gateguard
affaan-m/ECC
AI 에이전트가 편집이나 파괴적인 명령을 실행하기 전에 반드시 조사하도록 유도하여, 임포터, 데이터 스키마, 사용자 지침과 같은 구체적인 정보를 요구함으로써 코드 품질을 향상시킵니다.
...모든 것을 확장하십시오GateGuard — 사실 확인을 강제하는 사전 조치 게이트
클로드가 편집하기 전에 반드시 조사하도록 강제하는 PreToolUse 훅입니다. 자기 평가("정말 괜찮은가요?") 대신 구체적인 사실을 요구합니다. 조사라는 행위는 자기 평가로는 결코 얻을 수 없었던 인식을 심어줍니다.
활성화 시점
- 파일 편집이 여러 모듈에 영향을 미치는 코드베이스에서 작업할 때
- 특정 스키마나 날짜 형식을 가진 데이터 파일이 있는 프로젝트
- AI가 생성한 코드가 기존 패턴과 일치해야 하는 팀
- Claude가 조사하기보다 추측하는 경향이 있는 모든 워크플로우
핵심 개념
LLM 자체 평가는 효과가 없습니다. “정책을 위반했습니까?”라고 물으면 대답은 항상 “아니요”입니다. 이는 실험을 통해 검증되었습니다.
하지만 “이 모듈을 임포트하는 모든 파일을 나열해 주세요”라고 묻는다면 LLM이 Grep과 Read를 실행하도록 강제하게 됩니다. 조사 과정 자체가 맥락을 생성하여 출력을 변화시킵니다.
3단계 게이트:
1. DENY — block the first Edit/Write/Bash attempt
2. FORCE — tell the model exactly which facts to gather
3. ALLOW — permit retry after facts are presented
세 단계를 모두 수행하는 경쟁사는 없다. 대부분은 ‘부정’ 단계에서 멈춘다.
증거
두 차례의 독립적인 A/B 테스트, 동일한 에이전트, 동일한 과제:
| 과제 | 게이트 적용 | 게이트 없음 | 차이 |
|---|---|---|---|
| 분석 모듈 | 8.0/10 | 6.5/10 | +1.5 |
| 웹훅 유효성 검사기 | 10.0/10 | 7.0/10 | +3.0 |
| 평균 | 9.0 | 6.75 | +2.25 |
두 에이전트 모두 실행되고 테스트를 통과하는 코드를 생성합니다. 차이점은 설계의 깊이입니다.
게이트 유형
편집/다중 편집 게이트(파일당 첫 번째 편집)
다중 편집도 동일하게 처리됩니다. 즉, 배치 내의 각 파일에 대해 개별적으로 게이트 처리가 이루어집니다.
Before editing {file_path}, present these facts:
1. List ALL files that import/require this file (use Grep)
2. List the public functions/classes affected by this change
3. If this file reads/writes data files, show field names, structure,
and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
쓰기 게이트 (첫 번째 새 파일 생성 시)
Before creating {file_path}, present these facts:
1. Name the file(s) and line(s) that will call this new file
2. Confirm no existing file serves the same purpose (use Glob)
3. If this file reads/writes data files, show field names, structure,
and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
파괴적 Bash 게이트 (모든 파괴적 명령어)
다음 조건에서 트리거됨: rm -rf, git reset --hard, git push --force, drop table등
1. List all files/data this command will modify or delete
2. Write a one-line rollback procedure
3. Quote the user's current instruction verbatim
루틴 Bash 게이트 (세션당 한 번)
1. The current user request in one sentence
2. What this specific command verifies or produces
빠른 시작
옵션 A: ECC 후크 사용 (설치 불필요)
이 플러그인에는 scripts/hooks/gateguard-fact-force.js 이 플러그인에 포함되어 있습니다. hooks.json을 통해 활성화하십시오.
GateGuard가 설정 또는 복구 작업을 차단하는 경우, 세션을
ECC_GATEGUARD=off로 세션을 시작하십시오. 훅 수준에서 제어하려면
ECC_DISABLED_HOOKS GateGuard 후크 ID와 함께 계속 사용하십시오.
긴 세션에서는 첫 번째 GATEGUARD_FACT_FORCE_FULL_DENIALS
fact-force 거부(기본값 3)만 전체 4개 팩트 블록을 출력하며, 이후의
거부 사항은 거부 순서를 포함하는 한 줄로 압축되므로,
거의 동일한 블록이 컨텍스트 창에 누적되어
모델 반복 루프를 증폭시키는 현상을 방지합니다(#2142). 팩트를 제시한 후 동일한 파일이나
명령을 재시도해도 게이트가 다시 트리거되지 않습니다.
옵션 B: 구성 파일이 포함된 전체 패키지
pip install gateguard-ai
gateguard init
이 옵션은 .gateguard.yml 프로젝트별 구성(사용자 정의 메시지, 무시 경로, 게이트 토글)을 위한 기능을 추가합니다.
반패턴
- 대신 자체 평가를 사용하지 마십시오. "확실합니까?"라는 질문에는 항상 "예"라는 답변이 돌아옵니다. 이는 실험을 통해 검증된 사실입니다.
- 데이터 스키마 검사를 건너뛰지 마십시오. 실제 데이터가 사용되었을 때 A/B 테스트 에이전트 모두 ISO-8601 날짜 형식을 가정했습니다
%Y/%m/%d %H:%M. (값을 가린 상태에서) 데이터 구조를 확인하면 이러한 유형의 버그를 모두 방지할 수 있습니다. - 모든 Bash 명령어에 게이트를 적용하지 마십시오. 루틴 Bash 게이트는 세션당 한 번만 적용됩니다. 파괴적인 Bash 게이트는 매번 적용됩니다. 이러한 균형을 통해 실제 위험을 포착하면서도 속도 저하를 방지할 수 있습니다.
모범 사례
- 게이트가 자연스럽게 작동하도록 하세요. 게이트 질문에 미리 답하려고 하지 마세요. 조사 과정 자체가 품질을 향상시킵니다.
- 도메인에 맞게 게이트 메시지를 맞춤 설정하세요. 프로젝트에 특정 관례가 있다면, 이를 게이트 프롬프트에 추가하세요.
- 다음과 같이
.gateguard.yml를 사용하여 다음과 같은 경로는 무시하십시오..venv/,node_modules/,.git/.
관련 기술
safety-guard— 런타임 안전성 검사 (중복되지 않고 상호 보완적인)code-reviewer— 편집 후 검토 (GateGuard는 편집 전 조사 단계입니다)
---
name: gateguard
description: Forces AI agents to investigate before editing or running destructive commands, improving code quality by requiring concrete facts like importers, data schemas, and user instructions.
---
# GateGuard — Fact-Forcing Pre-Action Gate
A PreToolUse hook that forces Claude to investigate before editing. Instead of self-evaluation ("are you sure?"), it demands concrete facts. The act of investigation creates awareness that self-evaluation never did.
## When to Activate
- Working on any codebase where file edits affect multiple modules
- Projects with data files that have specific schemas or date formats
- Teams where AI-generated code must match existing patterns
- Any workflow where Claude tends to guess instead of investigating
## Core Concept
LLM self-evaluation doesn't work. Ask "did you violate any policies?" and the answer is always "no." This is verified experimentally.
But asking "list every file that imports this module" forces the LLM to run Grep and Read. The investigation itself creates context that changes the output.
**Three-stage gate:**
```
1. DENY — block the first Edit/Write/Bash attempt
2. FORCE — tell the model exactly which facts to gather
3. ALLOW — permit retry after facts are presented
```
No competitor does all three. Most stop at deny.
## Evidence
Two independent A/B tests, identical agents, same task:
| Task | Gated | Ungated | Gap |
| --- | --- | --- | --- |
| Analytics module | 8.0/10 | 6.5/10 | +1.5 |
| Webhook validator | 10.0/10 | 7.0/10 | +3.0 |
| **Average** | **9.0** | **6.75** | **+2.25** |
Both agents produce code that runs and passes tests. The difference is design depth.
## Gate Types
### Edit / MultiEdit Gate (first edit per file)
MultiEdit is handled identically — each file in the batch is gated individually.
```
Before editing {file_path}, present these facts:
1. List ALL files that import/require this file (use Grep)
2. List the public functions/classes affected by this change
3. If this file reads/writes data files, show field names, structure,
and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
```
### Write Gate (first new file creation)
```
Before creating {file_path}, present these facts:
1. Name the file(s) and line(s) that will call this new file
2. Confirm no existing file serves the same purpose (use Glob)
3. If this file reads/writes data files, show field names, structure,
and date format (use redacted or synthetic values, not raw production data)
4. Quote the user's current instruction verbatim
```
### Destructive Bash Gate (every destructive command)
Triggers on: `rm -rf`, `git reset --hard`, `git push --force`, `drop table`, etc.
```
1. List all files/data this command will modify or delete
2. Write a one-line rollback procedure
3. Quote the user's current instruction verbatim
```
### Routine Bash Gate (once per session)
```
1. The current user request in one sentence
2. What this specific command verifies or produces
```
## Quick Start
### Option A: Use the ECC hook (zero install)
The hook at `scripts/hooks/gateguard-fact-force.js` is included in this plugin. Enable it via hooks.json.
If GateGuard blocks setup or repair work, start the session with
`ECC_GATEGUARD=off`. For hook-level control, keep using
`ECC_DISABLED_HOOKS` with the GateGuard hook ID.
In long sessions, only the first `GATEGUARD_FACT_FORCE_FULL_DENIALS`
fact-force denials (default 3) emit the full four-fact block; later
denials are condensed to a single line carrying the denial ordinal, so
near-identical blocks cannot accumulate in the context window and
amplify model repetition loops (#2142). Retrying the same file or
command after presenting facts never re-triggers the gate.
### Option B: Full package with config
```bash
pip install gateguard-ai
gateguard init
```
This adds `.gateguard.yml` for per-project configuration (custom messages, ignore paths, gate toggles).
## Anti-Patterns
- **Don't use self-evaluation instead.** "Are you sure?" always gets "yes." This is experimentally verified.
- **Don't skip the data schema check.** Both A/B test agents assumed ISO-8601 dates when real data used `%Y/%m/%d %H:%M`. Checking data structure (with redacted values) prevents this entire class of bugs.
- **Don't gate every single Bash command.** Routine bash gates once per session. Destructive bash gates every time. This balance avoids slowdown while catching real risks.
## Best Practices
- Let the gate fire naturally. Don't try to pre-answer the gate questions — the investigation itself is what improves quality.
- Customize gate messages for your domain. If your project has specific conventions, add them to the gate prompts.
- Use `.gateguard.yml` to ignore paths like `.venv/`, `node_modules/`, `.git/`.
## Related Skills
- `safety-guard` — Runtime safety checks (complementary, not overlapping)
- `code-reviewer` — Post-edit review (GateGuard is pre-edit investigation)
모든 파일
1개 파일gateguard 설치
스킬 파일을 다운로드하여 .claude/skills/ 디렉터리에 압축을 풀어주세요.
ZIP 다운로드저장소를 클론하고 스킬 파일을 프로젝트에 복사하세요.
git clone https://github.com/affaan-m/ECC/tree/main/skills/gateguard # Copy SKILL.md to your .claude/skills/ directory
복사





집
