corgi agent harden
corgi agent harden
Write the safe defaults into this workspace's Claude settings
Synopsis
Adds to .claude/settings.local.json in the workspace: deny rules for reading secrets (.env, keys, ~/.ssh, ~/.aws) and for destructive shell and git (rm -rf, sudo, force push, reset --hard, --no-verify), and a hook that refuses to write a credential into a file. Nothing is removed; a rule already there is left alone.
corgi agent harden # the workspace you are in corgi agent harden --dry-run # show what would change corgi agent doctor --security # what is still loose
corgi agent harden [flags]
Options
--dry-run show what would change without writing
-h, --help help for harden
Options inherited from parent commands
--describe Describe contents of corgi-compose file
--dockerContext string Specify docker context to use, can be default,orbctl,colima (default "default")
-l, --exampleList List examples to choose from. Click on any example to download it
-f, --filename string Custom filepath for for corgi-compose
--fromScratch Clean the .corgi/corgi_services folder before running
-t, --fromTemplate string Create corgi service from template url
--fromTemplateName string Create corgi service from template name and url
-g, --global Use global path to one of the services
--interactive Force interactive prompts even when no TTY/agent detected
--isolate string Run this workspace under a named lease: own port block, own database names, own containers
--json Emit machine-readable JSON output
--privateToken string Private token for private repositories to download files
-o, --runOnce Run corgi once and exit
--silent Hide all welcome messages
SEE ALSO
- corgi agent - Keep Claude Code Remote Control running for your corgi workspaces