shellfirm
Safety guardrails for ai coding agents and human terminal commands
shellfirm is a Claude Code plugin and MCP server that intercepts dangerous shell commands before execution, providing safety guardrails for both AI coding agents and human developers. It analyzes commands against 100+ risky patterns across filesystems, git, Kubernetes, Docker, databases, and cloud platforms, prompting users to solve simple challenges before allowing destructive operations. The tool integrates with Claude Code via MCP to expose command analysis tools, while also installing shell hooks that automatically check every bash command for potential risks and suggest safer alternatives.
Key Features
Use Cases
- 01Preventing AI coding agents from executing destructive filesystem operations like rm -rf or accidental deletions
- 02Protecting teams from force-pushing over shared git branches with git push --force
- 03Blocking risky Kubernetes operations in production clusters before deployment errors cascade
- 04Intercepting database DROP commands and suggesting safer backup-first workflows
- 05Analyzing Terraform and cloud CLI commands for potential resource deletion before execution
- 06Enforcing team safety policies across local development and CI/CD environments via shared configuration
Related Plugins
View moreandrej-karpathy-skills
A single CLAUDE.md file to improve Claude Code behavior, derived from Andrej Karpathy's observations on LLM coding pitfalls.
claude-mem
Persistent Context Across Sessions for Every Agent – Captures everything your agent does during sessions, compresses it with AI, and injects relevant context back into future sessions. Works with Claude Code, OpenClaw, Codex, Gemini, Hermes, Copilot, OpenCode + More
Understand-Anything
Graphs that teach > graphs that impress. Turn any code into an interactive knowledge graph you can explore, search, and ask questions about. Works with Claude Code, Codex, Cursor, Copilot, Gemini CLI, and more.
rtk
CLI proxy that reduces LLM token consumption by 60-90% on common dev commands. Single Rust binary, zero dependencies
shellfirm — FAQ
What is shellfirm and how does it work with Claude Code?+
shellfirm is a command safety tool that intercepts risky shell commands before execution and integrates with Claude Code via an MCP server. It exposes tools that let Claude analyze commands, explain risks, and suggest safer alternatives while also installing hooks to automatically check every bash command.
How do I install and connect shellfirm to Claude Code?+
Install via npm (npm install -g @shellfirm/cli), Homebrew, or Cargo, then run 'shellfirm connect claude-code' to set up both automatic shell hooks and MCP integration. Restart your shell or source your rc file to activate the protection.
Which AI clients and shells does shellfirm support?+
shellfirm works with Claude Code, Cursor, and other MCP-compatible AI agents. It supports 8 shells: Zsh, Bash, Fish, Nushell, PowerShell, Elvish, Xonsh, and Oils.
Does shellfirm require API keys or external services?+
No, shellfirm runs entirely locally and does not require API keys or external services. It analyzes commands against built-in pattern libraries and project-level .shellfirm.yaml policies.
Is shellfirm free and open source?+
Yes, shellfirm is free and open source software released under the Apache-2.0 license. The code is available on GitHub at kaplanelad/shellfirm.
Can I customize which commands are flagged as risky?+
Yes, you can configure severity thresholds, challenge types, and add custom checks via configuration files. Teams can share .shellfirm.yaml project policies that add additional protection rules without weakening existing ones.
How do I install shellfirm?+
Open the source repository on GitHub and follow its README. shellfirm is a plugin — MCP Agents Market links you directly to the official repo.
Is shellfirm free?+
shellfirm is an open-source project hosted on GitHub. Check the repository for its license and any usage requirements.