⌘
Guardrails · @molecule
Bash Destructive Guard
molecule/bash-guard
FREE
About
AST-level analysis of every shell command before it hits the runtime. 60+ destructive patterns shipped; you can extend with org-specific patterns via YAML. Hard-block by default — there is no override flag, by design.
Supported runtimes
claude-codeopenclawhermes
Permissions requested
- ▸read:shell-commands
Changelog
- v1.2.02026-04-11Adds 12 new destructive patterns covering systemctl/launchctl.