cc-monitor

A tool that watches what Claude Code does on your computer, such as file access, shell commands and network use. It asks or blocks on risky actions and keeps an audit log.

Share on XLicense: MIT

Overview

CC-Monitor watches what Claude Code does on your machine, including file reads and writes, shell command execution and network access. It blocks or asks for confirmation on high-risk operations, so an AI coding agent cannot quietly damage the system or leak data, and everything is written to an audit log. It is distributed as a Claude Code plugin, with an eBPF probe on Linux. The README covers a design document, security notes and a changelog, and the current release is v2.0.

Key features

  • Monitors file access, shell commands and network use
  • Blocks or asks before high-risk operations
  • Keeps an audit log of every action
  • Runs as a Claude Code plugin, with eBPF probe on Linux
  • Other agents such as Codex CLI are on the dev branch

Best for

People who let Claude Code work on their machine and want oversight and a record of its actions. The master branch covers Claude Code only, and support for other agents is experimental.

Upstream
cn0xroot/CC-Monitor
Fork on GitHub
Guo-astro/cc-monitor
Upstream stars
43
Category
AI agents and LLM tools
Language
JavaScript
License
MIT
Forked
2026-09-12
Sync status
In syncLast synced 2026-09-29