Hermes Atlas
Security & sandboxing · works with Hermes Agent

CC Safety Net

kenryu42/cc-safety-net

Guard that blocks destructive Git and file commands and secret access before a coding agent runs them

In short

CC Safety Net is a pre-execution guard for AI coding agents that blocks destructive Git and file system commands and access to secrets before a tool call runs. Hermes Agent is one of 16 supported coding CLIs.

What CC Safety Net does

CC Safety Net, short for Coding CLI Safety Net, runs before a tool call and blocks destructive commands and access to secrets such as SSH keys and .env files. It parses what a command does, so wrapping it in bash -c or python -c, or reordering flags, does not hide it. Blocked examples include git reset --hard, git push --force and rm -rf on dangerous targets. A broken config file never blocks anything.

The README is explicit that it is not a sandbox: it does not contain processes, set filesystem permissions or watch network egress. Policy can be tuned in a GUI with Standard, Strict and Paranoid presets, extended with rulebooks for Terraform, AWS, gcloud and Azure, and shared with a team by committing the .cc-safety-net/ folder. Hermes Agent is one of 16 supported coding CLIs on Windows, macOS and Linux, and a Node.js library API exposes checkCommand.

Key features

  • Blocks destructive commands such as git reset --hard, git push --force and rm -rf on dangerous targets
  • Blocks access to SSH keys, .env files, ~/.aws and coding-CLI credentials
  • GUI with Standard, Strict and Paranoid presets, opened with npx cc-safety-net gui
  • Official rulebooks for Terraform, AWS, gcloud and Azure, or your own JSON
  • Team policy shared through a committed .cc-safety-net/ folder
  • Library API with checkCommand for Node.js

When to use it

  • Stop a Hermes Agent session from running git push --force by accident
  • Keep agents away from SSH keys and .env files
  • Apply the same command policy to every developer on a team

Who it is for: Developers who let coding agents run shell commands and want a safety check before each tool call.

How it fits with Hermes Agent

Hermes Agent is one of 16 supported coding CLIs and carries a hermes-agent topic on the repository.

How to install CC Safety Net

These commands are copied from the project's README. Check the repository for the latest steps before you run them.

npx -y cc-safety-net@latest install
npx -y cc-safety-net@latest doctor

Requirements: Node.js 18 or higher

FAQ

What is CC Safety Net?

CC Safety Net is a pre-execution guard for AI coding agents. It blocks destructive Git and file system commands and access to secrets such as SSH keys and .env files before a tool call runs.

Does CC Safety Net work with Hermes Agent?

Yes. Hermes Agent is on the list of supported coding CLIs, alongside Claude Code, Codex, Cursor, OpenClaw and others, on Windows, macOS and Linux.

How do I install CC Safety Net?

Run npx -y cc-safety-net@latest install to install into the coding CLIs on your machine, then npx -y cc-safety-net@latest doctor to check that protection works. Keep the @latest qualifier.

Similar security for Hermes Agent

All security

Related guides: How to run Hermes Agent securely