{"_id":"@agentguardsco/claude-selfhosted-plugin","_rev":"4-85489577a17660dc72c749b546b60417","name":"@agentguardsco/claude-selfhosted-plugin","dist-tags":{"latest":"0.1.11"},"versions":{"0.1.0":{"name":"@agentguardsco/claude-selfhosted-plugin","version":"0.1.0","keywords":["claude-code","claude-code-plugin","llm-security","guardrails","prompt-injection","jailbreak-detection","self-hosted"],"author":{"url":"https://agentguards.co","name":"AgentGuards","email":"support@agentguards.co"},"license":"MIT","_id":"@agentguardsco/claude-selfhosted-plugin@0.1.0","maintainers":[{"name":"agentguards_co","email":"dev@agentguards.co"}],"homepage":"https://agentguards.co","bugs":{"url":"https://github.com/alelaguard/agentguards-plugins/issues"},"dist":{"shasum":"c4904654301940da5d65a36c317a9dd57ebbf146","tarball":"https://registry.npmjs.org/@agentguardsco/claude-selfhosted-plugin/-/claude-selfhosted-plugin-0.1.0.tgz","fileCount":8,"integrity":"sha512-0VcEUDffOjhFm24fbXqge2fa1VmR89rI44aWInjLmuHFu0IcCs7K0iHQmcEna0rpgESsczIJmVcMzmVHcSFECg==","signatures":[{"sig":"MEUCIQDainH+ibkkFk19sh5z7tQ8wxZN+hOc8nqU243mOigChQIgRtNqJ4CjSHKIjy+PeBb8jDyzOlQQBpINemy2A1pFrHE=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":40407},"gitHead":"c8a22f27caf51ac09596c363e367797d3bb9d00a","_npmUser":{"name":"agentguards_co","email":"dev@agentguards.co"},"repository":{"url":"git+https://github.com/alelaguard/agentguards-plugins.git","type":"git","directory":"claude-selfhosted"},"_npmVersion":"10.8.2","description":"LLM security guardrails for Claude Code, for a self-hosted AgentGuards appliance — enforced entirely by hooks, no bundled MCP server.","directories":{},"_nodeVersion":"20.19.5","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/claude-selfhosted-plugin_0.1.0_1785843105195_0.9192258502680346","host":"s3://npm-registry-packages-npm-production"}},"0.1.8":{"name":"@agentguardsco/claude-selfhosted-plugin","version":"0.1.8","keywords":["claude-code","claude-code-plugin","llm-security","guardrails","prompt-injection","jailbreak-detection","self-hosted"],"author":{"url":"https://agentguards.co","name":"AgentGuards","email":"support@agentguards.co"},"license":"MIT","_id":"@agentguardsco/claude-selfhosted-plugin@0.1.8","maintainers":[{"name":"agentguards_co","email":"dev@agentguards.co"}],"homepage":"https://agentguards.co","bugs":{"url":"https://github.com/alelaguard/agentguards-plugins/issues"},"dist":{"shasum":"2ebe1a2303b4980226b055fe16a5773c83413f0d","tarball":"https://registry.npmjs.org/@agentguardsco/claude-selfhosted-plugin/-/claude-selfhosted-plugin-0.1.8.tgz","fileCount":8,"integrity":"sha512-3Avmb45PDfOxjexL1EvPllM2AhNtHT5BGMQKa8vWz1mRD9A1g6OmkT/MUEQ5aZdnJixzXlfacY8ioGGCdcCbaA==","signatures":[{"sig":"MEYCIQCZRxTO9tIfa7U3wRAio7LDKI6hq4ZyMI/tdb43ytQugwIhAMx3nddDs2/22AzIkmp33aY2EQsrOYDFnR9LqzXGkNtn","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentguardsco%2fclaude-selfhosted-plugin@0.1.8","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":50087},"gitHead":"9c2c95aefcf56974f2f8379b5e96853f35ac7fdf","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d8e38374-c4c8-42d6-9527-e04d9555ea4f"}},"repository":{"url":"git+https://github.com/alelaguard/agentguards-plugins.git","type":"git","directory":"claude-selfhosted"},"_npmVersion":"12.0.2","description":"LLM security guardrails for Claude Code, for a self-hosted AgentGuards appliance — enforced entirely by hooks, no bundled MCP server.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/claude-selfhosted-plugin_0.1.8_1786468053292_0.21951013332320657","host":"s3://npm-registry-packages-npm-production"}},"0.1.9":{"name":"@agentguardsco/claude-selfhosted-plugin","version":"0.1.9","keywords":["claude-code","claude-code-plugin","llm-security","guardrails","prompt-injection","jailbreak-detection","self-hosted"],"author":{"url":"https://agentguards.co","name":"AgentGuards","email":"support@agentguards.co"},"license":"MIT","_id":"@agentguardsco/claude-selfhosted-plugin@0.1.9","maintainers":[{"name":"agentguards_co","email":"dev@agentguards.co"}],"homepage":"https://agentguards.co","bugs":{"url":"https://github.com/alelaguard/agentguards-plugins/issues"},"dist":{"shasum":"bf56e84faf00511b561418195c5d36ebcbe1659f","tarball":"https://registry.npmjs.org/@agentguardsco/claude-selfhosted-plugin/-/claude-selfhosted-plugin-0.1.9.tgz","fileCount":9,"integrity":"sha512-Qu4ezD5I9tI1zxWGeMOZh/uIs05TUtiL6uttTvcDeqmDU5oGpbWJ0zOp4gpDD1+bVsZitqxRhk+7WQaiO1nbng==","signatures":[{"sig":"MEUCIQDXfqGp5VSdhWR2QSLyoSObAfJ0W8fTTTRbRV0mK4ge8AIgN3dJcmC2JHPl5QkWQQsWd9kmjXMClZtzbjjXW0F6z64=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentguardsco%2fclaude-selfhosted-plugin@0.1.9","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":51155},"gitHead":"28680cd897be96c12e663ac98e5864af401a54b3","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d8e38374-c4c8-42d6-9527-e04d9555ea4f"}},"repository":{"url":"git+https://github.com/alelaguard/agentguards-plugins.git","type":"git","directory":"claude-selfhosted"},"_npmVersion":"12.0.2","description":"LLM security guardrails for Claude Code, for a self-hosted AgentGuards appliance — enforced entirely by hooks, no bundled MCP server.","directories":{},"_nodeVersion":"24.18.0","_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/claude-selfhosted-plugin_0.1.9_1786545078274_0.29020358069435326","host":"s3://npm-registry-packages-npm-production"}},"0.1.11":{"name":"@agentguardsco/claude-selfhosted-plugin","version":"0.1.11","description":"LLM security guardrails for Claude Code, for a self-hosted AgentGuards appliance — enforced entirely by hooks, no bundled MCP server.","license":"MIT","homepage":"https://agentguards.co","repository":{"type":"git","url":"git+https://github.com/alelaguard/agentguards-plugins.git","directory":"claude-selfhosted"},"author":{"name":"AgentGuards","email":"support@agentguards.co","url":"https://agentguards.co"},"keywords":["claude-code","claude-code-plugin","llm-security","guardrails","prompt-injection","jailbreak-detection","self-hosted"],"gitHead":"292a82590e93b5d207d2b324804eaef8c8b06e09","_id":"@agentguardsco/claude-selfhosted-plugin@0.1.11","bugs":{"url":"https://github.com/alelaguard/agentguards-plugins/issues"},"_nodeVersion":"24.19.0","_npmVersion":"12.0.2","dist":{"integrity":"sha512-GdxbBXWKZpwCJZXtHadeqn8Pf5qjVvK/yWkWwfxCI6oEgpAhzDjF1cj2ud+YKhtE90JY6PB0nwaudYI34Y3Ofg==","shasum":"3507342f5e10f25dc5060b8e2c9cac88613e4948","tarball":"https://registry.npmjs.org/@agentguardsco/claude-selfhosted-plugin/-/claude-selfhosted-plugin-0.1.11.tgz","fileCount":9,"unpackedSize":51253,"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@agentguardsco%2fclaude-selfhosted-plugin@0.1.11","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHL+jYIFlfe4ok/SLeeSGQ3lmI8yxNMRyuY2Sys/eOVqAiEApo6jG/+G+gy23TW4ZHTVlXZjt9nyxjvjI4VQDbEXhz8="}]},"_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"oidc:d8e38374-c4c8-42d6-9527-e04d9555ea4f"}},"directories":{},"maintainers":[{"name":"agentguards_co","email":"dev@agentguards.co"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/claude-selfhosted-plugin_0.1.11_1787638913621_0.22701977429013054"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-04T11:31:44.960Z","modified":"2026-08-25T06:21:54.121Z","0.1.0":"2026-08-04T11:31:45.336Z","0.1.8":"2026-08-11T17:07:33.442Z","0.1.9":"2026-08-12T14:31:18.414Z","0.1.11":"2026-08-25T06:21:53.758Z"},"bugs":{"url":"https://github.com/alelaguard/agentguards-plugins/issues"},"author":{"name":"AgentGuards","email":"support@agentguards.co","url":"https://agentguards.co"},"license":"MIT","homepage":"https://agentguards.co","keywords":["claude-code","claude-code-plugin","llm-security","guardrails","prompt-injection","jailbreak-detection","self-hosted"],"repository":{"type":"git","url":"git+https://github.com/alelaguard/agentguards-plugins.git","directory":"claude-selfhosted"},"description":"LLM security guardrails for Claude Code, for a self-hosted AgentGuards appliance — enforced entirely by hooks, no bundled MCP server.","maintainers":[{"name":"agentguards_co","email":"dev@agentguards.co"}],"readme":"# AgentGuards plugin for Claude Code — self-hosted\n\nFor a **self-hosted AgentGuards appliance**. If you're on the hosted product\nat agentguards.co, install `agentguards-claude` instead — it bundles the MCP\nserver this variant deliberately does not.\n\n## Why a separate plugin\n\nClaude Code's plugin `.mcp.json` cannot substitute an environment variable\ninto its `url` field — it has to be a fixed string, baked in when the plugin\nis published. `agentguards-claude`'s `.mcp.json` therefore points at\n`https://prod.agentguards.co`, and there is no way to override that per\ninstallation. Shipping one plugin for both audiences meant a self-hosted\noperator's MCP tool calls (`check_input`, `authorize_action`, …) would go to\nAgentGuards' hosted service instead of their own appliance, with no error and\nno way to tell — the opposite of what a self-hosted deployment is for.\n\nThis variant ships **hooks only**, with no MCP server at all. Hooks read\n`AGENTGUARDS_URL` from the environment as a subprocess, correctly per\ninstallation, so they aren't affected by that limitation. They are also the\nactual enforcement mechanism — `check_input`/`authorize_action` in the other\nvariant are a cooperative convenience the model can choose to call; the hooks\nrun regardless. Nothing here is a reduced version of the guardrail, only a\nnarrower plugin.\n\n## Install\n\n```\n/plugin marketplace add alelaguard/agentguards-plugins\n/plugin install agentguards-claude-selfhosted@agentguards\n```\n\nThen point it at your appliance. Unlike the hosted plugin, **there is no\ndefault** — this is deliberate, so it can never silently talk to the wrong\ninstance:\n\n```\nexport AGENTGUARDS_URL=https://<your-appliance>\nexport AGENTGUARDS_API_KEY=ag_your_token_here\n```\n\nAdd both lines to your shell profile (`~/.bashrc`, `~/.zshrc`, …) and restart\nClaude Code. Or run `/agentguards:setup` and it will walk you through it,\nincluding the appliance's first-boot self-signed certificate if that applies.\n\n**Alternative: `npm install @agentguardsco/claude-selfhosted-plugin`.** Fetches\nthese files for programmatic use — it does not register with Claude Code on\nits own; use `/plugin install` above for that.\n\n## Commands\n\n- `/agentguards:setup` — configure the appliance URL and API key, and verify.\n- `/agentguards:status` — report reachability and whether the key is accepted.\n\n## Configuration\n\n| Variable | Required | Default | Purpose |\n|---|---|---|---|\n| `AGENTGUARDS_URL` | **yes** | — none | Your appliance's own address. No fallback, by design. |\n| `AGENTGUARDS_API_KEY` | yes | — | Your `ag_` token, generated on your appliance's own `/admin/ui/keys`. |\n| `AGENTGUARDS_CA_BUNDLE` | no | — | Pin the appliance's certificate while it's still self-signed. Verification stays on. |\n| `AGENTGUARDS_TLS_NO_VERIFY` | no | `false` | Skip certificate verification. Private-network evaluation only. |\n| `AGENTGUARDS_FAIL_OPEN` | no | `false` | Hooks fail **closed** by default. Set `true` to allow on error. |\n\n## How it works\n\nThe hooks call your appliance's REST API on every prompt, before every Bash\ncommand, and after every web fetch — blocking or redacting when it flags a\nrisk. There is no cooperative MCP layer in this variant; see the bundled\n`guardrails` skill for why that's not a gap.\n\nLearn more at https://agentguards.co.\n","readmeFilename":"README.md"}