Back to Hooks

Subagent Read Only Guard

Hooks security

Enforces read-only subagents. A PreToolUse hook denies Edit, Write, MultiEdit, NotebookEdit and PowerShell, and any Bash or Monitor command that is not read-only, when the call comes from a subagent (detected by the agent_id field Claude Code adds only inside subagents; tested on Claude Code 2.1.296). Shell commands pass only when every command is a bare program from a short read-only allowlist (ls, cat, grep, rg, find, jq, sort, sed -n 'N,Mp', cd, git log/diff/status/show/blame/branch/tag and similar) without the options that make it write or run other programs, including abbreviated long options. Redirection to files, command substitution, shell expansion ($VAR, {a,b}), subshells, env-var prefixes, git -c and anything the guard cannot classify are denied, including its own errors. The main conversation is never affected. Not covered: MCP tools, and git diff/blame running diff or textconv drivers already configured in the repo. Reading secrets (.env, printenv) is still allowed, so pair it with env-file-protection. Pairs with the hooks/subagents-explore-only setting, which tells subagents up front that they are exploration-only.

Install Command
npx claude-code-templates@latest --hook security/subagent-read-only-guard
View on GitHub
claude-code — subagent-read-only-guard

Content

JSON
{
"description": "Enforces read-only subagents. A PreToolUse hook denies Edit, Write, MultiEdit, N..."
"supportingFiles": [
{3 keys}
]
"hooks": {
"PreToolUse": [1 item]
}
}

Stack Builder

0 components

Your stack is empty

Browse components and click the + button to add them to your stack for easy installation.