Skip to content
MoorAI
// claude code security

Claude Code security: a check before every tool call

To secure Claude Code, use its own controls — permission deny rules, managed settings and the sandbox — and add a PreToolUse hook that inspects what each tool call carries before it runs. MoorAI is that hook, open source (MIT) and on the device: it checks file reads, shell commands, writes, web fetches and MCP tool calls for secrets, personal data, prompt injection and unsafe commands, and scans what comes back from shell commands, MCP tools and sub-agents. Nothing is sent anywhere to be checked.

How do I stop Claude Code from reading my .env file?

Add Read deny rules to Claude Code’s settings. This is the example Anthropic’s settings documentation gives, for ~/.claude/settings.json or a project’s .claude/settings.json:

{
  "permissions": {
    "deny": [
      "Read(./.env)",
      "Read(./.env.*)"
    ]
  }
}

Know where the rule stops. Per Anthropic’s permissions documentation, Read deny rules cover Claude’s built-in file tools, the Bash file commands Claude Code recognizes (cat, head, tail, sed, tee) and redirection targets. They do not cover a command that reads files without naming them, such as grep -r pattern ., or a Python or Node script that opens files itself; for that the documentation points to the sandbox.

MoorAI adds a check on content, not just on the path. Its hook treats a Read of .env — relative, absolute or ~/, including .env.local and .env.production — the same as cat .env, and asks before it runs; .env.example, .env.sample and .env.template are not flagged. It scans the content of every file read, command and MCP argument for secrets in known shapes (GitHub, AWS, Stripe, Slack, GCP, OpenAI and Anthropic keys, database connection strings, private keys) and by entropy. And it fingerprints your local secret values as keyed one-way hashes, so an outbound command that carries one verbatim is caught even when the value has no recognizable shape. Try it: node ~/.moorai/cli/moorai-explain.mjs "cat .env".

What is a Claude Code hook guardrail?

A hook guardrail is a program Claude Code runs at a fixed point in its loop that can allow, ask or deny what happens next. PreToolUse runs before a tool call, PostToolUse after it, UserPromptSubmit when you send a prompt. Unlike an MCP tool, which the model may choose not to call, the agent passes through the hook on every tool call its matcher names. MoorAI registers PreToolUse on Read, Bash, Write, Edit, MultiEdit, NotebookEdit, WebFetch, Agent, Task and every mcp__ tool, and PostToolUse on Bash, WebFetch, WebSearch, Agent, Task and every mcp__ tool. See the glossary entry for the PreToolUse hook.

What MoorAI checks in a Claude Code session

WhereWhat it catchesWhat it can do
Files read into contextSecrets, personal and health data in the file; .env and credential files by pathCoach, ask, block before the content reaches the model
Shell commandsReverse shells, destructive commands, a local secret leaving in an upload, typosquatted package installs, a proxy and CA override that lets traffic be decryptedCoach, ask, block, end the session
MCP tool callsSecrets or personal data in arguments, servers not on the allow-list, low-reputation serversCoach, ask, block, mask the value
Writes and editsSecrets and insecure code the agent writes (SQL injection, XSS, command injection, weak crypto, unsafe deserialization)Coach, ask, block, mask the value
Tool resultsIndirect prompt injection and secrets in command output, MCP responses, sub-agent reports and fetched pagesReport and warn the model; the tool has already run
Rules filesA poisoned CLAUDE.md or .mcp.json, and rules files leaving the device through the agentReport, per policy
Your promptOnly for intent alignment: keyed hashes of the sites, paths and services it names, never the textFlags a risky action aimed at something the prompt never mentioned

Every row is checked on the device. Scanning tool results costs one extra hook process per Bash, MCP or sub-agent call, about 82 ms at p50, and a PostToolUse block cannot un-run the tool: Claude still sees the output, with MoorAI’s warning beside it. Intent alignment is lexical, not semantic, and Claude Code only. Details and every limit: capabilities, rules-file security, on-device AI DLP.

Claude Code security for enterprises

An organization needs three things a single developer does not: a policy nobody can quietly switch off, the same policy on every machine, and a record it can keep.

  • Keep hooks on. Claude Code’s managed settings sit above user and project settings. Its allowManagedHooksOnly setting runs only the hooks your organization deploys, and disableAllHooks turns hooks off; moorai-doctor reports both, so you can see whether MoorAI’s hook can run on a machine at all.
  • One policy for the fleet. A device enrolled in the MoorAI console fetches its organization’s signed policy: per threat, per data tier, per tenant and per device, to coach, alert, mask, block, require a signed justification or end the session. With no policy set, built-in defaults block a reverse shell and a local secret leaving the machine, and ask before credential reads and five other high-risk actions.
  • Evidence without the content. The console receives a category, a risk level and a keyed one-way hash per event; the prompt, file and matched value stay on the machine. Events can stream to a SIEM as OpenTelemetry spans with the same fields, and a tamper-evident chain on the device’s logs shows whether a record was deleted or edited.
  • The same checks beyond Claude Code. Codex CLI, Copilot CLI, Gemini CLI and Cursor run the same engine through their own pre-tool hooks; those adapters are tested against each vendor’s documented payloads, not yet against the live agents.

The console is free for up to 200 users (pricing). What MoorAI does not do: it is not a sandbox, it fails open if its hook crashes or times out, and it runs as the same user as the agent, so it is built to stop mistakes and injected instructions and to keep an accurate record, not to contain an attacker who already has code execution on the machine. Keep Claude Code’s sandbox and deny rules alongside it.

Related reading

// faq

Deny rules, sandbox, and accounts.

Does a permissions deny rule stop Claude Code from reading .env?

Mostly. Anthropic’s documentation says Read deny rules apply to Claude’s built-in file tools, to Bash file commands Claude Code recognizes such as cat, head, tail and sed, and to redirection targets, but not to a command that reads files without naming them or to a script that opens files itself. For those, the documentation points to the sandbox. MoorAI adds a check on the content of every tool call, so a secret is caught by what it is, wherever it travels.

Does MoorAI replace Claude Code’s sandbox or permission rules?

No. Keep them. Deny rules and the sandbox decide what Claude Code may touch; MoorAI checks what is in the call and what comes back, and keeps a content-free record. MoorAI is governance, not a sandbox: it fails open if its hook crashes or times out, and it runs as the same user as the agent.

Does MoorAI block anything without an account?

No. Without enrollment it coaches: a flagged call goes on to Claude Code’s normal permission prompt with a note naming what was caught and the safer way, and nothing is posted anywhere. Blocking, sign-off and ending a session apply once the device is enrolled in a MoorAI console, free for up to 200 users.

What does the security team see from Claude Code sessions?

A category, a risk level and a keyed one-way hash per event, from enrolled devices only. Never the prompt, the file, the command text or the matched value. Events can also stream to a SIEM as OpenTelemetry spans carrying the same content-free fields.

Guard Claude Code
on the device.

One command installs the hooks. Open source (MIT).