By Lelu-ai
Enforce access policies on Claude Code's tool calls, blocking risky Bash, Edit, Write, and MCP actions until approved. Starts in shadow mode to audit without blocking.
Turn a plain-English rule into a Lelu policy entry, e.g. "/lelu never touch the prod database"
Leave shadow mode — Lelu's deny/ask decisions start actually applying instead of just being logged
Return to shadow mode — Lelu logs what it would have done but blocks nothing
Show Lelu's current mode (shadow vs enforce) and a summary of recent decisions
Executes bash commands
Hook triggers when Bash tool is used
Modifies files
Hook triggers on file write and edit operations
Own this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimOwn this plugin?
Verify ownership to unlock analytics, metadata editing, and a verified badge. GitHub access is read-only (username + org membership).
Sign in to claimBased on adoption, maintenance, documentation, and repository signals. Not a security audit or endorsement.
npx claudepluginhub lelu-ai/lelu --plugin leluAPort Agent Guardrails — security policy enforcement for every tool call. Intercepts tool use, evaluates against your passport policy, and blocks unauthorized actions.
AGT governance hooks and MCP tools for Claude Code sessions
Real-time policy enforcement and tamper-evident audit for tool calls (MCP and built-in) in a Claude Code session. Forwards every tool call to a local SecureVector app for cloud-managed deny rules and persistent audit logging. Fails open if the local app is unreachable.
Achieve flow state safely with Claude Code. Auto-approves routine work, gates risky actions, hard-blocks dangerous patterns. Dual enforcement (skill + hooks), token cap for cost governance, full audit trail. Zero dependencies.
ArmorIQ intent-based security enforcement for Claude Code: policy-based tool access control, intent verification, CSRG cryptographic proofs, and audit logging.
Security controls for AI agents — deterministic policy enforcement, OWASP ASI10 scanning, and audit trails.