A security system that allows Claude to safely run custom Skills while preventing dangerous commands in Cursor IDE.
- 🛡️ Enable Claude Skills - Let Claude run your custom scripts safely
- 🚫 Block dangerous commands - Prevent accidental system damage
- ✅ Whitelist approach - Only approved commands can execute
- 🔒 Skills protection - Run automation scripts without security risks
# Clone the repository
git clone https://github.com/bookmd/claude-skills-security-hook.git
# Create directories
mkdir -p .claude/hooks .cursor
# Copy files
cp claude-skills-security-hook/cursor-settings.json .cursor/settings.json
cp -r claude-skills-security-hook/hooks/* .claude/hooks/
# Install dependencies
cd .claude/hooks
npm installClose and reopen Cursor completely.
cd .claude/hooks
echo '{"tool_name": "Shell", "tool_input": {"command": "ls"}}' | node index.jsShould display: ✅ ALLOWED: Safe command
- Safe system commands:
ls,pwd,echo,git - Package management:
npm,node - File reading:
cat package.json - Custom skills from
scripts/directory
- Sensitive files:
.env,password,secret,key,token - Dangerous operations:
rm -rf,sudo,chmod 777,del,format - Everything else not explicitly allowed
your-project/
├── .cursor/
│ └── settings.json ← Cursor configuration
├── .claude/
│ └── hooks/
│ ├── index.js ← Security hook
│ ├── package.json ← Dependencies
│ └── node_modules/ ← Installed packages
└── scripts/ ← Your custom skills (optional)
├── backup.js
├── compress.js
└── analyze.js
Create scripts in a scripts/ directory:
// scripts/backup.js
console.log('🗂️ Starting backup...');
// Your backup logic here
console.log('✅ Backup completed!');Then ask Claude: "Run the backup script"
Claude will safely execute: node scripts/backup.js
The hook can be customized by editing .claude/hooks/index.js:
// Add more safe commands
const safeCommands = ['ls', 'pwd', 'echo', 'git', 'your-command'];
// Add more dangerous patterns to block
const dangerousCommands = ['rm -rf', 'sudo', 'your-dangerous-pattern'];- Check files are in correct locations
- Ensure Node.js is installed
- Restart Cursor completely
- Check terminal for error messages
- Verify command is in the
safeCommandsarray - Check for typos in command patterns
- Review hook logs in terminal
- Node.js ≥ 14.0.0
- Cursor IDE with Claude integration
- npm for dependency management
- Fork the repository
- Create a feature branch
- Make your changes
- Test thoroughly
- Submit a pull request
MIT License - see LICENSE file for details.
- Inspired by Claude Code Hooks documentation
- Built for the Claude/Cursor developer community
🎉 Ready to use Claude Skills securely!