The built-in Bash deny list gives you a false sense of security.
clawband actually stops destructive commands.
git clone https://github.com/jamessoubry/clawband && bash clawband/install.sh
Requires jq — pre-built binaries for Linux x86_64, macOS arm64, macOS x86_64. Rust only needed as a fallback.
brew install jamessoubry/clawband/clawband
Homebrew installs the binary — then run clawband install to wire the hook, and clawband verify to confirm it's active.
settings.json. You add rm -rf.
You feel protected. You're not.This hook blocks what actually matters. Two ways to use it:
Keep Claude Code's permission prompts active. Use clawband to guarantee that no compound-command trick or bypass can sneak a destructive command through — even when Claude hallucinates or gets prompt-injected.
Add patterns you trust to your allow.patterns file to stop being asked about them. clawband still hard-blocks anything catastrophic — you just stop approving the same safe commands over and over.
Turn off all of Claude Code's permission prompts (bypassPermissions mode). Your agent runs freely without grinding to a halt every few seconds.
clawband becomes your safety net — automatically blocking filesystem destruction, supply-chain attacks, and infra wipeouts before they execute. Semi-autonomous without the terror.
Note: in this mode clawband's ask-tier prompts are automatically suppressed (Claude Code wouldn't show them anyway when permissions are bypassed), so deny is your only real backstop here — the ask tier only gates behaviour when approvals are on (Mode A).
Registered as a PreToolUse hook — fires before Claude's Bash tool executes anything.
The built-in deny list never sees inside echo hi && rm -rf /. clawband splits first, checks every segment independently.
Catastrophic patterns are hard-blocked, unconditionally — even in bypassPermissions mode. Risky-but-legitimate ones prompt for approval when approvals are on, but are silently allowed in bypassPermissions mode (no prompt to suppress). Everything else passes instantly.
When a command runs a script (bash foo.sh, ./run.sh, bash < script), clawband reads the file and checks every line before execution.
If a compound command writes to a file and immediately runs it (echo "..." > run.sh && bash run.sh), clawband flags it — the content can't be scanned between write and execute.
Written in Rust. Single binary, no subprocesses. ~30ms per hook call vs ~380ms for an equivalent bash implementation.
| Category | Examples | Verdict |
|---|---|---|
| File system destruction | rm -rf /, rm -rf ~, sudo rm -rf, mkfs, dd if= |
deny |
| Silent file truncation | truncate -s 0 |
deny |
| Infrastructure | terraform destroy, kubectl delete --all |
deny |
| AWS destructive ops | aws s3 rm --recursive, aws cloudformation delete-stack, aws lambda delete-function |
deny |
| Pipe to interpreter | | bash, | sh, | python, | node, | ruby, | perl |
deny |
| Heredoc to interpreter | bash <<, python << |
deny |
| find / xargs escalation | find … -delete, -exec bash, xargs sh |
deny |
| Pipe to DB / system tools | | psql, | mysql, | patch, | crontab |
deny |
| git force push | git push --force, git push -f |
deny |
| eval | eval "$(brew shellenv)" — common but executes arbitrary strings |
ask |
| Destructive git (local) | git reset --hard, git checkout -- , git stash drop |
ask |
| git clean | git clean -f, git clean -fd — wipes untracked files |
ask |
| git push --delete | Remote branch deletion | ask |
| Safe inline code | | python3 -c "…", | python3 -m mod, --force-with-lease |
pass |
Extend or override the built-in lists without touching the binary. Create files in ~/.clawband/ — one case-insensitive regex per line.
Manage your pattern lists without editing files. Changes take effect immediately — no restart needed.
The installer also adds /allow and /deny Claude Code slash commands so you can update your lists without leaving the chat. When clawband prompts for approval it includes the exact clawband allow command to silence it permanently.
--dangerously-skip-permissions / bypassPermissions?rm -rf can wipe your files. clawband makes it far safer: it runs as a PreToolUse hook that hard-blocks catastrophic commands before they execute, regardless of permission mode. Many people run bypassPermissions specifically because clawband is the backstop.rm -rf or other destructive commands?rm -rf /, mkfs, dd, git push --force, pipe-to-shell, and 70+ more) before they run. Unlike Claude Code's built-in deny list, it splits compound commands so ls && rm -rf / is still caught.allow.patterns so you stop being asked about them; or turn approvals off entirely (bypassPermissions) and let clawband hard-block only the genuinely dangerous commands. Note that in bypassPermissions mode, clawband's own ask-tier prompts are also suppressed (Claude Code wouldn't surface them either) — deny is what's still protecting you there. Either way you stop rubber-stamping safe commands while staying protected from catastrophic ones.echo hi && rm -rf / sails through. clawband splits on &&, ||, and ;, scans script files before execution, inspects subshells, and catches write-then-execute tricks. It's a real parser, not a string match.CLAUDE_CODE_DEFAULT_MODE environment variable) and, when it's active, silently allows anything that would have been an ask-tier decision instead of prompting — a prompt would never be shown to you anyway once permissions are bypassed. deny-tier patterns are unaffected and keep hard-blocking unconditionally, so deny is the tier doing all the work while you're in YOLO mode.default_decision = allow in ~/.clawband/config. By default, a command that matches none of clawband's patterns falls through to Claude Code's native permission system, which prompts generically for anything not already on its own allow list. With default_decision = allow, clawband instead emits an explicit allow for unmatched commands, so only your deny/ask patterns stop or prompt anything — there's no native permission prompt to route around. (There's also default_decision = ask, which reviews everything not explicitly allowed; the default remains passthrough.)