Asks you before Claude reads a .env or key file, and refuses when no one is there to answer.

Small TypeScript mods that live inside Claude Code: a pane that knows your next step, one-click replies, a rate-limit countdown that resumes for you, your repo's pull requests and issues beside the conversation, a shelf of paths you use every day, presets that switch the model and the effort with one press, a chime when a long turn ends, a guard for the Office file you left open, a question before a commit or push on the default branch, a question before Claude reads a
.envor key file, a list of the files this session made, a list of the ones it read, a check that keeps banned claims out of a pull request, a gate that runs your checks and hands back only the failures, a nudge to fetch fresh tab IDs when a browser tab is gone, a name for the session from its first prompt, and one dialog for every mod's settings.
claude-mods is one developer's personal toolbox of Claude Code mods, shared as a plugin marketplace so anyone can install them. The mods are built for the author's own workflow first, and you are a welcome guest: install one, install all twenty, or read the source and write your own.
A mod is a plugin of function hooks: TypeScript that runs inside Claude Code and changes what it shows (a pane in the side panel, a band of buttons above the prompt, the status line) or what it does between turns. The mod's own code decides when to act, even when what it does is send the model a prompt.
| Runs as | Who decides when it acts | |
|---|---|---|
| Mod | TypeScript function hooks inside Claude Code | The mod's own code |
| Skill | Instructions the model reads | The model |
| Plain plugin | Commands, agents or shell hooks | You, or a shell script |
| Mod | Where it shows | What it does |
|---|---|---|
| 🧭 whats-next | Pane in the side panel | Lists the next steps of your workflow, each with a prompt ready to paste |
| ⚡ quick-reply | Band above the prompt | One-click replies, including the options Claude just offered, Pass, Fail and Skip for a verdict, and the next wayfinder ticket |
| ⏳ auto-resume | Band and status line | Counts down to a rate limit's reset, then sends "continue" |
| 🐙 github-panel | Pane in the side panel | The repo's open pull requests and issues, one click from the browser or from /implement and /wayfinder in the prompt; the issue a /wayfinder run works on, pinned with its next ticket; a toast when your branch's checks turn green or red |
| 📚 shelf | Band above the prompt | Named folders and files; one click drops a path into what you are typing |
| 🔔 turn-chime | Sound and toast | Tells you when a long turn ends or Claude stops to ask you something |
| 🔒 open-file-guard | Question dialog | Asks you to close a Word, Excel or PowerPoint file before Claude uses it |
| 🌿 branch-guard | Question dialog | Asks you before Claude commits or pushes on the default branch |
| 🔑 env-guard | Question dialog | Asks you before Claude reads a .env or key file, and refuses when no one is there to answer |
| 🩹 bash-quoting-rescue | Refused tool call | Stops a shell command that does not parse, such as an unclosed quote, before any of it runs |
| 📂 outputs | Pane in the side panel | The files this session made or changed, newest first; click one to open it |
| 🔎 sources | Pane in the side panel | The files Claude read, grouped by where they came from, with a lock to the project folder |
| 📊 hud | Two lines under the prompt | Model, effort, context window, rate limits, turn timer, tool calls, agents, git state, worktree, cost, session length and folder, each named and in colour |
| 🧹 post-merge-cleanup | Question dialog and toast | After a PR merges, /cleanup switches to the default branch, pulls and deletes the branch |
| 🧾 pre-pr-claims-check | Refusal Claude reads | Refuses gh pr create and gh pr edit while the pull request cites a file and line, holds a placeholder, or spells out a count |
| 🚦 lint-test-gate | Band above the prompt | Runs your checks on a press and before Claude's git commit, and hands back only the failures |
| 🔄 chrome-tab-self-heal | Note after a browser tool's error | When a Claude in Chrome tab is gone, tells Claude to fetch the current tab IDs before it tries again |
| 🏷 session-auto-namer | Band above the prompt | Suggests a name for the session from its first prompt; one press renames it |
| 🧠 model-effort-presets | Band above the prompt | Plan and execute presets: one press switches the model and the effort together |
| ⚙ mod-settings | Gear on each pane; a dialog | Change and save any mod's settings without leaving the session |
When more than one mod has a pane open, Claude Code shows them as tabs in the side panel.
A pane listing the next steps of your workflow for the project folder, kept between sessions. A skill of your choosing answers "what's next" in a headless run beside your session, and the mod turns the answer into steps.
What's next refresh
updated 3 min ago
Fix the failing parse test
working on it done
The check is red, so nothing else can merge.
Open a pull request for the fix
Review comes before the next feature starts.
Triage the two new issues
They arrived while you were heads-down.
flowchart LR
A[Skill answers<br/>what's next] --> B[Steps in the pane]
B --> C[You read a step's prompt<br/>and send it yourself]
C --> D[Step glows:<br/>working on it]
D --> E{Laya, Jev or Haiku:<br/>is the step finished?}
E -- not yet --> D
E -- yes --> F[Step leaves the list]
d to drop it yourself.git push, git config, git -c, gh api and --output are always denied.| Command or key | What it does |
|---|---|
/whats-next | Bring the pane to the front |
/whats-next refresh | Ask the skill again |
r | Refresh |
1 to 9 | Show that step's prompt in the pane |
p, n, c | Paste the shown prompt, paste it after /clear (and the prime command, once its turn ends), or copy it |
b | Back to the list |
d | Mark the active step done |
| Setting | Key | Default | Meaning |
|---|---|---|---|
| Skill | skill | /ask-sean | The skill that answers "what's next", written as you would run it: / followed by letters, digits, _, :, . or - |
| Most steps | maxSteps | 5 | How many steps to ask for (1-9) |
| Refresh on start | refreshOnStart | on | Ask for a fresh list when a session starts in a git repository |
| Tools the headless run may use | allowedTools | empty: the read-only set | Comma-separated permission rules for the headless run |
| Model | model | empty: your default | Model for the headless run, as an alias (haiku) or a full id |
| Prime command | primeCommand | empty: none | A slash command, with any arguments, run after /clear and before the paste (/lril:prime); the prompt is filled once the turn it starts ends, finished or not. A value that is not one slash command on one line is never run, and the step view says so |
| System One models | modelChoice | local only | Which System One model judges whether a turn finished the active step: local only (Laya on this machine, or Haiku as before), local first (Laya, and TypeSafe's hosted Jev while Laya is unavailable) or hosted first (Jev, and Laya while Jev is unavailable) |
| Jev API key | jevApiKey | empty | Your key for Jev, from console.typesafe.ai, kept in secure storage. Sent only to https://api.typesafe.ai, and only while System One models allows Jev |
| Laya port | layaPort | 8000 | The port your laya-serve listens on at 127.0.0.1 (1-65535) |
/ask-sean is the author's own skill, so point the Skill setting at a skill of yours that answers "what should I do next?" (how to set it):
echo '{"skill": "/next-steps", "maxSteps": "3", "model": "haiku"}' | claude plugin configure whats-next@claude-mods --values-stdin
The read-only set, used while Tools is empty, is Bash(git status:*), Bash(git log:*), Bash(git diff:*), Bash(git show:*), Bash(git rev-parse:*), Bash(git branch --show-current), Bash(git branch -vv), Bash(git remote -v), Bash(gh issue list:*), Bash(gh issue view:*), Bash(gh pr list:*), Bash(gh pr view:*), Bash(gh pr checks:*), Bash(gh run list:*), Read, Glob and Grep.
(...). One rule that is not, such as one starting with -, discards your whole list and the read-only set is used.Skill, so a skill that calls another still works. MCP servers load only when a rule names an mcp__ tool.What the judge sends to a System One model, once after each answered turn while a step is active:
Needs: the claude CLI on the PATH, and the skill named in the Skill setting. Laya and a Jev key are optional: with neither, the judge is Haiku, as before.
One row of buttons above the prompt after each answer. When Claude ends on a question, the band offers the choices Claude asked you to pick from, then your replies to a question. After any other answer it offers your other replies. You set both lists in the settings below.
Reply: [a: Keep the copies] [b: Add a sync script] [Yes] [Go with your recommendation] [No]
Verdicts. When Claude asks for a pass/fail verdict on a test or a check, as a UAT or /gsd:verify-work step does ("Pass or fail?", "Did it pass?", "Type pass or describe what's wrong"), the band offers a verdict in place of your replies:
Reply: [Pass] [Fail…] [Skip]
Pass sends "pass" and Skip sends "skip", as your own message. Fail… sends nothing: it puts "Fail: " in the prompt, where you say what went wrong and can paste a screenshot. A test's numbered steps are not offered as choices, and a question that only mentions passing ("Shall I make the tests pass?") gets your usual replies.
Next ticket. When you work a map with the wayfinder skill, the band leads with the next ticket after each turn that closes one or charts the map:
Reply: [Next ticket: /wayfinder 135] [Continue] [Commit and push]
One press runs /clear and then /wayfinder 135, the loop you would otherwise type. It is offered only in a session that ran the wayfinder skill, after a turn whose gh issue close worked; after charting it names the map the turn created. A close made some other way (gh api, the web) is not seen, so no button shows, and once a turn closes the map itself the loop ends.
| Setting | Key | Default | Meaning | |||
|---|---|---|---|---|---|---|
| Replies to a question | questionReplies | `Yes\ | Go with your recommendation\ | No` | Shown after Claude asks something, separated by `\ | `; empty shows only the choices Claude offered |
| Replies otherwise | idleReplies | `Continue\ | Commit and push` | Shown after any other answer; empty hides the band then, except for Next ticket | ||
| Offer the next wayfinder ticket | wayfinderNext | true | After a wayfinder turn closes a ticket or charts a map, offer Next ticket | |||
| System One models | modelChoice | local only | Which System One model reads how each answer ends: local only (Laya on this machine, or the band's own reading as before), local first (Laya, and TypeSafe's hosted Jev while Laya is unavailable) or hosted first (Jev, and Laya while Jev is unavailable) | |||
| Jev API key | jevApiKey | empty | Your key for Jev, from console.typesafe.ai, kept in secure storage. Sent only to https://api.typesafe.ai, and only while System One models allows Jev | |||
| Laya port | layaPort | 8000 | The port your laya-serve listens on at 127.0.0.1 (1-65535) |
Each list holds up to six replies. A reply longer than 120 characters is cut short, and a repeat is dropped. For example, to answer questions with your own three replies and hide the band after other answers (how to set it):
echo '{"questionReplies": "Yes|No|Explain that first", "idleReplies": ""}' | claude plugin configure quick-reply@claude-mods --values-stdin
What the band sends to a System One model, once after each answered turn:
Laya and a Jev key are optional: with neither, the band reads each answer as before.
When a turn dies on a rate limit or an overloaded API, auto-resume counts down to the reset and sends "continue" for you. Go to lunch, and come back to finished work.
⏳ rate limited: sending "continue" in 1 h 12 min [Resume now] [Cancel]
| Command | What it does |
|---|---|
/auto-resume | Say what is waiting, if anything |
/auto-resume now | Send the resume now |
/auto-resume cancel | Cancel the wait |
/auto-resume in <minutes> | Schedule a resume yourself (1 to 1440) |
| Setting | Key | Default | Meaning |
|---|---|---|---|
| Resume prompt | text | continue | What is sent when the wait is over; empty sends continue |
| Grace after reset (s) | graceSeconds | 60 | Extra seconds to wait past the limit's reset time (0-900) |
| Retry overloaded/server errors | retryOverloaded | on | Also resume after an overloaded or server error, backing off from one minute |
| Most retries in a row | maxRetries | 5 | Give up after this many resumes without a successful answer (1-20) |
For example, to send a longer prompt and wait two minutes past the reset (how to set it):
echo '{"text": "continue where you left off", "graceSeconds": "120"}' | claude plugin configure auto-resume@claude-mods --values-stdin
A GitHub pane beside What's next listing the repo's open pull requests and issues. Click one to open it in the browser. Under each issue, implement and wayfinder put /implement or /wayfinder and the issue's URL in the prompt. Nothing is sent. While a /wayfinder effort is under way, its issue is pinned at the top, with the next ticket to take.
octocat/hello-world refresh
updated just now
Decide how shared code is copied unpin
3 done · 1 takeable · 1 claimed · 2 blocked
next: Pick the drift check decision
work next
Pull requests 2 all
#41 Add a drift check for copied guards
draft · @octocat
#40 Bring the asked pane to the front
✗ checks failing · @hubot fix
Issues 2 all
#39 Share the headless-session check
blocked by #12 · ready… implement wayfinder
#12 Decide how shared code is copied
needs-triage · @hubot implement wayfinder
implement and wayfinder buttons take a line of their own.r.fix button. It fills the prompt box with the failed checks' names, the last 40 lines of the failed run's log, and "Fix it." Nothing is sent: you read it and send it yourself. The log is fetched only when you press fix; when gh cannot fetch it, such as while the run is still going, the prompt holds the names alone./wayfinder on an issue of this repo (/wayfinder 12, /wayfinder #12 or the issue's URL) pins that issue and brings the pane to the front. Anything else, such as prose or another repo's issue, pins nothing. The pin is kept for the repo across sessions, one at a time: a run on another issue replaces it. It goes when you press unpin, or once the issue is closed.next is the first takeable ticket in the order the issue lists its sub-issues, with its wayfinder: type label; click it to open it on GitHub. With nothing takeable it says so; an issue with no sub-issues yet says no tickets yet.work next fills /wayfinder and the pinned issue's URL into the prompt, without sending it, so the skill takes the frontier ticket fresh when it runs.| Command or key | What it does |
|---|---|
/github | Bring the pane to the front and refresh it |
r | Refresh |
all | Open the whole list on GitHub |
implement, wayfinder | Fill the command and the issue's URL into the prompt, without sending it |
fix | Fill a request to fix the current branch's failing checks into the prompt box |
unpin | Drop the pinned issue |
work next | Fill /wayfinder and the pinned issue's URL into the prompt, without sending it |
| Setting | Key | Default | Meaning |
|---|---|---|---|
| Most items per list | limit | 30 | How many open pull requests and issues to list each (1-100) |
| Refresh every (minutes) | refreshMinutes | 5 | How often to refresh (0-120); 0 refreshes only on open, after turns and on r |
| Implement button fills | implementCommand | /implement | The slash command the implement button fills before the issue's URL; empty hides the button |
| Wayfinder button fills | wayfinderCommand | /wayfinder | The slash command the wayfinder and work next buttons fill before the issue's URL, and the skill whose runs pin an issue; empty hides the button and turns pinning off |
A command must start with / and hold no spaces. Any other value falls back to the default, and a message says so when the session starts. A button is labelled with its command, without the /.
For example, to list fifty of each and stop the timer (how to set it):
echo '{"limit": "50", "refreshMinutes": "0"}' | claude plugin configure github-panel@claude-mods --values-stdin
Needs: the GitHub CLI, logged in, and a folder with a GitHub remote.
A row of named folders and files above the prompt, for the paths you type again and again. Click a name and its path lands at the cursor in what you are typing. Nothing is sent.
Shelf: [brand] [records] [kb]
/shelf always lists them all.| Command | What it does |
|---|---|
/shelf | List the shelf with each path |
/shelf add <name> [path] | Put a path on the shelf; with no path, the project folder |
/shelf remove <name> | Take one off |
The shelf has no settings: you fill it with /shelf add.
/shelf add brand "N:/Marketing/Brand Kit"
/shelf add records N:/RECORDS
/shelf add kb
/shelf remove brand
hooks/register.ts 66 lines1import type { EngineInterface, Register } from 'claude-code'
2
3import { guardedIn, guardedName, namedBy, parsePatterns, question, refusal, rejectedNotice } from './guarded'
4
5const ALLOW = 'Allow once'
6const REFUSE = 'Refuse'
7const KEYPICK = 'keypick'
8
9// Each mod carries its own copy (ADR-0001): a session shown on no surface is headless.
10async function isShown($: EngineInterface): Promise<boolean> {
11 return (await $.session.surfaces()).length > 0
12}
13
14/** Whether the keypick skill is installed: an exact name in the session's command list. A list that cannot be read has none. */
15async function hasKeypick($: EngineInterface): Promise<boolean> {
16 return (await $.command.list().catch(() => [])).some(command => command.name === KEYPICK)
17}
18
19/** The guarded file a path names, as spelled or where it lands, symlinks and junctions followed, when it exists and can be looked at. */
20async function guardedPath($: EngineInterface, path: string, extra: readonly RegExp[]): Promise<string | undefined> {
21 const named = guardedName(path, extra)
22 if (named !== undefined) return named
23 const realPath = (await $.fs.stat(path, { resolve: true }).catch(() => undefined))?.realPath
24 return realPath === undefined ? undefined : guardedName(realPath, extra)
25}
26
27/** Undefined to let the call through, or why it is refused. A guarded file is asked about each call; there is nothing to remember. */
28async function guard($: EngineInterface, names: readonly string[]): Promise<string | undefined> {
29 if (names.length === 0) return undefined
30 // A secret read cannot be taken back, so with no one to ask the call is refused rather than let through.
31 if (!(await isShown($).catch(() => false))) return refusal(names, false, await hasKeypick($))
32 const answer = await $.ui.ask(question(names), { header: 'Secrets', options: [ALLOW, REFUSE] }).catch(() => undefined)
33 // Refused, dismissed, or answered in other words: the call does not go on.
34 return answer === ALLOW ? undefined : refusal(names, true, await hasKeypick($))
35}
36
37export const register: Register = (on, options) => {
38 const patterns = parsePatterns(options.extraPatterns)
39 let isToldOfRejected = patterns.rejected.length === 0
40
41 // At a turn rather than at session start: a changed setting reloads the mod in a session already going.
42 on('turn.start', async ($, e, next) => {
43 if (!isToldOfRejected && (await isShown($).catch(() => false))) {
44 isToldOfRejected = true
45 $.ui.toast(rejectedNotice(patterns.rejected), { timeoutMs: 10_000 })
46 }
47 return next(e)
48 })
49
50 // Matched by pattern: which read tools a session has depends on the machine.
51 on('tool.call', { tool: /^(Read|Grep|Glob)$/ }, async ($, e, next) => {
52 const { path, filter } = namedBy(e.tool, e)
53 const searched = path === undefined ? undefined : await guardedPath($, path, patterns.guarded)
54 const filtered = filter === undefined ? undefined : guardedName(filter, patterns.guarded)
55 const names = [...new Set([searched, filtered])].filter(name => name !== undefined)
56 const deny = await guard($, names)
57 return deny === undefined ? next(e) : { deny }
58 })
59
60 on('tool.call', { tool: /^(Bash|PowerShell)$/ }, async ($, e, next) => {
61 const command = 'command' in e && typeof e.command === 'string' ? e.command : ''
62 const deny = await guard($, guardedIn(command, patterns.guarded))
63 return deny === undefined ? next(e) : { deny }
64 })
65}
66hooks/guarded.ts 118 lines1/** The extra file-name patterns the setting gives, compiled, and the ones passed over as malformed. */
2export type Patterns = { guarded: RegExp[]; rejected: string[] }
3
4/**
5 * A file-name glob as a case-insensitive match on the whole name: `*` is any characters and `?` one.
6 * As in a shell, a leading wildcard does not match a leading dot, so `*.key` passes over jq's `.key`.
7 */
8function compiled(glob: string): RegExp {
9 const body = glob.replace(/[.+^${}()|[\]\\]/g, '\\$&').replace(/\*/g, '.*').replace(/\?/g, '.')
10 return new RegExp(`^${/^[*?]/.test(glob) ? '(?!\\.)' : ''}${body}$`, 'i')
11}
12
13const BUILT_IN = ['.env', '.env.*', '*.pem', '*.key', '*.p12', '*.pfx', 'id_rsa*', 'id_ed25519*'].map(compiled)
14/** Built-in names that hold no secret: the templates of a `.env`, and the public half of a key pair. */
15const NOT_SECRET = ['.env.example', '.env.sample', '.env.template', 'id_rsa*.pub', 'id_ed25519*.pub'].map(compiled)
16
17/**
18 * The setting's patterns, separated by commas. A pattern with a folder in it, or with `[ ]` or `{ }`, which
19 * the mod does not read as a glob, is passed over and given back, so the person can be told.
20 */
21export function parsePatterns(value: unknown): Patterns {
22 const each = typeof value === 'string' ? value.split(',').map(pattern => pattern.trim()).filter(pattern => pattern !== '') : []
23 const isMalformed = (pattern: string) => /[\\/[\]{}]|\p{Cc}/u.test(pattern)
24 return { guarded: each.filter(pattern => !isMalformed(pattern)).map(compiled), rejected: each.filter(isMalformed) }
25}
26
27/** What the person is told once when the setting has patterns the mod passed over. */
28export function rejectedNotice(rejected: readonly string[]): string {
29 const quoted = rejected.map(pattern => `"${pattern}"`).join(', ')
30 return `env-guard: More guarded files has ${quoted}, which ${rejected.length === 1 ? 'is not a file name' : 'are not file names'} and so guard nothing. A pattern is a name, with * and ? as wildcards and no folder, [ ] or { }.`
31}
32
33/** Whether a file name is guarded: on the built-in list and not a template or a public key, or matching a pattern of the setting. */
34export function isGuarded(name: string, extra: readonly RegExp[]): boolean {
35 if (extra.some(pattern => pattern.test(name))) return true
36 return BUILT_IN.some(pattern => pattern.test(name)) && !NOT_SECRET.some(pattern => pattern.test(name))
37}
38
39/**
40 * The path with forward slashes, its `.` and `..` segments folded and no trailing slash, so two spellings
41 * of a place compare equal. A `..` at a drive, share or root stays there, as the file system has it;
42 * one at the start of a relative path is kept. Copied from sources (ADR-0001).
43 */
44export function normal(path: string): string {
45 const slashed = path.replace(/\\/g, '/')
46 const [, head = '', rest = ''] = /^(\/\/[^/]+\/[^/]+|[A-Za-z]:(?=\/|$)|\/?)(.*)$/.exec(slashed) ?? []
47 const parts: string[] = []
48 for (const part of rest.split('/')) {
49 if (part === '' || part === '.') continue
50 if (part !== '..') parts.push(part)
51 else if (parts.length > 0 && parts[parts.length - 1] !== '..') parts.pop()
52 else if (head === '') parts.push(part)
53 }
54 const body = parts.join('/')
55 if (head === '') return body === '' ? '.' : body
56 // A bare drive or the root keeps its slash; a share has none of its own.
57 if (head.startsWith('//')) return body === '' ? head : `${head}/${body}`
58 return head === '/' ? `/${body}` : `${head}/${body}`
59}
60
61/**
62 * The guarded file a path or a glob names, by the last part of it once folded, or undefined when it names
63 * none. A glob's last part counts both as written (`*.pem`) and with its wildcards dropped (`.env*`).
64 */
65export function guardedName(spelling: string, extra: readonly RegExp[]): string | undefined {
66 const folded = normal(spelling)
67 const name = folded.slice(folded.lastIndexOf('/') + 1)
68 return [name, name.replace(/[*?]/g, '')].some(each => isGuarded(each, extra)) ? name : undefined
69}
70
71/**
72 * What a read tool's call names: the file Read reads or the path Grep and Glob search, and the file-name
73 * filter Glob's `pattern` or Grep's `glob` gives. Grep's own `pattern` is a regex, not a path.
74 */
75export function namedBy(tool: string, input: object): { path?: string; filter?: string } {
76 const { file_path: file, path, pattern, glob } = input as { file_path?: unknown; path?: unknown; pattern?: unknown; glob?: unknown }
77 const named = typeof file === 'string' ? file : typeof path === 'string' ? path : undefined
78 const filter = tool === 'Glob' ? pattern : tool === 'Grep' ? glob : undefined
79 return { ...(named === undefined ? {} : { path: named }), ...(typeof filter === 'string' ? { filter } : {}) }
80}
81
82/**
83 * The guarded files a shell command names, each once. A quoted path counts whole, spaces and all, and every
84 * word counts on its own, so `bash -c "cat .env"` and `--env-file=.env` are seen too. A file the command
85 * reaches without naming it is not.
86 */
87export function guardedIn(command: string, extra: readonly RegExp[]): string[] {
88 const quoted = [...command.matchAll(/"([^"\n]+)"|'([^'\n]+)'/g)].map(match => match[1] ?? match[2] ?? '')
89 const words = command.split(/[\s"'`|<>;()&,=]+/)
90 const found = new Map<string, string>()
91 for (const spelling of [...quoted, ...words]) {
92 const name = spelling === '' ? undefined : guardedName(spelling, extra)
93 if (name !== undefined && !found.has(name.toLowerCase())) found.set(name.toLowerCase(), name)
94 }
95 return [...found.values()]
96}
97
98/** Names as a sentence lists them: `a`, `a and b`, `a, b and c`. */
99function listed(names: readonly string[]): string {
100 return names.length < 2 ? names.join('') : `${names.slice(0, -1).join(', ')} and ${names[names.length - 1]}`
101}
102
103/** What the person is asked before the call goes on. */
104export function question(names: readonly string[]): string {
105 return `Let Claude read ${listed(names)}?`
106}
107
108/** Why the call is refused, for the model to pass on: asked and not allowed, or no one there to ask. */
109export function refusal(names: readonly string[], isAsked: boolean, hasKeypick: boolean): string {
110 const files = listed(names)
111 const holds = names.length === 1 ? 'holds' : 'hold'
112 const why = isAsked
113 ? `env-guard: the person did not let Claude read ${files}, which ${holds} secrets.`
114 : `env-guard: ${files} ${holds} secrets, and in this session no one is there to let Claude read ${names.length === 1 ? 'it' : 'them'}.`
115 const instead = ' To run something that needs a key, use the keypick skill instead: it hands the command its keys without showing them.'
116 return hasKeypick ? `${why}${instead}` : why
117}
118