files

How it works

hooks/register.ts hooks tool.call for Edit: a protected path answers { deny }; anything else goes on with next(e).

Test

bun run turbo test --filter @claude-code-mods/protect-env-files

Runs tsc, claude plugin test (tests/) and claude plugin validate.

Source 1 files
hooks/register.ts 12 lines
1import type { Register } from "claude-code";
2
3const PROTECTED = /(^|\/)\.env(\.|$)/;
4
5export const register: Register = (on) => {
6  on("tool.call", { tool: "Edit" }, ($, e, next) =>
7    PROTECTED.test(e.file_path)
8      ? { deny: `${$.plugin.name}: ${e.file_path} is protected.` }
9      : next(e),
10  );
11};
12