Nicheloom

Market intelligence for builders — see what's gaining traction before it's crowded.

A context-aware permission guard for Claude Code

Details

External ID
47343927
Source
HN
Company
—
Product
A context-aware permission guard for Claude Code
Website domain
github.com
Launched
March 11, 2026
Cohort
—
Upvotes
127
Upvotes percentile
0.9317343173431735
Tags
—
Fetched at
Sept. 7, 2026, 9:26 p.m.
Updated at
Sept. 7, 2026, 9:26 p.m.

Description

We needed something like --dangerously-skip-permissions that doesn’t nuke your untracked files, exfiltrate your keys, or install malware.Claude Code's permission system is allow-or-deny per tool, but that doesn’t really scale. Deleting some files is fine sometimes. And git checkout is sometimes not fine. Even when you curate permissions, 200 IQ Opus can find a way around it. Maintaining a deny list is a fool's errand.nah is a PreToolUse hook that classifies every tool call by what it actually does, using a deterministic classifier that runs in milliseconds. It maps commands to action types like filesystem_read, package_run, db_write, git_history_rewrite, and applies policies: allow, context (depends on the target), ask, or block.Not everything can be classified, so you can optionally escalate ambiguous stuff to an LLM, but that’s not required. Anything unresolved you can approve, and configure the taxonomy so you don’t get asked again.It works out of the box with sane defaults, no config needed. But you can customize it fully if you want to.No dependencies, stdlib Python, MIT.pip install nah && nah installhttps://github.com/manuelschipper/nah

Enrichment

Theme
utilities for Claude and Claude Code
Vertical
Security
Function
Dev tools
Audience
Developer
AI stance
AI feature
Project type
Hobby / open-source project
Normalized one-liner
permission control for claude code editor
Manually corrected
False

Could you build this?

Yes It is a CLI wrapper or proxy script around Claude Code tool calls that inspects proposed commands and file operations against security heuristics before allowing execution.

Discussion

20 comments analyzed.

Competitors mentioned: railguard (Rust-based alternative), claude-container (Docker socket proxy approach), nah (permission guardrail tool)

Concerns raised: Context matters more than pattern matching - deleting temp files vs config files look identical to classifiers, Unknown-bad outcomes still possible even with permission checks - need supervision/recovery mechanisms, Anthropic's permission system is poor despite product traction, Shared state problems when multiple agents write simultaneously (race conditions), Secrets can leak via indirect access (git configs, env vars, credential helpers, repo contents)

Feature requests: Allowlist-based approach instead of blocklist/deny list, Better handling of piped commands (find/grep) without unnecessary permission prompts, Read-only GitHub CLI access restricted to specific repos, Filtered workspace mounts instead of full project directory access, Worktree-per-task isolation for cleaner boundaries

Competitors

Other products that read as similar to this one — 364 launches clear the similarity bar, closest 8 shown.

Attention rank: #24 of 365 (itself plus its competitors, highest first — normalized so YC and Product Hunt are compared fairly).

Launched 125 days after the earliest competitor.

Other launches for this product

Same idea, different domain

Nobody's really built a dev tools tool for Sales yet.