Skip to main content

corgi agent harden

corgi agent harden

Write the safe defaults into this workspace's Claude settings

Synopsis

Adds to .claude/settings.local.json in the workspace: deny rules for reading secrets (.env, keys, ~/.ssh, ~/.aws) and for destructive shell and git (rm -rf, sudo, force push, reset --hard, --no-verify), and a hook that refuses to write a credential into a file. Nothing is removed; a rule already there is left alone.

corgi agent harden # the workspace you are in corgi agent harden --dry-run # show what would change corgi agent doctor --security # what is still loose

corgi agent harden [flags]

Options

--dry-run show what would change without writing
-h, --help help for harden

Options inherited from parent commands

--describe Describe contents of corgi-compose file
--dockerContext string Specify docker context to use, can be default,orbctl,colima (default "default")
-l, --exampleList List examples to choose from. Click on any example to download it
-f, --filename string Custom filepath for for corgi-compose
--fromScratch Clean the .corgi/corgi_services folder before running
-t, --fromTemplate string Create corgi service from template url
--fromTemplateName string Create corgi service from template name and url
-g, --global Use global path to one of the services
--interactive Force interactive prompts even when no TTY/agent detected
--isolate string Run this workspace under a named lease: own port block, own database names, own containers
--json Emit machine-readable JSON output
--privateToken string Private token for private repositories to download files
-o, --runOnce Run corgi once and exit
--silent Hide all welcome messages

SEE ALSO

  • corgi agent - Keep Claude Code Remote Control running for your corgi workspaces
Auto generated by spf13/cobra on 20-Sep-2026