Agent skill

Verify Cc Safety Net

by kenryu42 in kenryu42/cc-safety-net

Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

MITAuto-check passedTesting & QA

Install Verify Cc Safety Net

skills CLI
$ npx skills add kenryu42/cc-safety-net --skill verify-cc-safety-net -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install kenryu42/cc-safety-net verify-cc-safety-net --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/kenryu42/cc-safety-net.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/verify-cc-safety-net .claude/skills/verify-cc-safety-net && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-cc-safety-net
GitHub stars
1.6k
Token cost
~2k tokens
SKILL.md length
843 words
Files
8
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

  • A change needs proof in the running app
  • SKILL.md covers Launch, Doctor, Drive and Evidence, plus 2 more sections
  • Calls git and bun
  • Not just the test suite

What it does

Verify Cc Safety Net is an agent skill from kenryu42/cc-safety-net. Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence. Use when a change needs proof in the running app, not just the test suite.

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 8 other files (for example `features/README.md`, `features/audit-logs.md` and `features/diagnostics.md`).

It sits in Testing & QA, covering Test generation. The repository describes itself as: A pre-execution guard for AI coding agents. It blocks destructive Git and file system commands, plus common attempts to access sensitive files, before a tool call runs. Supports… The licence is MIT.

When your agent uses it

  • A change needs proof in the running app
  • Not just the test suite

Example prompts

  • “/verify-cc-safety-net”

What it can do on your machine

Read from SKILL.md and the folder at commit 5ec6058. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git
    • bun

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Verify Cc Safety Net loads about 2k tokens when it runs. Until then it costs about 67 tokens; SKILL.md has 843 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~67
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from kenryu42/cc-safety-net at commit 5ec6058, republished under its MIT licence (© kenryu42). 843 words, ~1,985 tokens.

Download SKILL.mdSave it as .claude/skills/verify-cc-safety-net/SKILL.md (or your agent's skills folder). This skill also uses 7 other files; get the full folder from GitHub.
name
verify-cc-safety-net
description
Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence. Use when a change needs proof in the running app, not just the test suite.

Verify cc-safety-net

cc-safety-net is a CLI (cc-safety-net / ccsn) that coding-agent CLIs invoke as a pre-tool-use hook: JSON describing a tool call arrives on stdin, an allow/deny decision leaves on stdout, and every decision is appended to an audit log under the active home. Users also run diagnostic commands (status, doctor, explain, logs) and a local web GUI (gui).

Safety invariants for every run:

  • Command strings under test (git reset --hard, rm -rf /, …) are analyzer INPUT. They go into a JSON payload or an explain argument. Never execute one in a shell.
  • Never run the CLI against the real home. Every invocation goes through ./ccsn-isolated (see Helpers), which redirects HOME, CC_SAFETY_NET_HOME, and CC_SAFETY_NET_AUDIT_HOME into a disposable directory. A bare bun run src/entries/bin.ts writes to the developer's real ~/.cc-safety-net/logs.
  • Never drive install, update, or uninstall (CLI or GUI Integrations tab) in a verification run: install detection and npx-cache clearing reach real machine state beyond $HOME.

Launch

No build step: the CLI runs from source with bun. Set up one isolated run:

bash
REPO=$(git rev-parse --show-toplevel)
RUN_ID=verify-$(date +%Y%m%d-%H%M%S)
export CCSN_VERIFY_HOME=$REPO/artifacts/verify-homes/$RUN_ID   # disposable fake $HOME
EVIDENCE=$REPO/artifacts/verify/$RUN_ID                        # proof artifacts (gitignored)
WS=$CCSN_VERIFY_HOME/workspace                                 # cwd the "agent" works in
mkdir -p "$CCSN_VERIFY_HOME" "$EVIDENCE" "$WS"

One-shot commands (hook, explain, status, logs, doctor) need no server — each drive is one ./ccsn-isolated … invocation from $REPO/.agents/skills/verify-cc-safety-net/.

The only long-lived instance is the GUI:

bash
cd "$WS" && "$REPO/.agents/skills/verify-cc-safety-net/ccsn-isolated" gui --no-open > "$EVIDENCE/gui.log" 2>&1 &
GUI_PID=$!

Ready when gui.log contains CC Safety Net policy GUI: http://127.0.0.1:<port>/?token=<token> (poll for it; it appears in under ~2s). The server picks a free port itself, so instances never collide. Teardown: kill $GUI_PID — kill the PID you started, never by process name.

Isolation: two runs side by side are fine as long as each has its own CCSN_VERIFY_HOME.

Doctor

Before driving, prove the instance is worth driving — from the skill directory:

bash
./ccsn-isolated --version        # must print "dev" — source checkout, not an installed copy
./ccsn-isolated status | head -6 # must print "CC Safety Net — ready" with Level standard
./ccsn-isolated doctor --json --skip-update-check > "$EVIDENCE/doctor.json"

If --version prints a semver, you are running a packaged copy, not this checkout — stop. Healthy in doctor.json means engineSelfTest.failed is 0 and configState.state is "ready". Do not gate on doctor's exit code: under a fresh isolated home it exits 1 solely because no integration is configured (integration.none-configured in findings), which is inherent to the isolation, not a defect. Any other error-severity finding means the checkout is broken — stop and report rather than driving features. After the first hook drive, additionally confirm isolation held: entries exist under $CCSN_VERIFY_HOME/.cc-safety-net/logs/ and ls ~/.cc-safety-net/logs/*/*/*ccsn-verify* 2>/dev/null finds nothing (every probe session id starts with ccsn-verify-, so a leak is identifiable by filename in the real log tree).

Drive

Three drive styles; the per-feature recipes live in features/.

Hook (the production path). Write the payload the coding CLI would send, pipe it in, capture stdout and the exit code:

bash
printf '%s' '{"hook_event_name":"PreToolUse","tool_name":"Bash","session_id":"ccsn-verify-'"$RUN_ID"'-reset","cwd":"'"$WS"'","tool_input":{"command":"git reset --hard"}}' \
  | ./ccsn-isolated hook --claude-code

Deny prints {"hookSpecificOutput":{…,"permissionDecision":"deny","permissionDecisionReason":"…Rule: git.reset-hard…"}}; allow prints nothing. Both exit 0 — the decision is the stdout JSON, never the exit code. hook also takes --cursor, --gemini-cli, --copilot-cli, --kimi-code, --grok-build, --hermes-agent, --antigravity-cli (payload shapes differ; see the integration under src/hosts/<id>/hook.ts).

Plain CLI. ./ccsn-isolated explain --json "<command>", status, doctor --json --skip-update-check, logs --json [--all]. logs is scoped to the current working directory — run it from the same $WS the hook payload's cwd named (ccsn-isolated runs relative commands from your cwd, so cd "$WS" first).

GUI. Drive the API with curl (GET /api/policy?token=$TOKEN; POSTs need the x-cc-safety-net-token: $TOKEN header too), or the page with a browser (playwright-cli or claude-in-chrome) at the printed URL. Views are hash-routed: #overview, #activity, #policy, #rules, #integrations, #settings; stable handles are element ids (#tester-input, #tester-run, #tester-result, #save, #activity-feed) and a[data-nav="<view>"].

Show full SKILL.md (305 more words)Show less

Evidence

Everything lands in $EVIDENCE (artifacts/verify/<run-id>/ — gitignored, survives cleanup).

  • Exercise the real user path: payloads through hook --<integration> exactly as the host CLI sends them, not checkCommand library calls or internal functions.
  • Capture the action and the resulting state: for a hook decision, save the payload, the stdout decision, and the exit code, then pair it with the side effect — the audit entry in $CCSN_VERIFY_HOME/.cc-safety-net/logs/<cwd-slug>/<YYYY-MM>/<date>-<session_id>.jsonl (or its absence: plain allows under default policy are also recorded, so assert content, not existence).
  • The hook answers; the host enforces. A hook proof covers the decision and the audit trail — it cannot prove a file survived, and staging a sentinel proves nothing (this harness never executes the command). Survival proofs live in tests/e2e, which stage a real host runner.
  • An allow proof is a negative: empty stdout AND exit 0 AND an allow audit entry for the session id. Capture all three — empty stdout alone also looks like a crash swallowed by a pipe.
  • GUI proofs: screenshot with the view name visible, plus the API response or on-disk policy file ($CCSN_VERIFY_HOME/.cc-safety-net/policy.json) showing the mutation stuck.
  • Record with every artifact: feature ID, the exact command, and the entry point used.

Cleanup

bash
kill $GUI_PID 2>/dev/null          # only if this run started a GUI
/bin/rm -rf "$CCSN_VERIFY_HOME"    # /bin/rm — plain rm may be aliased to trash on this machine

Cleanup removes the isolated home and any GUI process this run started — nothing else. Never delete $EVIDENCE, never touch the real ~/.cc-safety-net, and never kill by process name (other bun processes are not yours). Run this after failed attempts too.

Helpers

ccsn-isolated (executable, in this directory) runs the CLI from source under the isolated home:

bash
CCSN_VERIFY_HOME=/abs/disposable/dir ./ccsn-isolated <command> [args...]

It requires CCSN_VERIFY_HOME to be absolute, redirects HOME/USERPROFILE/ CC_SAFETY_NET_HOME/CC_SAFETY_NET_AUDIT_HOME into it, blanks the CC_SAFETY_NET_LEVEL/ STRICT/PARANOID*/WORKTREE overrides a developer shell might export, and execs bun run <repo>/src/entries/bin.ts "$@" with stdin/stdout/exit code passing through, so hook payloads pipe straight in. It runs the CLI from your current cwd — cd into $WS for cwd-scoped commands like logs.

© kenryu42, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 7 other files in .agents/skills/verify-cc-safety-net of kenryu42/cc-safety-net.

  • SKILL.md
  • ccsn-isolated
  • features/README.md
  • features/audit-logs.md
  • features/diagnostics.md
  • features/explain-trace.md
  • features/hook-protection.md
  • features/policy-gui.md

Open the folder on GitHubat commit 5ec6058

Compare with similar skills

Verify Cc Safety Net next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Verify Cc Safety Net compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Verify Cc Safety Net this skillkenryu42/cc-safety-net1.6k—~2kAutomated safety check: PassMIT
Emcaklofas/kicad-happy1.4k1 repos~2.8kAutomated safety check: PassMIT
Swig Testswig/swig6.3k—~2.3kAutomated safety check: PassCustom licence
Generate Test Cases342164796/generate-test-cases1191 repos~2.9kAutomated safety check: PassNone
Wioworkersio/skills200—~5.8kAutomated safety check: PassMIT
File Servermicrosoft/WindowsProtocolTestSuites567—~4.1kAutomated safety check: PassMIT

Similar skills

  • Emc

    aklofas/kicad-happy

    EMC pre-compliance risk analysis for KiCad PCB designs — 18 check categories, 44 rule IDs covering ground planes, decoupling, I/O filtering, switching harmonics, clock routing, differential pair…

    1.4k GitHub starsUsed in 1 repo~2.8k tokens
    Testing & QAAuto-check passed
  • Swig Test

    swig/swig

    Run SWIG test suite for specific languages. An agent skill from swig/swig.

    6.3k GitHub stars~2.3k tokensUpdated 2 days ago
    Testing & QAAuto-check passed
  • Generate Test Cases

    342164796/generate-test-cases

    自主学习型测试文档生成器。从需求文档(Markdown)生成测试用例 XMind 文件,支持持久化记忆和持续学习。当用户提到"生成测试用例"、"根据需求生成测试"时触发。

    119 GitHub starsUsed in 1 repo~2.9k tokens
    Testing & QAAuto-check passed
  • Wio

    workersio/skills

    Testing workflow skill for finding high-value test candidates, writing focused tests, generating realistic workloads, reviewing test value, and diagnosing test-suite health.

    200 GitHub stars~5.8k tokensUpdated 2 mo ago
    Testing & QAAuto-check passed
  • File Server

    microsoft/WindowsProtocolTestSuites

    Official

    ALWAYS LOAD THIS SKILL when working with FileServer, SMB, SMB2, SMB3, CIFS, file sharing, MS-SMB2, MS-FSCC, MS-FSA, MS-DFSC, MS-FSRVP, MS-RSVD, MS-SQOS, or any file server protocol test…

    567 GitHub stars~4.1k tokensUpdated 24 days ago
    Testing & QAAuto-check passed
  • Add E2E Test Suite

    crowdin/crowdin-cli

    Adds a new end-to-end (e2e) test suite for the Crowdin CLI under tests/e2e/suites/, exercising real CLI commands against a freshly-created Crowdin project.

    320 GitHub stars~2.4k tokensUpdated yesterday
    Testing & QAAuto-check passed

More from kenryu42/cc-safety-net

  • Release Notes

    kenryu42/cc-safety-net

    Generate and publish concise, evidence-based notes in the body of the latest existing GitHub Release.

    1.6k GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • Cc Safety Net

    kenryu42/cc-safety-net

    Operate CC Safety Net: explain why a command was blocked, triage false positives, configure custom rulebooks, manage agent CLI integrations, and diagnose protection.

    1.6k GitHub stars~4.4k tokensUpdated today
    Auto-check: notes
  • Ccsn Find Simplifications

    kenryu42/cc-safety-net

    A skill your agent uses when working in the cc-safety-net repo to find non-obvious simplification candidates: dead, duplicated, speculative, over-built, or contract-exceeding surfaces in the shell…

    1.6k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Ccsn No Comments

    kenryu42/cc-safety-net

    Use in the cc-safety-net repo when bun run lint:comments or bun run check reports a comment, a stale comment-allowlist entry, or a file it cannot parse, and before writing a code comment there.

    1.6k GitHub stars~907 tokensUpdated today
    Auto-check passed

Categories

Questions about Verify Cc Safety Net

What does Verify Cc Safety Net do?

Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence. Verify Cc Safety Net is an agent skill from kenryu42/cc-safety-net. Launch and drive the real cc-safety-net CLI — the hook decision path, explain, status/doctor, logs, and the local policy GUI — against an isolated home, capturing evidence.

When should I use Verify Cc Safety Net?

Verify Cc Safety Net fits situations like: A change needs proof in the running app; not just the test suite.

How do I install Verify Cc Safety Net in Claude Code?

Run `npx skills add kenryu42/cc-safety-net --skill verify-cc-safety-net -a claude-code`. Or copy the skill folder (.agents/skills/verify-cc-safety-net in kenryu42/cc-safety-net) into .claude/skills/verify-cc-safety-net in your project. Claude Code loads it when a task matches its description.

How do I install Verify Cc Safety Net in Codex?

Run `npx skills add kenryu42/cc-safety-net --skill verify-cc-safety-net -a codex`. Or copy the skill folder (.agents/skills/verify-cc-safety-net in kenryu42/cc-safety-net) into .agents/skills/verify-cc-safety-net in your project. Codex loads it when a task matches its description.

Can I use Verify Cc Safety Net in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add kenryu42/cc-safety-net --skill verify-cc-safety-net -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-cc-safety-net, .gemini/skills/verify-cc-safety-net, .github/skills/verify-cc-safety-net and .opencode/skills/verify-cc-safety-net in your project.

What does Verify Cc Safety Net need to run?

Going by SKILL.md and its folder, Verify Cc Safety Net needs the command-line tools its instructions call (git and bun).

Does Verify Cc Safety Net access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Verify Cc Safety Net safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Verify Cc Safety Net use?

Verify Cc Safety Net is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Verify Cc Safety Net use?

About 2k tokens (SKILL.md is roughly 7.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Verify Cc Safety Net?

Skills that share tags, products or a category with Verify Cc Safety Net: Emc (aklofas/kicad-happy, 1.4k stars), Swig Test (swig/swig, 6.3k stars), Generate Test Cases (342164796/generate-test-cases, 119 stars) and Wio (workersio/skills, 200 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Verify Cc Safety Net?

kenryu42 (a GitHub user) maintains it in kenryu42/cc-safety-net, which has 1,583 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on October 9, 2026.

Source: kenryu42/cc-safety-net on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.