Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
Show all changes
108 commits
Select commit Hold shift + click to select a range
70d3c31
feat(settings)!: one settings document per IDE installation and project
serialexperimentslainnnn Aug 20, 2026
359cd69
feat(permission): report every route past a rule, and name which one
serialexperimentslainnnn Aug 20, 2026
e7b5910
feat(ui): one mode of three, a readable whitelist, pages at the root
serialexperimentslainnnn Aug 20, 2026
3dfbade
chore(release): bump to 6.0.0
serialexperimentslainnnn Aug 20, 2026
062a857
fix(ui): whitelist scope above the list, and both pages reflow
serialexperimentslainnnn Aug 20, 2026
40a8242
fix(permission): bypass warnings name the rule and the undo
serialexperimentslainnnn Aug 20, 2026
954a342
docs(changelog): cut the 6.0.0 entry down to what changed
serialexperimentslainnnn Aug 20, 2026
97b30a9
fix(permission): a block explains itself instead of ordering the model
serialexperimentslainnnn Aug 20, 2026
0078a6a
feat(permission): log every guard alert, and restore the rows from it
serialexperimentslainnnn Aug 20, 2026
2e5f4c5
fix(ui): the branch graph draws to the full height of its row
serialexperimentslainnnn Aug 20, 2026
0da0689
refactor(ui)!: both settings pages on the Kotlin UI DSL
serialexperimentslainnnn Aug 20, 2026
8982d37
feat(settings)!: the last plugin state moves into the IDE's safe
serialexperimentslainnnn Aug 20, 2026
0390f2b
fix(ui): the whitelist scope is a category and then a rule
serialexperimentslainnnn Aug 20, 2026
2c676be
feat(settings): export, import, and migrate from another IDE
serialexperimentslainnnn Aug 20, 2026
a1db3b2
fix(permission)!: the project boundary applies to shell commands too
serialexperimentslainnnn Aug 20, 2026
b4f85b8
feat(permission)!: refuse privilege escalation
serialexperimentslainnnn Aug 20, 2026
0d00c3f
docs: no comments in the code, and where the reasoning goes instead
serialexperimentslainnnn Aug 20, 2026
ed6b2d3
docs(permission): the alert log and the agent index share a drawer now
serialexperimentslainnnn Aug 20, 2026
a9362cb
chore: drop the project-map generator, the maps are hand-written now
serialexperimentslainnnn Aug 20, 2026
1f4c895
chore: stop descending into the local testing sandbox
serialexperimentslainnnn Aug 20, 2026
d37a575
test(permission): pin the refusal wording and the restored guard rows
serialexperimentslainnnn Aug 20, 2026
1211bc1
refactor: strip the comments out of the source
serialexperimentslainnnn Aug 20, 2026
d1f3d34
feat(permission): widen the destructive rules
serialexperimentslainnnn Aug 20, 2026
a2cd231
fix(permission): cap command length and fix three quadratic patterns
serialexperimentslainnnn Aug 20, 2026
0847607
fix(permission): expand home and env before the proxy-bypass check
serialexperimentslainnnn Aug 20, 2026
e020c66
feat(permission): add the anti-forensic detection rule
serialexperimentslainnnn Aug 20, 2026
0d89de7
feat(permission): add the cryptocurrency-miner detection rule
serialexperimentslainnnn Aug 20, 2026
1a27bfa
feat(permission): block inhibiting system recovery
serialexperimentslainnnn Aug 20, 2026
ab1a057
feat(permission): block container escapes to the host
serialexperimentslainnnn Aug 20, 2026
47872bb
feat(permission): extend anti-forensic to timestamp manipulation
serialexperimentslainnnn Aug 20, 2026
24adee5
feat(permission): cover WinRE and ESXi recovery inhibition
serialexperimentslainnnn Aug 20, 2026
64929b5
feat(permission): block network tunnels and anonymising proxies
serialexperimentslainnnn Aug 20, 2026
2830e8d
feat(permission): block disabling the host security defences
serialexperimentslainnnn Aug 20, 2026
dcefe29
feat(permission): widen VCS bypass detection, fix a false positive
serialexperimentslainnnn Aug 20, 2026
3ae0ae0
feat(permission): widen the blocked anonymous-service list
serialexperimentslainnnn Aug 20, 2026
2252f6f
feat(permission): widen container-escape to the full T1611 flag set
serialexperimentslainnnn Aug 20, 2026
68060f2
feat(permission): detect history and log clearing as anti-forensic
serialexperimentslainnnn Aug 20, 2026
1534039
feat(permission): detect process kills and driver unloads as evasion
serialexperimentslainnnn Aug 20, 2026
25b2537
feat(permission): widen resource-hijacking to more miners and Stratum V2
serialexperimentslainnnn Aug 20, 2026
954cf00
feat(permission): widen tunnelling to more pivots and VPN clients
serialexperimentslainnnn Aug 20, 2026
8283611
feat(permission): widen VCS-bypass to signing and hook overrides
serialexperimentslainnnn Aug 20, 2026
72d1e3c
feat(permission): widen inhibit-recovery to VSS and APFS snapshots
serialexperimentslainnnn Aug 20, 2026
8afa576
feat(permission): decode hex and reversed payloads before judging
serialexperimentslainnnn Aug 20, 2026
2479cb5
chore: ignore the assistant worktree directory
serialexperimentslainnnn Aug 21, 2026
1762103
fix(forge): identify the plugin and tell a rate limit from a denial
serialexperimentslainnnn Aug 21, 2026
ed6158f
feat(ui): notify when the guard refuses while you are looking elsewhere
serialexperimentslainnnn Aug 21, 2026
6333b68
test: pin the IDE's resolved dependency model as an inventory source
serialexperimentslainnnn Aug 21, 2026
fb78746
docs: say plainly what leaves the machine, and what does not
serialexperimentslainnnn Aug 21, 2026
d731e74
docs: add the 6.0.0 release notes
serialexperimentslainnnn Aug 21, 2026
0d0dd9a
docs(guard): stop promising a gate that is not there
serialexperimentslainnnn Aug 21, 2026
adba64c
feat(ui): add the guard log view
serialexperimentslainnnn Aug 21, 2026
e47227d
feat(vuln): add the dependency vulnerability view, consumer first
serialexperimentslainnnn Aug 21, 2026
8834817
docs: drop the emphasis the notes converter does not render
serialexperimentslainnnn Aug 21, 2026
2ddbd1c
fix(permission): cover OpenShift projects in the orchestration rule
serialexperimentslainnnn Aug 21, 2026
76b3795
fix(session): keep restored entries with the agent that produced them
serialexperimentslainnnn Aug 21, 2026
f7ed07d
feat(guard): make the guard log searchable and whitelistable
serialexperimentslainnnn Aug 21, 2026
e445eaa
feat(forge): read the whole page of runs, not just the newest
serialexperimentslainnnn Aug 21, 2026
a41747e
fix(ui): date the payload absolutely so unchanged pushes dedupe
serialexperimentslainnnn Aug 21, 2026
e164b88
fix(ui): reconcile the dashboard instead of rebuilding it
serialexperimentslainnnn Aug 21, 2026
71ed424
fix(agents): update an agent transcript in place instead of redrawing it
serialexperimentslainnnn Aug 21, 2026
7571a61
feat(git): give merge requests and pipelines a tab each
serialexperimentslainnnn Aug 21, 2026
747207f
feat(vuln): fill the scanner seam with a client for the OSV database
serialexperimentslainnnn Aug 21, 2026
ab0f6b2
fix(session): place a restored guard alert where it happened
serialexperimentslainnnn Aug 21, 2026
483e3fb
feat(guard): filter the log from a dropdown that ticks what you chose
serialexperimentslainnnn Aug 21, 2026
a98e4e7
feat(guard): let the log's retention be set, in days
serialexperimentslainnnn Aug 21, 2026
656799e
feat(vuln): filter findings by severity and plan the whole set at once
serialexperimentslainnnn Aug 21, 2026
c9a0b11
feat(vuln): send the update prompts into the project's own code
serialexperimentslainnnn Aug 21, 2026
352b4dd
feat(git): show every open merge request, not just this branch's
serialexperimentslainnnn Aug 21, 2026
4f03494
feat(forge): teach the client to write, and to say why it was refused
serialexperimentslainnnn Aug 21, 2026
f6aaa01
feat(forge): create the token from a button instead of guessing scopes
serialexperimentslainnnn Aug 21, 2026
818e65f
feat(forge): read what this account may actually do on this project
serialexperimentslainnnn Aug 21, 2026
6350983
feat(git): act on a merge request and a run from the panel
serialexperimentslainnnn Aug 21, 2026
315c87d
feat(git): widen the IDE actions and report what they did
serialexperimentslainnnn Aug 21, 2026
1ce0cd5
feat(git): ask Claude about a request or a failing run, safely
serialexperimentslainnnn Aug 21, 2026
ede3a2c
fix(git): make View diff work in the Git conversation
serialexperimentslainnnn Aug 21, 2026
c26190c
revert(git): drop the merge request and pipeline views
serialexperimentslainnnn Aug 21, 2026
768f700
feat(git): link out to the IDE's own request and log views
serialexperimentslainnnn Aug 21, 2026
8397b1d
docs(prompt): say the plugin note is context, not policy
serialexperimentslainnnn Aug 21, 2026
ec2a30e
refactor(vuln): give the OSV client an identity of its own
serialexperimentslainnnn Aug 21, 2026
60a0326
feat(git): drop the forge client, prune the view to the IDE
serialexperimentslainnnn Aug 21, 2026
409428d
fix(session): keep restored guard alerts in their own transcript
serialexperimentslainnnn Aug 21, 2026
9cc3018
test(ui): match the dashboard tests to the reconciling dashboard
serialexperimentslainnnn Aug 21, 2026
4d6f087
test(vuln): stop the report fixture ageing out of its own assertion
serialexperimentslainnnn Aug 21, 2026
c2a1e26
build: gate the vuln package on what a headless test can reach
serialexperimentslainnnn Aug 21, 2026
6808c6d
refactor: satisfy the gates on the reconciled work
serialexperimentslainnnn Aug 21, 2026
37064ca
fix(session): drop an unplaceable guard alert instead of piling it
serialexperimentslainnnn Aug 21, 2026
b0bfed8
style(ui): put the Plan button back at the end of the view row
serialexperimentslainnnn Aug 21, 2026
5814568
fix(guard): show an alert in the transcript that produced it
serialexperimentslainnnn Aug 21, 2026
856218d
fix(guard): give an agent's alert the same footer the chat's gets
serialexperimentslainnnn Aug 21, 2026
2be9c36
fix(guard): stop a restored agent alert appearing twice
serialexperimentslainnnn Aug 21, 2026
e8dcd67
fix(guard): record whose chat an alert belongs to when it fires
serialexperimentslainnnn Aug 21, 2026
a4fe8ac
chore(release): cut this release as 5.7.0
serialexperimentslainnnn Aug 21, 2026
a3bb7b3
fix(release): bump PLUGIN_VERSION to 5.7.0 to match the build
serialexperimentslainnnn Aug 21, 2026
3ff6632
feat(permission): see through obfuscation, judge more of what runs
serialexperimentslainnnn Aug 21, 2026
375e120
feat(permission): cover destructive and secret-revealing cloud commands
serialexperimentslainnnn Aug 21, 2026
d622268
fix(permission): keep a variable's value out of the refusal it causes
serialexperimentslainnnn Aug 28, 2026
edc06fc
fix(jcef): allow only our own pages to navigate, not only our own clicks
serialexperimentslainnnn Aug 28, 2026
17bb695
fix(settings): a file does not get to decide what the plugin executes
serialexperimentslainnnn Aug 28, 2026
9d8a3c1
fix(settings): put the execution-trust gate where the running happens
serialexperimentslainnnn Aug 28, 2026
1698e08
fix(settings): keep an until-IDE-closes relaxation in its own project
serialexperimentslainnnn Aug 28, 2026
f85fcdf
fix(permission): answer for every command in an input, not the first
serialexperimentslainnnn Aug 28, 2026
c48fa84
fix(permission): decide containment by the filesystem's own case rules
serialexperimentslainnnn Aug 28, 2026
de5be1e
fix(permission): resolve a variable properly, and judge a path by its…
serialexperimentslainnnn Aug 28, 2026
3522066
chore(build): make every release gate run and pass on this machine
serialexperimentslainnnn Aug 28, 2026
48139e4
docs(readme): say that the plugin installs the CLI for you
serialexperimentslainnnn Aug 28, 2026
eeeca30
chore(gitignore): ignore the subprojects directory
serialexperimentslainnnn Aug 28, 2026
8101028
chore(hooks): drop the local commit-message gate
serialexperimentslainnnn Aug 28, 2026
8d3c9b1
fix(jcef): stop a pending timer from reaching for a page that is gone
serialexperimentslainnnn Aug 28, 2026
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
64 changes: 0 additions & 64 deletions .githooks/commit-msg

This file was deleted.

4 changes: 2 additions & 2 deletions .github/dependabot.yml
Original file line number Diff line number Diff line change
Expand Up @@ -19,7 +19,7 @@ updates:
commit-message:
prefix: build # Conventional Commits — the commit-msg hook and the changelog both depend on it
include: scope
labels: [dependencies, ci]
labels: [dependencies]
groups:
# Every action here is pinned by full commit SHA, so a bump is a one-line SHA change per action and
# reviewing them one PR at a time buys nothing but pipeline runs.
Expand Down Expand Up @@ -126,7 +126,7 @@ updates:
commit-message:
prefix: build
include: scope
labels: [dependencies, ci]
labels: [dependencies]
groups:
security:
applies-to: security-updates
Expand Down
8 changes: 7 additions & 1 deletion .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -80,6 +80,7 @@
*.pyc
**/__pycache__/
*.log
subprojects/

# ==========================================================================================
# SECRETS AND KEY MATERIAL — LAST, and it must stay last.
Expand Down Expand Up @@ -131,4 +132,9 @@ secrets.yaml
# filename included. A leak has to stay an explicit mistake.
!/docs/trust-chain.asc
PROJECTMAP.md
**/PROJECTMAP.md
**/PROJECTMAP.md

# Anchored, because this holds whole checkouts: an assistant working in isolated worktrees puts them
# under .claude/worktrees/, and an unanchored pattern would also hide a real directory of that name
# somewhere in the tree. Committing it would commit a copy of the repository into the repository.
/.claude/
63 changes: 63 additions & 0 deletions CHANGELOG.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,6 +4,69 @@ All notable changes to this project will be documented in this file.
Format follows [Keep a Changelog](https://keepachangelog.com/en/1.1.0/).
Versioning follows [Semantic Versioning](https://semver.org/spec/v2.0.0.html).

## [5.7.0] — 2026-08-21

**The guard is now something you can see, tune and audit**, instead of a set of rules that only spoke up to
refuse something.

### Added
- **A Guard view in the chat's view row.** Every alert raised in this project: what matched, what the rule
saw, the verdict, and what let the call through if anything did. Free-text search, multi-select filters by
category and by rule, and a *Whitelist* button on any entry. Retention is configurable; capped at 500.
- **The guard keeps its alerts in the IDE's password safe, per project** — which is what makes the view
above possible, and what puts the guard's rows back when you reopen a chat. Each row returns anchored to
the call it judged, and an alert raised inside an agent is drawn in that agent's transcript, not the main
one. An *Allow All* given on a card comes back without its undo link: that approval died with the IDE.
- **A shield in the chat's button row**, left of auto-scroll: switches the guard to Allow All for a chosen
duration, and back with one click. Unlit whenever the guard is not deciding.
- **Settings ▸ Claude Code Security**, its own page: the guard's mode, a mode per rule with *All Enforcing* /
*All Permissive* per category, live suspensions you can end, extra credential globs, extra blocked domains,
and the whitelist at three reaches — all rules, one category, one rule. Any rule can be whitelisted;
credential and foreign-path rules ask for confirmation first.
- **A warning row whenever a rule matched and the call ran anyway.** It names the rule, what it saw and what
let it through, and carries the link that undoes it — including **Remove from whitelist**, which takes the
command off whichever of the three lists is letting it through, narrowest first.
- **A *Whitelist Command* link on a guard block**, beside *Disable rule*. Files the exact command under the
rule that refused it, and will not add a duplicate.
- **A Vulnerabilities view.** Checks your project's dependencies against a public advisory database
(OSV.dev) for known CVEs, filters by severity, and hands the findings to Claude to plan how to solve
them — reading your code and checking current advisories first, not just bumping a version.
- **Export, import and migrate settings**, including straight from another JetBrains IDE on this machine. An
exported file never carries your environment variables; a keychain-to-keychain migration does, because it
never leaves the machine. A permission mode that would weaken security is refused on the way in.

### Changed
- **Both settings pages rebuilt, and they now fit the window.** Titled groups instead of one column of forty
rows, with Tools, MCP and Advanced folded away; every note sits under its own field and re-wraps as you
resize. Nothing runs off the right edge any more.
- **The guard has a mode: Enforcing, Permissive or Allow All.** Enforcing refuses, Permissive asks on a card
every time, Allow All lets the call run. Rules take the first two and are Enforcing by default.
- **Settings are per project, per IDE installation.** Two repositories can disagree about the model, the
permission mode or a security rule. The login stays global, and signing out no longer wipes your settings.
- ***Always allow this command* on a guard alert is per chat, and in memory.** It was written to the settings
document, so one conversation answered for every other one, for ever. Revocable from that chat's ⚙ menu.
- **Every view redraws in place instead of from scratch**, so a filter, a scroll position or an open card
survives the transcript refreshing underneath it, and an agent's transcript no longer flickers as it runs.
- **The branch graph draws to the full height of its row.** An `<svg>` is a replaced element, so a tall row —
uncommitted changes with its file list, a commit carrying several ref tags — had its edge stop short of
the next commit and its dot sat below the junction.

### Security
- **Privilege escalation is refused**: `sudo`, `su`, `doas`, `pkexec`, `runuser`, `setpriv`, `run0`, the
desktop wrappers, `osascript` asking for administrator privileges, `runas`,
`Start-Process -Verb RunAs`, `psexec`, `wsl -u root`. Matched only where the payload **executes**, so a
file that documents `sudo apt update` trips nothing. Whitelistable per command.
- **The "outside the project" rule now sees paths inside shell commands.** It only ever read a tool's own
location argument, so `Read /home/you/notes.txt` was refused while `cat ~/notes.txt` was not — and the
shell is where the work happens.
- **Obfuscated payloads are decoded before they are judged** — hex and reversed strings.
- **Destructive orchestration covers OpenShift**: `oc delete project` alongside the `kubectl` equivalents.
- **Recovery inhibition covers VSS and APFS snapshots.**
- **A variable that decides which code runs is never an innocent declaration.** `PATH`, `LD_PRELOAD`,
`BASH_ENV`, `GIT_SSH_COMMAND` and their family are checked wherever they are set. Declaring a path is not
reaching it; expanding it is.
- **System binaries and inert devices are not reaches**: `/usr/bin/git status` and `2>/dev/null` still run.

## [5.5.0] — 2026-08-19

**This release needs IntelliJ Platform 2025.3.1 (build 253.29346.138) or newer.** On 2026.2 it is the fix:
Expand Down
24 changes: 24 additions & 0 deletions CLAUDE.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,29 @@
t# Project rules

## ⛔ NO COMMENTS IN THE CODE

**Do not write comments.** No KDoc, no block comments, no line comments, no docstrings — in any
language in this repository.

This overrides the general engineering habit of documenting rationale in place. It is a decision
taken for **this** project and it is not up for re-litigation: the plugin is small, the comments were
reaching **80% of the lines**, and the whole lot was stripped by hand once already. A codebase where
most lines are prose is harder to read, not easier, and the bloat is paid on every read by every
session.

Where the reasoning goes instead:

- **A name.** If a function needs a paragraph, it needs a better name or a smaller body.
- **A test.** A contract worth explaining is a contract worth asserting — that is what the contract
tests in `src/test/` are for, and an assertion cannot go stale silently.
- **The commit message.** Why a change was made belongs to whoever runs `blame` or `bisect`, and it
is already required to say so.
- **`docs/`** for anything a user or a maintainer has to know.

The only exceptions are text that is not a comment about the code: a licence header if one is ever
required, a machine-read pragma (`@Suppress`, `// noinspection`, a `MAP:GENERATED` marker), and the
`description` a tool renders to a user.

## ⛔ ABSOLUTE PROHIBITION — the plugin's security code is off limits

**Claude is CATEGORICALLY FORBIDDEN from modifying any code in this project that implements the
Expand Down
Loading