Claude Code Haiku Guard
Description
Safe-by-default Bash permission guard for Claude Code powered by Claude Haiku — auto-approves routine commands, surfaces a dialog only on real risks
Installation
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open the source below and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
README
🛡️ claude-code-haiku-guard
⚠️ Superseded by Auto Mode
Claude Code's native [Auto Mode](https://code.claude.com/docs/en/permission-modes) (`"defaultMode": "auto"`) now performs the same job — model-side safety checks that auto-approve commands aligned with the user's request, surfacing only the ones that need human judgment. Codex shipped an equivalent native classifier.
If you've adopted Auto Mode, this hook is largely redundant — you'll be paying for two classifiers (Anthropic's internal one + OpenRouter Haiku) and they can disagree on edge cases. The repo stays available for users who prefer explicit rule-based gating with a custom config and audit log, but new features are no longer planned.
Anyone who uses Claude Code heavily eventually gets tired of approving harmless commands. Most people start by adding allow-list exceptions, and some end up switching on `--dangerously-skip-permissions`. The incident reports linked below are a good reminder of why that trade-off is risky.
The idea in this repo is simple: keep rules for obviously safe commands, and use a small, fast model such as Haiku for the harder cases. In practice, that means most routine commands are approved automatically, while the user only sees the commands that look dangerous or unclear.
Technically, this is a Claude Code hook that classifies the full Bash command by risk. By default, the LLM step runs through OpenRouter.
On current OpenRouter pricing this is usually a cents-per-day tool, not a dollars-per-day one. The rough math is in [SETUP.md](SETUP.md).
[Русская версия →](README.ru.md)
⚖️ What happens to a command
| Risk | Behavior |
|---|---|
none / low |
allow silently |
medium |
ask Haiku for a yes/no decision in context |
high / critical |
always show a dialog |
Real-world cases where AI agents ran `rm -rf`, `git reset --hard`, and similar commands through over-broad allow-list rules are collected in [INCIDENTS.md](INCIDENTS.md).
🔍
Related Skills
Awesome Go
A curated list of awesome Go frameworks, libraries and software
Development next.js
| The React Framework | 138360 | 1503 | 1 |
Development sharing-skills
skill for guidance.
Development root-cause-tracing
Use when errors occur deep in execution and you need to trace back to find the original trigger.
Development Template Skill
Minimal skeleton for a new skill project structure.
Development Third-party Notices
THE FOLLOWING SETS FORTH ATTRIBUTION NOTICES FOR THIRD PARTY SOFTWARE THAT MAY BE CONTAINED IN PORTIONS OF THI
Development