Claude Code moves fast, but it lacks native brakes. On October 11, 2026, the Skillkeel team released v0.1.13 of skillkeel-starter, a free, MIT-licensed plugin that introduces guard hooks to intercept destructive shell commands and credential leaks before they hit the filesystem. The release specifically targets Claude Code 2.1.284, achieving an 8 of 8 pass rate on its internal evaluation suite.
The Guardrails
The core of the plugin is guard-bash, which blocks dangerous operations like rm -rf /, force pushes without --force-with-lease, and ORM wipes such as prisma migrate reset or rails db:reset. A secondary hook, secret-scan, blocks file writes containing AWS keys, Anthropic tokens, or hard-coded passwords. Unlike a full sandbox, this is a guardrail system: when a command is blocked, Claude sees the reason and asks the user for permission, preserving developer control while preventing catastrophic mistakes.
Public Verification
What sets this release apart is the transparency of its testing. The plugin itself is validated by 89 unit tests and 8 evaluation cases. It references a broader community effort: the shared corpus skillkeel/tamper-cases, which contains 105 cases. This corpus includes 52 evasion tests from a separate project (lumis-skills) and destructive command families from this suite. While the 52 evasion cases are a reference rather than part of the plugin's direct test suite, the shared corpus provides a robust, community-verified benchmark. These results are documented in docs/compat.md with pass counts for every Claude Code version tested since September 18, 2026. The eval runner even includes a 'trigger mode' to verify that skills activate on plain requests, ensuring the plugin works as intended without explicit invocation.
Installation and Limitations
Developers can install the plugin via npx github:skillkeel/skillkeel-starter or directly inside Claude Code using the marketplace. The source notes that the package is not yet on the npm registry, so the installer fetches directly from the repository. While the free starter covers essential guardrails, the team also offers a paid 'Skillkeel Kit' with additional skills, subagents, and playbooks, though the open-source core remains fully functional for basic protection.
Key Takeaways
- Skillkeel v0.1.13 introduces
guard-bashandsecret-scanhooks for Claude Code, blocking destructive commands and credential leaks in file writes. - The plugin is validated by 89 unit tests and 8 eval cases, referencing a broader community corpus of 105 tamper cases.
- Installation is straightforward via
npxor the Claude Code marketplace, with no npm registry dependency yet. - A paid tier exists for advanced features, but the MIT-licensed starter provides essential safety nets for free.
The Bottom Line
Skillkeel fills a critical gap in the Claude Code ecosystem by providing transparent, community-verified guardrails that prevent common developer errors. The commitment to a public tamper corpus sets a new standard for trust in AI agent tooling.