agentguard CLAUDE.md

agentguard CLAUDE.md is an instructions file for coding agents from SumonMSelim/agentguard. It costs 1,489 tokens per session, scanned F, original, MIT.

Project instructions for agentguard, a tool that installs security rules for AI coding agents such as Claude Code, Kiro, Cursor, Codex, and Grok.

In plain words
What is it for?
Use it to install, preview, check, manage, or remove guardrails globally or in a project, with optional skill packs such as Go or AWS.
Why use it?
It places guardrails at the shell-command level, so safety rules are enforced when commands run rather than existing only as written instructions.

Instructions file

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add instructions/sumonmselim/agentguard/claude-md
Clone the repo
git clone --depth 1 https://github.com/SumonMSelim/agentguard

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for agentguard CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/sumonmselim/agentguard/claude-md.svg)](https://agentmods.dev/instructions/sumonmselim/agentguard/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/sumonmselim/agentguard/claude-md"><img src="https://agentmods.dev/badge/instructions/sumonmselim/agentguard/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,489 This file is loaded in full into every session.
When invoked 1,489 The same file — it is already loaded in full.
Security scan F 4 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.01489 $0.01489
Opus 5 $0.00745 $0.00745
Sonnet 5 $0.00298 $0.00298
Haiku 4.5 $0.00149 $0.00149

Measured 5d ago against content hash 9ba6d3a5eef1, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade F, and why

agentguard CLAUDE.md scanned grade F with 4 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 5d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Downloads and executes remote codehighSupply chain

curl | sh runs whatever the server returns today, which is not necessarily what it returned when this was reviewed.

| `block-destructive-ops.sh` | `rm -rf /`, `rm ~`, pipe-to-shell (`curl \| bash`, `wget \| sh`) |

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

When `~/.claude/settings.json` exists, installer merges rather than overwrites:

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

| `block-destructive-ops.sh` | `rm -rf /`, `rm ~`, pipe-to-shell (`curl \| bash`, `wget \| sh`) |

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

| `block-destructive-ops.sh` | `rm -rf /`, `rm ~`, pipe-to-shell (`curl \| bash`, `wget \| sh`) |
CLAUDE.md · 101 lines

How it starts

The opening of the file, as written. The whole thing — 101 lines — stays where its author put it; the contents beside it link to each section on GitHub.

CLAUDE.md

Guidance for Claude Code (claude.ai/code) working in this repo.

What this repo is

agentguard installs security guardrails for AI coding agents (Claude Code, Kiro, Cursor, Codex, Grok). Enforces rules at shell hook level — not just instructions. Install target: user home (~/.claude/, ~/.kiro/, ~/.grok/) or project dir (.cursor/), not this repo.

Commands

Preferred: Use the agentguard command (installed by the wrapper or packages).

# Install / manage guardrails
agentguard claude                          # Claude Code (global)
agentguard kiro                            # Kiro (global)
agentguard grok                            # Grok
agentguard cursor                          # Cursor (project-local, run from CWD)
agentguard all                             # All agents
agentguard claude --dry-run                # Preview without writing
agentguard claude --skills go,aws          # With specific skill packs
agentguard cursor --skills go,aws          # Cursor full install + skills
agentguard claude --project --skills go    # Append skills to CWD only (no hooks)

# Uninstall / check
agentguard uninstall claude
agentguard uninstall claude --dry-run
agentguard check claude
agentguard check all

# Bootstrap (one time only, from a fresh clone — this installs the `agentguard` CLI wrapper)
#   ./install.sh claude     # after this, use `agentguard claude` etc. for everything

# Tests
bash tests/run_all.sh                        # All suites
bash tests/claude.sh                         # Hook logic + Claude install check
bash tests/claude.sh hooks                   # Hook logic only
bash tests/claude.sh install                 # Install check only
bash tests/check-sync.sh                     # Assert instruction files are in sync

Requirements: bash, jq.

Architecture

Hooks (hooks/)

Six shell scripts enforcing rules at tool-call level. Each reads JSON from stdin, exits 2 to block or 0 to allow. Exit codes: 0 = allow, 2 = block (agent sees stderr as feedback), 1 = hook error (also blocks).

Read the full file on GitHub · 101 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 5d ago First seen · 101 lines · 1,489 tokens per session scan F 9ba6d3a5eef1

Subscribe to this mod's changes

agentguard CLAUDE.md is an instructions file published in the GitHub repository SumonMSelim/agentguard (56 stars, last pushed 1mo ago), licensed MIT. It adds 1,489 tokens to every session, about $0.0074 per session on Opus 5. A static security scan graded it F with 4 findings (downloads and executes remote code, reads agent configuration directories, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.

Related

Other instructions, from other repositories

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

deepseek-harness AGENTS.md

AGENTS.md instructions for deepseek-ai/deepseek-harness, covering agents.md, pre-stable apis and released session data, repository layout, commands and host sandbox failures.

deepseek-ai/deepseek-harness · 3,733 tokens