オプション

gateguard

affaan-m/ECC affaan-m/ECC

AIエージェントに対し、破壊的なコマンドを編集または実行する前に調査を行うよう促し、インポーター、データスキーマ、ユーザーからの指示といった具体的な事実の提示を義務付けることで、コードの品質を向上させます。

...すべて拡張します
0
更新された時間 2026年10月1日

GateGuard — 事実確認を義務付ける事前アクションゲート

編集前にクロードに調査を強制するPreToolUseフック。自己評価(「本当に大丈夫か?」)の代わりに、具体的な事実を要求する。調査という行為は、自己評価では決して得られなかった気づきを生み出す。

有効にするタイミング

  • ファイルの編集が複数のモジュールに影響を与えるコードベースでの作業時
  • 特定のスキーマや日付形式を持つデータファイルを含むプロジェクト
  • AIが生成したコードが既存のパターンに合致しなければならないチーム
  • Claudeが調査せずに推測しがちなワークフロー

中核となる概念

LLMによる自己評価は機能しません。「ポリシーに違反しましたか?」と尋ねても、答えは常に「いいえ」です。これは実験的に検証されています。

しかし、「このモジュールをインポートしているファイルをすべてリストアップしてください」と尋ねると、LLMはGrepやReadを実行せざるを得なくなります。調査そのものが文脈を生み出し、それが出力を変えるのです。

3段階のゲート:

1. DENY  — block the first Edit/Write/Bash attempt
2. FORCE — tell the model exactly which facts to gather
3. ALLOW — permit retry after facts are presented

これら3つすべてを実行できる競合他社は存在しない。大半は「違反していない」という否定で止まってしまう。

証拠

2つの独立したA/Bテスト、同一のエージェント、同一のタスク:

タスク ゲートあり ゲートなし 差
分析モジュール 8.0/10 6.5/10 +1.5
Webhook バリデータ 10.0/10 7.0/10 +3.0
平均 9.0 6.75 +2.25

どちらのエージェントも、実行可能でテストに合格するコードを生成します。違いは設計の深さです。

ゲートの種類

編集/マルチ編集ゲート(ファイルごとの最初の編集)

マルチ編集も同様に処理されます。バッチ内の各ファイルは個別にゲート処理されます。

Before editing {file_path}, present these facts:

1. List ALL files that import/require this file (use Grep)
2. List the public functions/classes affected by this change
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim

書き込みゲート(最初の新規ファイル作成時)

Before creating {file_path}, present these facts:

1. Name the file(s) and line(s) that will call this new file
2. Confirm no existing file serves the same purpose (use Glob)
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim

破壊的Bashゲート(すべての破壊的コマンド)

以下の場合にトリガーされます: rm -rf, git reset --hard, git push --force, drop tableなど

1. List all files/data this command will modify or delete
2. Write a one-line rollback procedure
3. Quote the user's current instruction verbatim

ルーチンBashゲート(セッションごとに1回)

1. The current user request in one sentence
2. What this specific command verifies or produces

クイックスタート

オプションA:ECCフックを使用(インストール不要)

このプラグインには scripts/hooks/gateguard-fact-force.js にあるフックは、このプラグインに含まれています。hooks.json を通じて有効にしてください。

GateGuardがセットアップや修復作業をブロックする場合は、セッションを ECC_GATEGUARD=offでセッションを開始してください。フックレベルでの制御を行う場合は、引き続き ECC_DISABLED_HOOKS を使用し続けてください。

長時間のセッションでは、最初の GATEGUARD_FACT_FORCE_FULL_DENIALS fact-forceによる拒否(デフォルトは3回)のみが完全な4ファクトのブロックを出力します。それ以降の 拒否は、拒否の順序番号を含む1行に凝縮されるため、 ほぼ同一のブロックがコンテキストウィンドウに蓄積して モデルの繰り返しループを増幅することがありません(#2142)。 事実の提示後に同じファイルや コマンドを再試行しても、ゲートは再トリガーされません。

オプション B: 設定を含むフルパッケージ

pip install gateguard-ai
gateguard init

これにより、 .gateguard.yml プロジェクトごとの設定(カスタムメッセージ、無視パス、ゲートの切り替え)が可能になります。

アンチパターン

  • 代わりに自己評価を使用しないでください。「本当に実行しますか?」という質問には、常に「はい」という回答が返ってきます。これは実験的に検証されています。
  • データスキーマのチェックを省略してはいけません。実際のデータが使用された際、A/Bテストの両エージェントは ISO-8601 形式の日付を想定していました %Y/%m/%d %H:%M。データ構造のチェック(値を伏せた状態で)を行うことで、この種のバグをすべて未然に防ぐことができます。
  • すべてのBashコマンドにゲート処理を行わないでください。ルーチンのBashゲートはセッションごとに1回行います。破壊的なBashゲートは毎回行います。このバランスにより、実際のリスクを捕捉しつつ、処理の遅延を回避できます。

ベストプラクティス

  • ゲートは自然に発動させるようにしましょう。ゲートの質問に先回りして答えようとしてはいけません。調査そのものが品質向上につながるのです。
  • ドメインに合わせてゲートメッセージをカスタマイズしてください。プロジェクトに固有の規約がある場合は、それらをゲートのプロンプトに追加してください。
  • .gateguard.yml を使用して、次のようなパスを無視するように設定してください .venv/, node_modules/, .git/.

関連スキル

  • safety-guard — 実行時の安全性チェック(補完的であり、重複しない)
  • code-reviewer — 編集後のレビュー(GateGuardは編集前の調査です)
GitHubで見る
---
name: gateguard
description: Forces AI agents to investigate before editing or running destructive commands, improving code quality by requiring concrete facts like importers, data schemas, and user instructions.
---

# GateGuard — Fact-Forcing Pre-Action Gate

A PreToolUse hook that forces Claude to investigate before editing. Instead of self-evaluation ("are you sure?"), it demands concrete facts. The act of investigation creates awareness that self-evaluation never did.

## When to Activate

- Working on any codebase where file edits affect multiple modules
- Projects with data files that have specific schemas or date formats
- Teams where AI-generated code must match existing patterns
- Any workflow where Claude tends to guess instead of investigating

## Core Concept

LLM self-evaluation doesn't work. Ask "did you violate any policies?" and the answer is always "no." This is verified experimentally.

But asking "list every file that imports this module" forces the LLM to run Grep and Read. The investigation itself creates context that changes the output.

**Three-stage gate:**

```
1. DENY  — block the first Edit/Write/Bash attempt
2. FORCE — tell the model exactly which facts to gather
3. ALLOW — permit retry after facts are presented
```

No competitor does all three. Most stop at deny.

## Evidence

Two independent A/B tests, identical agents, same task:

| Task | Gated | Ungated | Gap |
| --- | --- | --- | --- |
| Analytics module | 8.0/10 | 6.5/10 | +1.5 |
| Webhook validator | 10.0/10 | 7.0/10 | +3.0 |
| **Average** | **9.0** | **6.75** | **+2.25** |

Both agents produce code that runs and passes tests. The difference is design depth.

## Gate Types

### Edit / MultiEdit Gate (first edit per file)

MultiEdit is handled identically — each file in the batch is gated individually.

```
Before editing {file_path}, present these facts:

1. List ALL files that import/require this file (use Grep)
2. List the public functions/classes affected by this change
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
```

### Write Gate (first new file creation)

```
Before creating {file_path}, present these facts:

1. Name the file(s) and line(s) that will call this new file
2. Confirm no existing file serves the same purpose (use Glob)
3. If this file reads/writes data files, show field names, structure,
   and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
```

### Destructive Bash Gate (every destructive command)

Triggers on: `rm -rf`, `git reset --hard`, `git push --force`, `drop table`, etc.

```
1. List all files/data this command will modify or delete
2. Write a one-line rollback procedure
3. Quote the user's current instruction verbatim
```

### Routine Bash Gate (once per session)

```
1. The current user request in one sentence
2. What this specific command verifies or produces
```

## Quick Start

### Option A: Use the ECC hook (zero install)

The hook at `scripts/hooks/gateguard-fact-force.js` is included in this plugin. Enable it via hooks.json.

If GateGuard blocks setup or repair work, start the session with
`ECC_GATEGUARD=off`. For hook-level control, keep using
`ECC_DISABLED_HOOKS` with the GateGuard hook ID.

In long sessions, only the first `GATEGUARD_FACT_FORCE_FULL_DENIALS`
fact-force denials (default 3) emit the full four-fact block; later
denials are condensed to a single line carrying the denial ordinal, so
near-identical blocks cannot accumulate in the context window and
amplify model repetition loops (#2142). Retrying the same file or
command after presenting facts never re-triggers the gate.

### Option B: Full package with config

```bash
pip install gateguard-ai
gateguard init
```

This adds `.gateguard.yml` for per-project configuration (custom messages, ignore paths, gate toggles).

## Anti-Patterns

- **Don't use self-evaluation instead.** "Are you sure?" always gets "yes." This is experimentally verified.
- **Don't skip the data schema check.** Both A/B test agents assumed ISO-8601 dates when real data used `%Y/%m/%d %H:%M`. Checking data structure (with redacted values) prevents this entire class of bugs.
- **Don't gate every single Bash command.** Routine bash gates once per session. Destructive bash gates every time. This balance avoids slowdown while catching real risks.

## Best Practices

- Let the gate fire naturally. Don't try to pre-answer the gate questions — the investigation itself is what improves quality.
- Customize gate messages for your domain. If your project has specific conventions, add them to the gate prompts.
- Use `.gateguard.yml` to ignore paths like `.venv/`, `node_modules/`, `.git/`.

## Related Skills

- `safety-guard` — Runtime safety checks (complementary, not overlapping)
- `code-reviewer` — Post-edit review (GateGuard is pre-edit investigation)

すべてのファイル

1件のファイル

gateguardをインストール

スキルファイルをダウンロードし、.claude/skills/ ディレクトリに解凍してください。

ZIPをダウンロード

リポジトリをクローンし、スキルファイルをプロジェクトにコピーしてください。

git clone https://github.com/affaan-m/ECC/tree/main/skills/gateguard # Copy SKILL.md to your .claude/skills/ directory

コピー コピー
クイックセットアップ: スキルフォルダを .claude/skills/ にコピーしてください。 Claude が自動的にそのスキルを検出して使用します。
リポジトリ affaan-m/ECC

関連スキル

algorithmic-art
更新された時間 2026年8月27日
systematic-debugging
更新された時間 2026年9月3日
tech-debt-tracker
更新された時間 2026年8月29日
continual-learning
更新された時間 2026年9月10日
OR