Agent skill

Cc Safety Net

by kenryu42 in kenryu42/cc-safety-net

Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.

MITAuto-check: notesDevelopment

Install Cc Safety Net

skills CLI
$ npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kenryu42/cc-safety-net cc-safety-net --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cc-safety-net .claude/skills/cc-safety-net && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cc-safety-net
GitHub stars
1.6k
Token cost
~4.4k tokens
SKILL.md length
2,431 words
Files
2
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.

  • Works in 4 steps: Get the exact blocked command. If the… → Pass the exact command to npx -y… → Read the trace: how the command was… → …
  • Development work in your project
  • SKILL.md covers Learn the current CLI, Core model, Choose the workflow and Explain a decision, plus 7 more sections
  • Calls npx, git and npm

What it does

Cc Safety Net is an agent skill from kenryu42/cc-safety-net. Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.

Its SKILL.md is about 4.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files (for example `agents/openai.yaml`).

It sits in Development. The repository describes itself as: A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports… The licence is MIT.

When your agent uses it

  • Development work in your project

Example prompts

  • “/cc-safety-net”

Requirements

  • Node.js

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Get the exact blocked command. If the user does not have it, find it with
  2. Pass the exact command to npx -y cc-safety-net explain as one literal argument. Prefer an
  3. Read the trace: how the command was split, which rule matched, and the RESULT status and
  4. Report the reason in plain language. For a genuine hazard, suggest the safer alternative the

What it can do on your machine

Read from SKILL.md and the folder at commit 2615848. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx
    • git
    • npm

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, git and npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Cc Safety Net loads about 4.4k tokens when it runs. Until then it costs about 45 tokens; SKILL.md has 2,431 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~45
When it runs · the whole SKILL.md, loaded when a task matches
~4.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:184
    exact file name (for example `~/code/**/.env.local`; the

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kenryu42/cc-safety-net at commit 2615848, republished under its MIT licence (© kenryu42). 2,431 words, ~4,442 tokens.

Download SKILL.mdSave it as .claude/skills/cc-safety-net/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
cc-safety-net
description
Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.
disable-model-invocation
true

CC Safety Net

CC Safety Net hooks into coding agent CLIs (Claude Code, Codex, Cursor, Gemini CLI, and others) and blocks destructive commands and secret access before they run. The cc-safety-net CLI inspects and controls that protection. Run it as npx -y cc-safety-net.

Learn the current CLI

The installed CLI is the authority for command syntax. Do not guess flags.

bash
npx -y cc-safety-net --help
npx -y cc-safety-net help <command>

Run npx -y cc-safety-net rule doc and treat that output as the complete source of truth for rulebook schema, paths, GitHub sources, matching behavior, and validation.

These commands are read-only and safe to run for discovery: --help, --version, status, doctor, logs (without --prune-legacy), explain, rule list, rule verify, rule doc, policy check, help. Every other command mutates configuration or installed integrations; run those only as part of a workflow below.

Core model

  • Built-in guards always apply. Custom rules only add restrictions; nothing in rule config can bypass built-in CC Safety Net protections.
  • Config files (rule.json) list rulebook sources. Rule definitions live in rulebook.json, not directly in rule.json.
  • Three scopes: user (all projects), project (current project only), and shareable GitHub rulebooks at .cc-safety-net/rules/<rulebook-name>/rulebook.json in a repository.
  • Rulebooks are live files. The runtime reads each rulebook.json on every tool call, so a saved edit applies to the next command with no sync step.
  • policy.json sets the safety level, per-feature toggles, per-rule overrides, and path lists. It has two scopes: the project file .cc-safety-net/policy.json, committed and shared with the team, layered on the user file that applies to every project.
  • The session safety level is standard, strict, or paranoid, set per session with the CC_SAFETY_NET_LEVEL environment variable.

Choose the workflow

  • The user asks why a command was blocked, or shows a BLOCKED by CC Safety Net message: explain a decision.
  • The user thinks a block was wrong: triage a false positive.
  • The user wants to add, edit, disable, or migrate blocking rules: configure rules.
  • The user wants to change the safety level, toggle a protection, or adjust path lists: configure the policy.
  • The user wants CC Safety Net installed into or removed from an agent CLI: manage integrations.
  • A rule does not fire, or the user asks whether protection is working: diagnose.
  • The user asks how or why the analyzer behaves a certain way, beyond what explain and rule doc show: answer from the source.

Explain a decision

  1. Get the exact blocked command. If the user does not have it, find it with npx -y cc-safety-net logs (narrow with --project ., --agent <name>, or --since <days>).
  2. Pass the exact command to npx -y cc-safety-net explain as one literal argument. Prefer an argv-capable tool; when invoking through a shell, shell-escape the whole command as one argument. Never interpolate raw command text into double quotes: $(), backticks, and variables would expand before explain receives it. Add --cwd <path> when the decision depends on the working directory. Once received, explain analyzes the string and never executes it.
  3. Read the trace: how the command was split, which rule matched, and the RESULT status and reason. explain exits 0 for both allowed and blocked verdicts; read the verdict from the output, not the exit status.
  4. Report the reason in plain language. For a genuine hazard, suggest the safer alternative the reason names, such as git stash before git reset --hard.

Triage a false positive

  1. List recent suspect denials with npx -y cc-safety-net logs --suspect --since 7, or fetch one entry with npx -y cc-safety-net logs --id <id>.
  2. Reproduce the decision with explain and read which rule fired.
  3. If a custom rule fired, fix that rulebook: disable or reword it with an override, or edit the rule (see configure rules), then re-run explain to confirm the new verdict.
  4. If a built-in rule fired, no rule edit can relax it. Check the reason for a documented escape hatch, such as CC_SAFETY_NET_WORKTREE=1 for local git discards in linked worktrees (git discards in a temp-root repository outside the workspace are already allowed), or rule wrapper add when a trusted transparent wrapper hid the real command from the analyzer. Pass the wrapper name as a separate argv value, or shell-escape it as one argument. If the user explicitly wants that built-in rule off, read its id from the ruleId field of explain --json and propose a per-rule policy override (see configure the policy). Otherwise explain the risk the rule guards against and suggest reporting the case at https://github.com/kenryu42/cc-safety-net/issues.

Configure rules

Use information already provided in the user's prompt. Ask only when the scope, action, rule intent, merge behavior, or target command is unclear.

  1. Determine the requested scope from the prompt when possible:
    • User: applies to all projects.
    • Project: applies only to the current project.
    • GitHub: edits or creates a shareable rulebook structure in the current repository.
  2. Determine whether to add a rule, edit a rule, disable a rule, override a reason, trust a transparent wrapper, migrate legacy rules, or explain custom rules from the prompt when possible.
  3. Inspect existing configs before modifying installed local rules:
    • Run npx -y cc-safety-net rule verify
    • Run npx -y cc-safety-net rule list
  4. Inspect relevant project files only when the user asks for rule suggestions or the requested rule depends on project context. Look at manifests, scripts, task runners, CI, infrastructure, database, migration, and deployment files that explain risky commands.
  5. Convert the request into valid CC Safety Net JSON using rule doc.
    • For User or Project scope, add or edit the selected local rule.json and <rulebook-name>/rulebook.json.
    • For GitHub scope, add or edit .cc-safety-net/rules/<rulebook-name>/rulebook.json in the current repository.
    • Do not offer to add a GitHub source with owner/repo; installing rules from a GitHub source is outside this workflow.
    • If the user explicitly asks to install existing GitHub rulebooks instead of authoring them, use npx -y cc-safety-net rule add owner/repo --only <rulebook...>; omit --only only when they want every rulebook, and add --ref <ref> only when they name a non-default ref. rule add --only <rulebook...> with no source selects from the official cc-safety-net/rulebooks repository, whose curated rulebooks block destructive Terraform, AWS, gcloud, and Azure CLI operations; prefer installing one of those over authoring when it already covers the request.
    • For transparent wrappers, prefer npx -y cc-safety-net rule wrapper add with the trusted wrapper name passed as a separate argv value, or shell-escaped as one argument, over editing rule.json by hand.
  6. Preserve unrelated existing rulebook sources, overrides, and rulebooks. Preview proposed JSON before writing when creating a new rulebook, merging with existing config, or resolving ambiguity.
  7. For GitHub rules, ensure the repository layout is .cc-safety-net/rules/<rulebook-name>/rulebook.json, and ensure the source name, directory name, and rulebook name match exactly.
  8. Validate after edits:
    • User or Project rules: run npx -y cc-safety-net rule verify and npx -y cc-safety-net rule list. Both commands cover every scope, so neither takes --global.
    • Shareable GitHub rulebook-only edits: run npx -y cc-safety-net rule verify. Run list only if the rulebook is also installed in local rule.json.
  9. If validation fails, show the exact errors and make the smallest fix.
  10. Confirm the saved paths or GitHub rulebook path and summarize the added or updated rules.

Rule invariants:

  • Do not use legacy inline .safety-net.json or ~/.cc-safety-net/config.json rules. Convert existing legacy files with npx -y cc-safety-net rule migrate.
  • Every rule command must be listed in allowed_commands. The tests fixtures are optional; rule verify evaluates rulebook_version 2 fixtures against the rulebook's own rules, and fixture commands are analyzer input that CC Safety Net never executes.
  • A blocked fixture, when present, must specify the expected rule, and that rule must exist in the rulebook.
  • Local source names are bare names such as project-rules; do not put filesystem paths in rules.
  • A saved rulebook is live. There is no pending state and nothing to run afterwards, so verify the edit rather than activating it.
  • A missing or invalid rulebook file makes that source inactive, and an unreadable or invalid rule.json makes every source in its scope inactive: those rules stop applying while other custom rules and built-in protections stay active. Fix the file named in the diagnostic.
  • A duplicate rulebook name keeps the first claim, user scope before project scope, and ignores the later rulebook.
  • npx -y cc-safety-net rule add owner/repo fetches remote rulebooks, validates them, and vendors each one into <rulebook-name>/rulebook.json; npx -y cc-safety-net rule update [source] re-fetches and overwrites those copies and prints what changed. The runtime never fetches, and a remote source with no vendored file reports that rule update has to vendor it first.
  • rule sync is deprecated: it only migrates lock and cache leftovers from an earlier version. Never run it as a validation or activation step.
Show full SKILL.md (1,072 more words)Show less

Configure the policy

Both policy.json files are protected: you propose the change, the user applies it. Reading them is allowed, writing them is not.

policy.json fields, all optional except version: 1 (policy check reports every schema error, so validate against it rather than guessing further fields):

  • safety.level: standard, strict, or paranoid. safety.overrides: booleans for fail_closed, paranoid_rm, and paranoid_interpreters that pin one capability apart from the level.
  • workflow.worktree_mode: boolean, allows local git discards in linked worktrees; discards in a temp-root repository outside the workspace need no toggle.
  • destructive_command_protection and secret_protection: an enabled boolean, and per-rule overrides mapping a built-in rule id (git.reset-hard, secret.basename.env) to "on" or "off". Get the id for a blocked command from the ruleId field of explain --json.
  • destructive_command_protection.allow_paths: absolute or ~/ paths where recursive delete targets are permitted. secret_protection.allow_paths: exact user-managed files or directories, or a folder followed by **/ and an exact file name (for example ~/code/**/.env.local; the folder cannot be home or above it), exempted from built-in secret patterns. Deny paths and Coding CLI protections still win. Other glob forms are rejected. secret_protection.deny_paths: extra paths protected like built-in secrets.
  • audit.retention_days: days of audit history to keep, user scope only.
  1. Inspect the current state: npx -y cc-safety-net status for the effective policy and the file paths it loaded, npx -y cc-safety-net rule list for custom rules, plus whatever project context the request depends on. Read an existing policy.json before proposing changes to it.
  2. Write the proposed policy JSON to an unprotected path such as policy-proposal.json. For project scope, set only the fields the team intends to control; an unset field inherits from the user policy, and apply writes only the fields the proposal sets. Applying replaces the target file, so the proposal is the complete policy, not a patch. Audit settings are user scope only; a project proposal cannot set them.
  3. Run npx -y cc-safety-net policy check policy-proposal.json and show the user the printed diff. Add --global to target the user policy instead of the project one. Fix every reported error and re-check until it passes.
  4. Ask the user to run the apply in their own terminal and quote the exact command: npx -y cc-safety-net policy apply policy-proposal.json (with --global when that is the scope). It confirms interactively, there is no --yes flag, and agent invocations of policy apply are blocked by design, so never run it, wrap it, or write the file yourself.
  5. Once the user confirms they applied it, run npx -y cc-safety-net status and report the effective policy, including any project scope deltas it prints.

Manage integrations

  1. Run npx -y cc-safety-net doctor first. It reports each supported platform as detected, configured, and verified, and names outdated installs with the exact repair command.
  2. Install with an explicit target flag, such as npx -y cc-safety-net install --claude-code. Run npx -y cc-safety-net help install for the full target list. Bare install opens an interactive picker; leave that for the user's own terminal.
  3. Run npx -y cc-safety-net@latest update to update every installed integration at once.
  4. Uninstall only when the user explicitly asks to remove protection, with the matching target flag.
  5. After any install, update, or uninstall, run doctor again and confirm the affected platform rows read as verified.

Diagnose

  1. npx -y cc-safety-net status shows what the runtime enforces right now, including a degraded policy.json that rule list does not report.
  2. npx -y cc-safety-net doctor verifies the installation: platform detection and hook config, a synthetic guard self-test, and configuration scopes. Use --json when parsing the result.
  3. When a custom rule does not fire, run in order: rule verify, rule list, then re-test the command with explain.

Answer from the source

For questions the CLI output cannot settle, such as why the analyzer treats a construct a certain way or whether a gap is a known limitation, read the source code of the installed version.

  1. Get <version> from npx -y cc-safety-net --version.

  2. Locate the repository. Plugin installs ship the full repository, and this skill file lives at <repo>/skills/cc-safety-net/SKILL.md inside it, so the repository root is two directories above the skill file. Use the candidate only if its package.json has "name": "cc-safety-net" and version <version>, and a src/ directory exists next to it. If the package version differs, run doctor to report the outdated integration, then treat the candidate as unavailable and continue to the next step.

  3. If no matching local root exists (skill-only installs, a mismatched plugin, or guidance without a file path), resolve the immutable commit recorded with the published package using npm view "cc-safety-net@<version>" gitHead. Require a 40-character lowercase hexadecimal commit and fetch that exact commit into a fresh owner-only temporary directory:

    bash
    set -euo pipefail
    git_head=$(npm view "cc-safety-net@<version>" gitHead)
    [[ $git_head =~ ^[0-9a-f]{40}$ ]] || { echo "Invalid published gitHead" >&2; exit 1; }
    source_dir=$(mktemp -d "${TMPDIR:-/tmp}/cc-safety-net-v<version>-XXXXXXXX")
    trap 'rm -rf -- "$source_dir"' EXIT
    chmod 700 "$source_dir"
    git -c init.templateDir= init "$source_dir"
    git -c core.hooksPath=/dev/null -C "$source_dir" fetch --depth 1 https://github.com/kenryu42/cc-safety-net "$git_head"
    git -c core.hooksPath=/dev/null -C "$source_dir" checkout --detach "$git_head"
    [[ $(git -C "$source_dir" rev-parse HEAD) == "$git_head" ]] || { echo "Source checkout mismatch" >&2; exit 1; }
    printf 'Source checkout: %s\n' "$source_dir"
    trap - EXIT

    Never answer from main; it can contain unreleased behavior the installed version does not have.

  4. Read docs/ first; residual-risk.md and secret-protection-known-limitations.md exist to answer whether something is a known gap. For behavior questions, continue into src/analyzer, src/guards, and src/rules.

  5. State in the answer which version the source came from. Treat the located source as read-only reference; do not edit, build, or run it.

  6. Remove a temporary checkout after the source inspection: rm -rf -- "<source_dir>".

Safety rules

  • Help the user operate CC Safety Net, never evade it. Do not change levels, uninstall, edit config, or propose a policy that weakens protection to get a blocked command through unless the user explicitly asks for that outcome and understands what the block guards against.
  • Never run hook; it is the integration entry point that reads hook JSON from stdin, not a user-facing command.
  • logs --prune-legacy permanently deletes legacy logs. Run it only on an explicit request, and run it with --dry-run first.
  • rule remove --delete-source deletes the local source directory. Ask before using it.
  • Prefer gui --no-open and give the user the URL instead of opening a browser from a session.
  • If a command prints an UPDATE_AVAILABLE: line, ask the user once whether to run npx -y cc-safety-net@latest update, continue the workflow without waiting either way, and do not raise it again.

© kenryu42, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file in skills/cc-safety-net of kenryu42/cc-safety-net.

  • SKILL.md
  • agents/openai.yaml

Open the folder on GitHubat commit 2615848

Compare with similar skills

Cc Safety Net next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cc Safety Net compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cc Safety Net this skillkenryu42/cc-safety-net1.6k—~4.4kAutomated safety check: NotesMIT
Vercel Composition Patternssupabase/supabase111k59 repos~726Automated safety check: PassMIT
Finishing a Development Branchobra/superpowers296k5 repos~1.9kAutomated safety check: PassMIT
Typescript Advanced Typesrolling-scopes/rsschool-app10k25 repos~4.2kAutomated safety check: PassMPL-2.0
PR Babysitteropeninterpreter/openinterpreter69k3 repos~4.2kAutomated safety check: PassApache-2.0
Code Review ChecklistshareAI-lab/learn-claude-code78k5 repos~1.1kAutomated safety check: PassMIT

Similar skills

  • Official

    React composition patterns that scale. An agent skill from supabase/supabase.

    111k GitHub starsUsed in 59 repos~726 tokens
    DevelopmentAuto-check passed
  • Walks the last step of a branch: confirm tests pass, detect the git environment, ask how to integrate, carry out your choice and clean up the worktree.

    296k GitHub starsUsed in 5 repos~1.9k tokens
    DevelopmentAuto-check passed
  • Typescript Advanced Types

    rolling-scopes/rsschool-app

    Master TypeScript's advanced type system including generics, conditional types, mapped types, template literals, and utility types for building type-safe applications.

    10k GitHub starsUsed in 25 repos~4.2k tokens
    DevelopmentAuto-check passed
  • PR Babysitter

    openinterpreter/openinterpreter

    Watches an open GitHub pull request until it merges, handling review comments, diagnosing CI failures and retrying flaky checks along the way.

    69k GitHub starsUsed in 3 repos~4.2k tokens
    DevelopmentAuto-check passed
  • Code Review Checklist

    shareAI-lab/learn-claude-code

    Reviews code against a five-part checklist covering security, correctness, performance, maintainability and testing, and reports findings in a fixed format.

    78k GitHub starsUsed in 5 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Greploop

    onyx-dot-app/onyx

    Iteratively improves a PR (GitHub), MR (GitLab), or shelved changelist (Perforce) until Greptile gives it a 5/5 confidence score with zero unresolved comments.

    32k GitHub starsUsed in 4 repos~3.3k tokens
    DevelopmentAuto-check passed

More from kenryu42/cc-safety-net

  • Release Notes

    kenryu42/cc-safety-net

    Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.

    1.6k GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • Verify Cc Safety Net

    kenryu42/cc-safety-net

    Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

    1.6k GitHub stars~2k tokensUpdated yesterday
    Auto-check passed
  • Ccsn Find Simplifications

    kenryu42/cc-safety-net

    A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…

    1.6k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed
  • Ccsn No Comments

    kenryu42/cc-safety-net

    Use in the cc-safety-net repo when bun run lint:comments or bun run check reports a comment, a stale comment-allowlist entry, or a file it cannot parse, and before writing a code comment there.

    1.6k GitHub stars~907 tokensUpdated yesterday
    Auto-check passed

Categories

Questions about Cc Safety Net

What does Cc Safety Net do?

Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection. Cc Safety Net is an agent skill from kenryu42/cc-safety-net. Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.

When should I use Cc Safety Net?

Cc Safety Net fits situations like: development work in your project.

How do I install Cc Safety Net in Claude Code?

Run `npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a claude-code`. Or copy the skill folder (skills/cc-safety-net in kenryu42/cc-safety-net) into .claude/skills/cc-safety-net in your project. Claude Code loads it when a task matches its description.

How do I install Cc Safety Net in Codex?

Run `npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a codex`. Or copy the skill folder (skills/cc-safety-net in kenryu42/cc-safety-net) into .agents/skills/cc-safety-net in your project. Codex loads it when a task matches its description.

Can I use Cc Safety Net in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kenryu42/cc-safety-net --skill cc-safety-net -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cc-safety-net, .gemini/skills/cc-safety-net, .github/skills/cc-safety-net and .opencode/skills/cc-safety-net in your project.

What does Cc Safety Net need to run?

Going by SKILL.md and its folder, Cc Safety Net needs the command-line tools its instructions call (npx, git and npm). Our summary lists: Node.js.

Does Cc Safety Net access the network?

SKILL.md contains no URLs. Its commands use npx, git and npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cc Safety Net safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cc Safety Net use?

Cc Safety Net is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cc Safety Net use?

About 4.4k tokens (SKILL.md is roughly 18k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cc Safety Net?

Skills that share tags, products or a category with Cc Safety Net: Vercel Composition Patterns (supabase/supabase, 111k stars), Finishing a Development Branch (obra/superpowers, 296k stars), Typescript Advanced Types (rolling-scopes/rsschool-app, 10k stars) and PR Babysitter (openinterpreter/openinterpreter, 69k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cc Safety Net?

kenryu42 (a GitHub user) maintains it in kenryu42/cc-safety-net, which has 1,582 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 8, 2026.

Source: kenryu42/cc-safety-net on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.