Gateguard

作者 affaan-mef648e01899b無授權條款275K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫3 天前更新

API、エージェント、およびLLMエンドポイントのアクセス制御と認可パターン。

AI 產生的概覽

一個 PreToolUse 掛鉤,在程式碼修改前攔截首次編輯並強制蒐集事實。

功能
GateGuard 是一個 PreToolUse 掛鉤,會拒絕首次 Edit、Write 或 Bash 嘗試,告知模型需要蒐集哪些具體事實,並在事實呈現後允許重試。它為編輯、建立新檔案、破壞性 Bash 指令和例行 Bash 指令分別定義了閘門,並提供對比啟用與未啟用閘門的 A/B 測試結果。它僅包含說明,可透過專案設定檔或環境變數進行設定。
適用情境
適用於編輯會影響多個模組的程式碼庫、包含具有特定結構或日期格式之資料檔案的專案,以及 AI 生成程式碼必須符合既有模式的團隊。它面向模型傾向於猜測而非調查的工作流程。
執行需求
不包含指令碼,僅為說明。方案 A 引用 ECC 掛鉤檔案和 hooks.json;方案 B 需要安裝 gateguard-ai Python 套件並執行 gateguard init 以產生 .gateguard.yml 設定檔。

GateGuard — Fact-Forcing Pre-Action Gate

A PreToolUse hook that forces Claude to investigate before editing. Instead of self-evaluation ("are you sure?"), it demands concrete facts. The act of investigation creates awareness that self-evaluation never did.

When to Activate

  • Working on any codebase where file edits affect multiple modules
  • Projects with data files that have specific schemas or date formats
  • Teams where AI-generated code must match existing patterns
  • Any workflow where Claude tends to guess instead of investigating

Core Concept

LLM self-evaluation doesn't work. Ask "did you violate any policies?" and the answer is always "no." This is verified experimentally.

But asking "list every file that imports this module" forces the LLM to run Grep and Read. The investigation itself creates context that changes the output.

Three-stage gate:

1. DENY  — block the first Edit/Write/Bash attempt2. FORCE — tell the model exactly which facts to gather3. ALLOW — permit retry after facts are presented

No competitor does all three. Most stop at deny.

Evidence

Two independent A/B tests, identical agents, same task:

TaskGatedUngatedGap
Analytics module8.0/106.5/10+1.5
Webhook validator10.0/107.0/10+3.0
Average9.06.75+2.25

Both agents produce code that runs and passes tests. The difference is design depth.

Gate Types

Edit / MultiEdit Gate (first edit per file)

MultiEdit is handled identically — each file in the batch is gated individually.

Before editing {file_path}, present these facts:
1. List ALL files that import/require this file (search the tree — Glob/Grep, or find/grep via Bash)2. List the public functions/classes affected by this change3. If this file reads/writes data files, show field names, structure,   and date format (use redacted or synthetic values, not raw production data)4. Quote the user's current instruction verbatim

Write Gate (first new file creation)

Before creating {file_path}, present these facts:
1. Name the file(s) and line(s) that will call this new file2. Confirm no existing file serves the same purpose (search the tree — Glob/Grep, or find/grep via Bash)3. If this file reads/writes data files, show field names, structure,   and date format (use redacted or synthetic values, not raw production data)4. Quote the user's current instruction verbatim

Destructive Bash Gate (every destructive command)

Triggers on: rm -rf, git reset --hard, git push --force, drop table, etc.

1. List all files/data this command will modify or delete2. Write a one-line rollback procedure3. Quote the user's current instruction verbatim

Routine Bash Gate (once per session)

1. The current user request in one sentence2. What this specific command verifies or produces

Quick Start

Option A: Use the ECC hook (zero install)

The hook at scripts/hooks/gateguard-fact-force.js is included in this plugin. Enable it via hooks.json.

If GateGuard blocks setup or repair work, start the session with ECC_GATEGUARD=off. For hook-level control, keep using ECC_DISABLED_HOOKS with the GateGuard hook ID.

Option B: Full package with config

bash
pip install gateguard-aigateguard init

This adds .gateguard.yml for per-project configuration (custom messages, ignore paths, gate toggles).

Anti-Patterns

  • Don't use self-evaluation instead. "Are you sure?" always gets "yes." This is experimentally verified.
  • Don't skip the data schema check. Both A/B test agents assumed ISO-8601 dates when real data used %Y/%m/%d %H:%M. Checking data structure (with redacted values) prevents this entire class of bugs.
  • Don't gate every single Bash command. Routine bash gates once per session. Destructive bash gates every time. This balance avoids slowdown while catching real risks.

Best Practices

  • Let the gate fire naturally. Don't try to pre-answer the gate questions — the investigation itself is what improves quality.
  • Customize gate messages for your domain. If your project has specific conventions, add them to the gate prompts.
  • Use .gateguard.yml to ignore paths like .venv/, node_modules/, .git/.

Related Skills

  • safety-guard — Runtime safety checks (complementary, not overlapping)
  • code-reviewer — Post-edit review (GateGuard is pre-edit investigation)

來源與署名

來源:affaan-m/ecc位於docs/ja-JP/skills/gateguard提交ef648e0

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架