CC Safety Net
kenryu42/cc-safety-net
Guard that blocks destructive Git and file commands and secret access before a coding agent runs them
CC Safety Net is a pre-execution guard for AI coding agents that blocks destructive Git and file system commands and access to secrets before a tool call runs. Hermes Agent is one of 16 supported coding CLIs.
What CC Safety Net does
CC Safety Net, short for Coding CLI Safety Net, runs before a tool call and blocks destructive commands and access to secrets such as SSH keys and .env files. It parses what a command does, so wrapping it in bash -c or python -c, or reordering flags, does not hide it. Blocked examples include git reset --hard, git push --force and rm -rf on dangerous targets. A broken config file never blocks anything.
The README is explicit that it is not a sandbox: it does not contain processes, set filesystem permissions or watch network egress. Policy can be tuned in a GUI with Standard, Strict and Paranoid presets, extended with rulebooks for Terraform, AWS, gcloud and Azure, and shared with a team by committing the .cc-safety-net/ folder. Hermes Agent is one of 16 supported coding CLIs on Windows, macOS and Linux, and a Node.js library API exposes checkCommand.
Key features
- Blocks destructive commands such as git reset --hard, git push --force and rm -rf on dangerous targets
- Blocks access to SSH keys, .env files, ~/.aws and coding-CLI credentials
- GUI with Standard, Strict and Paranoid presets, opened with npx cc-safety-net gui
- Official rulebooks for Terraform, AWS, gcloud and Azure, or your own JSON
- Team policy shared through a committed .cc-safety-net/ folder
- Library API with checkCommand for Node.js
When to use it
- Stop a Hermes Agent session from running git push --force by accident
- Keep agents away from SSH keys and .env files
- Apply the same command policy to every developer on a team
Who it is for: Developers who let coding agents run shell commands and want a safety check before each tool call.
How it fits with Hermes Agent
Hermes Agent is one of 16 supported coding CLIs and carries a hermes-agent topic on the repository.
How to install CC Safety Net
These commands are copied from the project's README. Check the repository for the latest steps before you run them.
npx -y cc-safety-net@latest install
npx -y cc-safety-net@latest doctorRequirements: Node.js 18 or higher
FAQ
What is CC Safety Net?
CC Safety Net is a pre-execution guard for AI coding agents. It blocks destructive Git and file system commands and access to secrets such as SSH keys and .env files before a tool call runs.
Does CC Safety Net work with Hermes Agent?
Yes. Hermes Agent is on the list of supported coding CLIs, alongside Claude Code, Codex, Cursor, OpenClaw and others, on Windows, macOS and Linux.
How do I install CC Safety Net?
Run npx -y cc-safety-net@latest install to install into the coding CLIs on your machine, then npx -y cc-safety-net@latest doctor to check that protection works. Keep the @latest qualifier.
Similar security for Hermes Agent
All securityHook and skill guard that stops AI coding agents from unrequested checksums and scope creep
LoRexxar KunLun-MOpen-source static code security scanner with a built-in skill for AI agents including Hermes
Infisical Agent VaultHTTP credential proxy and vault that keeps real API keys away from AI agents such as Hermes
prompt-security ClawSecSecurity skill suite with signed advisories and drift detection for OpenClaw, Hermes and related agents
SafeAI-Lab-X ClawKeeperHost-agnostic safety middleware that blocks risky agent tool calls and redacts sensitive tool results
Zyrexnn CybermesSecurity assistant framework for authorized bug bounty work, with an MCP server and Hermes Agent support
Related guides: How to run Hermes Agent securely