Skip to content
KitploitKITPLOIT
उपकरणब्लॉग
Log in
जमा करें
उपकरणब्लॉग
जमा करें

हैकिंग, पेनटेस्ट और साइबर सुरक्षा उपकरण आपके सुरक्षा शस्त्रागार के लिए!

Kitploit हैकिंग, साइबर सुरक्षा और पेंटेस्टिंग टूल्स की एक निर्देशिका है। कमजोरियों को खोजने, सिस्टम का विश्लेषण करने, परीक्षण को स्वचालित करने और अपनी सुरक्षा को मजबूत करने के लिए नवीनतम प्रोजेक्ट अपडेट खोजें।

फ़ीडसंपर्कगोपनीयता© 2026 Kitploit

टूल निर्देशिका

श्रेणियाँ

सभी श्रेणियाँ देखें
Loading categories
Boucle-framework — Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it. | Kitploit
उपकरण/GitHubGitHub/bande-a-bonnot/boucle-framework
Defensive ToolsPrivilege EscalationConfiguration AuditingData ExfiltrationDevSecOpsAI Security
GitHubbande-a-bonnot/boucle-framework

Boucle-framework

Autonomous agent framework with structured memory, safety hooks, and loop management. Built by the agent that runs on it.

रिपॉजिटरी देखें
120101205 दिन पहलेKitploit द्वारा समीक्षित

सबसे लोकप्रिय

सभी देखें →

हमारे समुदाय द्वारा सबसे अधिक उपयोग किए जाने वाले उपकरण खोजें।

सभी उपकरण खोजें

हमारे उपकरणों का संग्रह ब्राउज़ करें

सभी उपकरण देखें →
साझा करें
वेबसाइट
अनुरोधित भाषा में सामग्री उपलब्ध नहीं है। अंग्रेज़ी संस्करण दिखाया जा रहा है।

Boucle

Tests License: MIT

Claude Code hooks that actually enforce your rules. 7 standalone hooks, plus enforce-hooks for CLAUDE.md policy, audit tooling, 1,900+ tests, and a searchable Claude Code gaps corpus with severity ratings and workarounds.

Quick links: Check your setup · Install hooks · Known limitations · JSON export · Quickstart · Triage · Update checklist · Safe support evidence · Support examples · Read-only audits · Individual hooks · Platform support · Recommended Claude Code version · Troubleshooting · Boucle Framework (optional, for autonomous agents)

Claude Code Hooks

Claude Code's CLAUDE.md rules are read but not enforced — they work at session start and degrade as context grows. Its permission system has known gaps — wildcards don't match compound commands, deny rules don't check pipe segments and can be bypassed with multi-line comments. These hooks enforce boundaries that text rules and permissions can't.

What happens when a hook blocks a dangerous command:

Claude tries:  rm -rf ~/projects
bash-guard:    bash-guard: rm -rf targeting a critical system path. This would cause irreversible data loss.
Claude sees:   ⚠ Hook blocked this action. Suggesting safer alternative...

No prompts, no "are you sure" dialogs. The command never runs.

Check your current setup:

curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/safety-check/check.sh | bash

Run this from the same project root where you start Claude Code. Project hooks are resolved from the current directory, so a subdirectory launch can miss .claude/settings.json at the repo root. If you are already somewhere inside a git checkout:

cd "$(git rev-parse --show-toplevel)"
curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/safety-check/check.sh | bash

Scores your Claude Code safety configuration from A to F and shows one-liner fixes for each gap. Add --verify to send test payloads to each hook and confirm they actually block:

curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/safety-check/check.sh | bash -s -- --verify

For CI or a scripted workstation check, fail when verification finds a FAIL-OPEN hook, broken hook files, skipped PreToolUse checks, no hooks, or no payload checks:

curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/safety-check/check.sh | bash -s -- --verify --strict

Use the scripted checks guide for GitHub Actions, developer workstation checks, exit codes, and the limits of what CI can prove.

Checks hook installation, hook health (missing/non-executable scripts), live verification (sends rm -rf / to bash-guard, git push --force to git-safe, etc. and confirms they block), enforce-hooks and CLAUDE.md @enforced rules, environment issues (IS_DEMO, JSONC settings, jq/python3 dependencies, Windows hook reliability), and known CLI version regressions. Scans both user-level (~/.claude/settings.json) and project-level (.claude/settings.json) settings, with a hook inventory that shows custom/third-party hooks alongside framework hooks. The summary counts 8 framework hook slots because it includes the enforce-hooks policy hook; install.sh all installs the 7 standalone hooks listed below. Also warns when deny rules are configured without bash-guard, since deny patterns can be bypassed by compound commands and multi-line scripts. No hook installation required for the audit. Covered by hundreds of tests.

For a 10-minute path from audit to verified hooks, see the safety-check quickstart. If you need to ask for help, use the safe support evidence guide to share the summary block without exposing private settings or secrets. To print only that bounded public block, run:

curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/safety-check/check.sh | bash -s -- --verify --summary-only

For examples of safe public reports and unsafe snippets to avoid, see safe support examples.

For upstream Claude Code hook and permission gaps, use the searchable limitations page, the machine-readable JSON export, or the Atom feed.

macOS / Linux requirements: bash, python3, and jq. The installer uses python3 to manage Claude Code settings.json, safety-check uses python3 for its audit, and most standalone shell hooks use jq to parse Claude Code hook payloads.

Start with the essentials (bash-guard + git-safe + file-guard):

curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/install.sh | bash -s -- recommended

These three hooks form the safety net every Claude Code user should have: block dangerous commands, prevent destructive git operations, and protect sensitive files. After installing, run the safety check above with --verify to confirm each hook blocks what it should.

If the install succeeds but hooks do not block anything:

  • Run install.sh check --verify --strict first on macOS/Linux (install.ps1 verify on native Windows). A clean install is not proof the hooks are firing.
  • Run install.sh doctor next (install.ps1 doctor on Windows). It catches missing files, bad permissions, JSONC in settings.json, and other silent fail-open states.
  • On Windows, use PowerShell 7 (pwsh), not Windows PowerShell 5.
  • If you write custom deny hooks, prefer stderr + exit 2 for hard blocks. JSON permissionDecision: "deny" is still inconsistent across Claude Code surfaces.

Install all hooks at once:

curl -fsSL https://raw.githubusercontent.com/Bande-a-Bonnot/Boucle-framework/main/tools/install.sh | bash -s -- all
टूल डाउनलोड करें