SLOPSHOPPER

read-only-mode

Toggle a reminder guard that refuses built-in mutating tools and Bash.

newpaneguardcommand
A shopper browsing a rack in a slop shop
Preview · a replayed session in a sandbox
claude · ~/work/app · read-only-mode
│ ┃ Read-only Mode ✕ › fix the failing auth test and add an audit log call │ ┃ Read-only Mode │ ┃ ⏺ Read(src/auth.ts) │ ┃ Toggle a reminder guard that refuses ⎿ Read 6 lines │ ┃ built-in mutating tools and Bash. ⏺ Update(src/auth.ts) │ ┃ ⎿ Added 2 lines, removed 1 line │ ┃ Guard OFF ⏺ Bash(bun test) │ ┃ ⎿ 3 pass, 1 fail │ ┃ Blocks Edit, Write, NotebookEdit, and all │ ┃ Bash calls. MCP and other mods are outside ● Done. refresh now rejects expired claims and logs an audit event. │ ┃ this reminder guard. │ ┃ ✻ Worked for 42s · done 4:20 PM │ ┃ 0 calls refused │ ┃ › /read-only-mode │ ┃ [ Enable guard ] │ ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── › ? for shortcuts

Draws

Pane · Read-only Mode
Read-only Mode Toggle a reminder guard that refuses built-in mutating tools and Bash. Guard OFF Blocks Edit, Write, NotebookEdit, and all Bash calls. MCP and other mods are outside this reminder guard. 0 calls refused [ Enable guard ]
README

Read-only Mode

Toggle a reminder guard that refuses built-in mutating tools and Bash.

Use it when: Use a session for inspection with an extra visible guard.

Read-only Mode render preview

Screenshot of this mod's render tree in the fixture preview, with sample data. This is not a capture of the Claude Code application. How previews are made.

Install and open

claude plugin marketplace add whyashthakker/awesome-claude-code-mods
claude plugin install read-only-mode@awesome-claude-code-mods

Run /reload-plugins in an existing session, then /read-only-mode. Use Tab and Enter to operate controls; Esc closes the pane. Terminal and Desktop Code tab supported; pane UI is unavailable in claude -p and the VS Code chat panel.

Try the source without installing:

claude --plugin-dir ./mods/read-only-mode

Access and behavior

Refuses selected tool.call events when manually enabled. No permission approvals. Not a security boundary; other tools/mods can write.

Module variables reset on hot reload. Diagnostic history begins when the mod loads and lasts until reload or process exit; it does not reconstruct earlier activity. All display output is bounded; viewers may truncate long content to 9,000 characters. Relative file paths and Git commands use the session working directory.

Verify

Tested with Claude Code 2.1.288. Minimum documented mods version: 2.1.287. The API can change; validate against your installed version.

claude plugin validate mods/read-only-mode --strict
claude plugin test mods/read-only-mode

Tests cover plugin commands, pane isolation, both UI surfaces, and the behavior described in tests/register.test.ts. Drawing tests validate element trees; they do not verify pixels painted by the native apps. Validation details.

MIT licensed. No runtime packages or build step required.

Source 2 files
hooks/register.js 42 lines
1import { clean, text, code, row, frame, bar, pretty, bounded, entries, safePath } from './ui.js'
2const ID = "read-only-mode"
3let enabled=false,blocked=0
4export function register(on) {
5  on('session.start', async ($, e, next) => {
6
7    await $.command.register({name:ID, description:"Toggle a reminder guard that refuses built-in mutating tools and Bash.", immediate:true, argumentHint:""})
8    return next(e)
9  })
10  on('command.run', {command:"read-only-mode"}, async ($, e) => {
11
12    await $.ui.open({id:ID,title:"Read-only Mode",focus:true,closeOnEscape:true})
13    return {}
14  })
15
16on('tool.call',{tool:['Edit','Write','NotebookEdit','Bash']},async($,e,next)=>{
17 if(!enabled)return next(e)
18 blocked+=1;$.ui.invalidate('ui.render')
19 return {deny:'Read-only Mode is enabled. Use inspection tools or ask the user to disable it in /read-only-mode.'}
20}).catch(async()=>({deny:'Read-only Mode guard failed; this call was refused.'}))
21
22  on('ui.render', {component:'Pane'}, async ($, e, next) => {
23    if(e.requestId !== ID) return next(e)
24    const E = $.ui.resolve(e)
25    try {
26      const body = await draw($, E)
27      return frame(E,"Read-only Mode","Toggle a reminder guard that refuses built-in mutating tools and Bash.",body)
28    } catch(error) {
29      return frame(E,"Read-only Mode",'Unable to inspect this data.',[text(E,error.message,{color:'yellow'}),E.Button({key:'refresh',label:'Refresh',onPress:()=>$.ui.invalidate('ui.render')})])
30    }
31  })
32}
33async function draw($, E) {
34  const refresh = E.Button({key:'refresh',label:'Refresh',hotkey:'r',plain:true,onPress:()=>$.ui.invalidate('ui.render')})
35
36return [text(E,enabled?'Guard ON':'Guard OFF',{bold:true,color:enabled?'green':'yellow'}),
37 text(E,'Blocks Edit, Write, NotebookEdit, and all Bash calls. MCP and other mods are outside this reminder guard.'),
38 text(E,blocked+' calls refused'),
39 E.Button({key:'toggle',label:enabled?'Disable guard':'Enable guard',onPress:()=>{enabled=!enabled;$.ui.invalidate('ui.render')}})]
40
41}
42
hooks/ui.js 36 lines
1// Pure UI helpers. No engine access; each plugin contains its own copy.
2export function clean(value, limit = 9000) {
3  return String(value ?? '').replace(/[\u0000-\u0008\u000b\u000c\u000e-\u001f\u007f-\u009f]/g, '').slice(0, limit)
4}
5export function text(E, value, props = {}) {
6  return E.Text({ ...props, children: [clean(value)] })
7}
8export function code(E, value, language = 'text') {
9  return E.Code({ source: clean(value), language })
10}
11export function row(E, children) {
12  return E.Box({ flexDirection: 'row', columnGap: 2, flexWrap: 'wrap', children })
13}
14export function frame(E, title, subtitle, children) {
15  return E.Box({ flexDirection: 'column', gap: 1, children: [
16    text(E, title, { bold: true, color: 'cyan' }),
17    text(E, subtitle, { dimColor: true }), ...children,
18  ] })
19}
20export function bar(percent, width = 24) {
21  const p = Math.max(0, Math.min(100, Number(percent) || 0))
22  const n = Math.round(p / 100 * width)
23  return '[' + '#'.repeat(n) + '-'.repeat(width - n) + '] ' + p.toFixed(1) + '%'
24}
25export function pretty(value) { return JSON.stringify(value, null, 2) }
26export function bounded(value, max = 9000) {
27  if (value.length > max) throw new Error('Input exceeds ' + max + ' characters. Use a smaller selection.')
28  return value
29}
30export function entries(value) { return value && typeof value === 'object' ? Object.entries(value) : [] }
31export function safePath(value) {
32  const path = value.trim()
33  if (!path || path.startsWith('-') || /[\x00-\x1f]/.test(path)) throw new Error('Enter a path without control characters or leading flags.')
34  return path
35}
36