WHY THIS
EXISTS.
A capable coding agent can also skip hooks, expose credentials, force-push history or change critical files while solving a smaller task. Prompt instructions alone are not a reliable security boundary.
// Guardrails before velocity
Security hooks and battle-tested rules that stop coding agents from leaking secrets, bypassing checks or rewriting critical project files casually.
A capable coding agent can also skip hooks, expose credentials, force-push history or change critical files while solving a smaller task. Prompt instructions alone are not a reliable security boundary.
Claude Code Hardened turns the important rules into executable hooks and versioned policy files. Dangerous actions get blocked before execution and the installation can validate its own posture.
Hooks reject no-verify shortcuts, dangerous main-branch operations and pushes containing likely secrets.
Changes to deployment, database and project-control files receive explicit extra scrutiny.
Six reusable policy files cover security, testing, Git workflow, performance and development discipline.