Skip to main content

Knox Claude Code Plugin

The Knox Claude Code plugin is the standalone developer version of Knox. It runs outside Claude’s model context and checks tool calls before they execute. It is useful for:
  • developer safety
  • autonomous coding sessions
  • scheduled Claude Code tasks
  • MCP-heavy workflows
  • auditing what agents attempted
  • preventing destructive commands before they run

Repository

The plugin lives in:
Important files:

Install

The canonical Knox install path is the Claude Code plugin marketplace.
For private marketplace access, run the same commands with a GitHub token available in GITHUB_TOKEN. There is no uvx install path for Knox. Local development and fallback hook wiring:
That fallback wires hooks directly into Claude Code settings. It is useful for development, but for normal use prefer claude plugin install knox@qoris. One-off local plugin session:

How It Works

Knox is wired into Claude Code hooks. The most important hook is PreToolUse. It runs before actions such as Bash commands, file writes, reads, MCP tool calls, and scheduled task creation. If an action is safe, Knox allows it. If an action is risky, Knox can:
  • deny it with a reason
  • hard block it
  • sanitize it
  • write an audit event
  • inject additional context after repeated denials

What It Protects

The plugin protects common developer-agent risk surfaces:
  • shell commands
  • PowerShell commands
  • background monitor commands
  • file reads
  • file writes and edits
  • MCP tool calls
  • cron and scheduled task creation
  • settings changes that could disable Knox
  • prompt injection in submitted user prompts
  • suspicious loaded instructions

Configuration

Knox reads policy from layered config files. Common files:
.knox.json is project policy. .knox.local.json is personal local policy and should not be committed.

Policy Presets

Knox ships with presets:
Use standard for normal developer safety. Use stricter presets for autonomous or high-risk environments.

Best Use Cases

Knox is strongest when agents operate beyond a single watched chat session:
  • background coding agents
  • cron jobs
  • subagents
  • MCP-connected agents
  • external input channels
  • enterprise teams that need consistent policy and audit
In interactive sessions, the model may refuse many obvious attacks before Knox fires. Knox still provides a mechanical backstop and an audit trail.