tarotene

Bleep — AI skill for Claude Code

AI community

Stops AI coding agents (Claude Code, Codex, Copilot) from leaking private/company repository names onto public GitHub surfaces — a PreToolUse hook guardrail for git push, PR/Issue creation, and MCP to.

How to install Bleep

This entry records only its repository, not the path inside it, so there is no exact command to give. Open tarotene/bleep and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Bleep does

Stops AI coding agents (Claude Code, Codex, Copilot) from leaking private/company repository names onto public GitHub surfaces — a PreToolUse hook guardrail for git push, PR/Issue creation, and MCP tool calls.

Alternatives in AI

  • Empryo — Empryo issue tracker + SoulForge (v2) 1.1k ★
  • Update Branch Name — by giselles-ai - Updates branch names with proper prefixes and formats, enforcing naming conventions, supporti 502 ★
  • AI Surface — Find and govern AI attack surfaces in application code, at PR time and inside your AI coding tool (MCP server 131 ★

README

bleep

A black censor bar over the word BLEEP

A deny/ask gate that prevents AI coding agents from leaking company/private repository names onto public GitHub surfaces (git push, PR/Issue creation, MCP tool calls).

Formerly `publish-guard` — see [docs/adr/0001-name-bleep.md](docs/adr/0001-name-bleep.md) for why it was renamed.

Background

Born as a Claude Code PreToolUse hook (originally `config/claude/hooks/public-publish-guard.sh` in [tarotene/dotfiles](https://github.com/tarotene/dotfiles), from this repository's time as `publish-guard`), this repository extracted the decision engine into an agent-agnostic CLI (`bleep`, Bash) and a small Rust binary (`bleep-hook`) that translates each host's PreToolUse payload into calls against that CLI. A thin Bash shim (`hooks/bleep.sh`) is what each host actually registers — it locates `bleep-hook` and execs into it, falling back to an `ask` verdict if the binary isn't installed (see [Install](#install)).

Install

**Upgrading from `publish-guard`**: this tool was renamed from `publish-guard`/`publish-guard-hook` to `bleep`/`bleep-hook` (see [docs/adr/0001-name-bleep.md](docs/adr/0001-name-bleep.md)). There is no compatibility shim — move your config and state directories by hand, once:

$ mv ~/.config/publish-guard ~/.config/bleep
$ mv ~/.local/state/publish-guard ~/.local/state/bleep   # if it exists

Then reinstall the plugin/hooks under the new name (see below) and remove the old `publish-guard@publish-guard` plugin install.

If you skip the move, `bleep` does not silently run without your org list. While `orgs.txt` is missing and the old `~/.config/publish-guard/` directory still exists, every publish check returns **ask** and says the migration is incomplete.

This repository never commits denylist data (org names, repo names). You place your own under `$XDG_CONFIG_HOME/bleep/` (defaults to `~/.config/bleep/`). **The only thing you realistically have to