anthropics / anthropics/claude-agent-sdk-python

Example: use HOL Guard from PreToolUse for Bash command safety

未關閉
#1,235 0 則留言 0 個 reaction 已指派 0 人 在 GitHub 檢視
documentation enhancement
主要語言
Python
星號
8.1k
分支
1.3k
PR 合併指標
PR 指標待擷取

描述

## Request

Would you be open to a maintained Claude Agent SDK example showing how to invoke HOL Guard from the existing `PreToolUse` hook for Bash command safety?

The current hooks example already demonstrates that `PreToolUse` can return `permissionDecision: "deny"` before a tool executes. A focused HOL Guard example could replace the local pattern check with a real external command-safety engine while keeping the SDK API unchanged.

## Proposed landing surface

Either a small dedicated example under `examples/` or a focused addition next to the existing hooks example/README section.

The example would:

- install the actual runtime with `pipx install hol-guard`;
- register a `PreToolUse` `HookMatcher` for `Bash`;
- extract the command from the tool input and invoke `hol-guard command test --json` before execution;
- allow an explicitly safe result exactly once;
- return `permissionDecision: "deny"` for unsafe/review-required results and fail closed on unavailable, timeout, malformed, or error results so the Bash action does not execute;
- include a small test/example assertion that blocked/error paths result in zero underlying Bash executions.

`hol-guard command test` is deliberately side-effect free: it classifies the command but does not execute it, create an approval, evaluate the final Guard policy, or record a receipt. So this example would be scoped as command-safety classification at the SDK's existing pre-tool boundary, not as a claim that Claude Agent SDK is already a full HOL Guard harness integration or that Guard Cloud approvals are wired in.

This would put HOL Guard itself in an official SDK example and give users a concrete security integration path without adding a generic guardrail API.

If this placement fits the project, I can follow up with the smallest example/docs PR and tests.

貢獻指南

這個儲存庫沒有索引到貢獻指南

評估

這個 Issue 還沒有評估資料。

把新 issue 寄到你的電子郵件信箱

精選適合新手參與的 GitHub issue 摘要。