Blocks dangerous shell commands (rm -rf, force push, hard reset, DROP TABLE)

From the video "3 Claude Code Mods I Built in 5 Minutes (Take Them)".
| Mod | What it does |
|---|---|
spinner-quips | Replaces the spinner word with a joke ("Blaming the intern", "Googling the error"…) and counts tool calls |
safety-net | Blocks rm -rf, git push --force, git reset --hard and DROP TABLE, and shows a warning |
session-hud | A live HUD above the prompt: time, tool calls, files edited, context bar, cost, and a mood 😎 😅 🥵 |
Needs Claude Code v2.1.287 or newer (Desktop app v2.1.286+).
/plugin marketplace add ivtrade777/coding-tips-mods
/plugin install spinner-quips@coding-tips-mods
/plugin install safety-net@coding-tips-mods
/plugin install session-hud@coding-tips-mods
/reload-plugins
Install only the ones you want.
git clone https://github.com/ivtrade777/coding-tips-mods.git
claude --plugin-dir ./coding-tips-mods
Each mod is one short file: <mod>/hooks/register.ts (or .tsx). Change the jokes in spinner-quips, add your own dangerous commands to safety-net, or new stats to session-hud, then run /reload-plugins.
Mods are not sandboxed: they run with your permissions. Read the code (each mod is one short file in hooks/) and check what it does:
claude plugin validate ./session-hud
Tests: claude plugin test ./safety-net
Not affiliated with or endorsed by Anthropic. MIT licence.
hooks/register.ts 22 lines1import type { Register } from 'claude-code'
2
3const DANGEROUS: [RegExp, string][] = [
4 [/\brm\s+-[a-z]*r[a-z]*f|\brm\s+-[a-z]*f[a-z]*r/i, 'rm -rf'],
5 [/\bgit\s+push\b.*(--force\b|\s-f\b)/i, 'git push --force'],
6 [/\bgit\s+reset\s+--hard\b/i, 'git reset --hard'],
7 [/\bdrop\s+(table|database)\b/i, 'DROP TABLE'],
8]
9
10export const register: Register = on => {
11 on('tool.call', { tool: 'Bash' }, ($, e, next) => {
12 const hit = DANGEROUS.find(([pattern]) => pattern.test(e.command))
13 if (!hit) return next(e)
14
15 $.ui.toast(`🛑 safety-net blocked: ${hit[1]}`)
16 return { deny: `safety-net: "${hit[1]}" is blocked. Ask the user to run it themselves if they really mean it.` }
17 }).catch(($, e, next) =>
18 // If the guard itself fails, block instead of letting the command through
19 next.called ? next(e) : { deny: 'safety-net: the guard failed, so the command was blocked.' },
20 )
21}
22