Knox Claude Code Plugin
The Knox Claude Code plugin is the standalone developer version of Knox. It runs outside Claude’s model context and checks tool calls before they execute. It is useful for:- developer safety
- autonomous coding sessions
- scheduled Claude Code tasks
- MCP-heavy workflows
- auditing what agents attempted
- preventing destructive commands before they run
Repository
The plugin lives in:Install
The canonical Knox install path is the Claude Code plugin marketplace.GITHUB_TOKEN.
There is no uvx install path for Knox.
Local development and fallback hook wiring:
claude plugin install knox@qoris.
One-off local plugin session:
How It Works
Knox is wired into Claude Code hooks. The most important hook isPreToolUse. It runs before actions such as Bash commands, file writes, reads, MCP tool calls, and scheduled task creation.
If an action is safe, Knox allows it.
If an action is risky, Knox can:
- deny it with a reason
- hard block it
- sanitize it
- write an audit event
- inject additional context after repeated denials
What It Protects
The plugin protects common developer-agent risk surfaces:- shell commands
- PowerShell commands
- background monitor commands
- file reads
- file writes and edits
- MCP tool calls
- cron and scheduled task creation
- settings changes that could disable Knox
- prompt injection in submitted user prompts
- suspicious loaded instructions
Configuration
Knox reads policy from layered config files. Common files:.knox.json is project policy.
.knox.local.json is personal local policy and should not be committed.
Policy Presets
Knox ships with presets:standard for normal developer safety. Use stricter presets for autonomous or high-risk environments.
Best Use Cases
Knox is strongest when agents operate beyond a single watched chat session:- background coding agents
- cron jobs
- subagents
- MCP-connected agents
- external input channels
- enterprise teams that need consistent policy and audit
