env-guard
Reviewed
at commit 0f95222
Blocks Claude from editing or writing .env files, private keys and other common secret files, and tells it why.
0 upvotes
Log in to upvote or save- Pinned commit
-
0f9522210e5bf9072a7d39fac5736a7afc501397 - Review
-
Reviewed
Written and reviewed by the modsforClaude.com maintainers at the pinned commit. Hooks only Edit, Write and NotebookEdit tool calls and reads the file path, never the content. Uses $.fs.stat to resolve symlinks. No network calls, nothing stored. Validates with claude plugin validate; 5 of 5 tests pass on Claude Code 2.1.286.
- Categories
- Hooked events
When Claude tries to change a protected file with Edit, Write or NotebookEdit, the call is refused before it runs and Claude is told why, so it asks you to make the change yourself.
Protected by default: .env, .env.*, *.pem, *.key, *.pfx, *.p12, id_rsa, id_dsa, id_ecdsa, id_ed25519, secrets.*. Always allowed: .env.example, .env.sample, .env.template. Both lists can be changed in the settings of the mod.
Symlinks that lead to a protected file are blocked too. The mod only looks at the file path: it never reads the content of the edit or the files themselves, makes no network calls and stores nothing.
What it does not do
It is a safety net against accidental edits, not a security boundary. It does not block reading secret files, and it does not block shell commands that write to them, such as echo X >> .env. Use Claude Code's permission rules for those.
Load it
See How to load a Claude Code mod for the terminal and the desktop app.