Subagent Read Only Guard
Enforces read-only subagents. A PreToolUse hook denies Edit, Write, MultiEdit, NotebookEdit and PowerShell, and any Bash or Monitor command that is not read-only, when the call comes from a subagent (detected by the agent_id field Claude Code adds only inside subagents; tested on Claude Code 2.1.296). Shell commands pass only when every command is a bare program from a short read-only allowlist (ls, cat, grep, rg, find, jq, sort, sed -n 'N,Mp', cd, git log/diff/status/show/blame/branch/tag and similar) without the options that make it write or run other programs, including abbreviated long options. Redirection to files, command substitution, shell expansion ($VAR, {a,b}), subshells, env-var prefixes, git -c and anything the guard cannot classify are denied, including its own errors. The main conversation is never affected. Not covered: MCP tools, and git diff/blame running diff or textconv drivers already configured in the repo. Reading secrets (.env, printenv) is still allowed, so pair it with env-file-protection. Pairs with the hooks/subagents-explore-only setting, which tells subagents up front that they are exploration-only.
npx claude-code-templates@latest --hook security/subagent-read-only-guard