Repository snapshot does not include a lockfile.
pawl
Deterministic hooks for Claude Code, Codex, and Antigravity that gate destructive commands, credential access, outbound messages, and repeated tool calls using Python's standard library
ulukaya/pawl · v0.4.1 · Development & Workflow
Trust Score
87
Security
95
Surfaces
1
What is pawl?
pawl is a published development & workflow plugin for AI coding agents in the codex ecosystem, developed by Ulukaya and distributed through the HOL AI plugin registry. Deterministic hooks for Claude Code, Codex, and Antigravity that gate destructive commands, credential access, outbound messages, and repeated tool calls using Python's standard library
- Canonical slug
- ulukaya/pawl
- Version
- v0.4.1 · updated Oct 7, 2026
- Open data
- entity.json (JSON-LD)
Trust & Reputation
Factor Analysis
Per-metric points (0–100 each) combined via a weighted average into the overall score.
Registry Snapshot
- Repository
- https://github.com/ulukaya/pawl
- Homepage
- https://github.com/ulukaya/pawl
- Canonical profile
- https://hol.org/registry/plugins/ulukaya%2Fpawl
- Publisher verification
- No
- Marketplace source
- Unknown
- Scanner
- Broker fallback
- Safety label
- safe
- Digest verified
- Yes
Trust & reputation
Trust & Reputation
Factor Analysis
Per-metric points (0–100 each) combined via a weighted average into the overall score.
Provenance
- Plugin root
- .
- Source repo
- https://github.com/ulukaya/pawl
- Source commit
- 5af1ad360770…
- Publisher verified
- No
- Owner verified
- @ulukaya
Scanner CI check is still running
No action is required. This listing will update after the catalog rechecks scanner CI.
README badge check is still running
No action is required. This listing will update after the catalog rechecks the source README.
Security Posture
- Provider
- registry-broker-fallback
- Grade
- A · safe
- Version
- Unknown
Findings
Cisco skill scanner timed out after 60000 ms
pawl — Frequently asked questions
- What is pawl?
- pawl is an AI plugin in the HOL registry. Deterministic hooks for Claude Code, Codex, and Antigravity that gate destructive commands, credential access, outbound messages, and repeated tool calls using Python's standard library
- How do I install pawl?
- Install pawl in your harness: Codex — codex plugin marketplace add ulukaya/pawl; Claude Code — /plugin marketplace add ulukaya/pawl; Any agent — npx skills add ulukaya/pawl. Full step-by-step guidance is on the HOL plugin page.
- How do I install pawl in Codex?
- To install pawl in Codex, start with codex plugin marketplace add ulukaya/pawl. The complete step-by-step install guide for Codex is on the HOL plugin page.
- How do I install pawl in Claude Code?
- To install pawl in Claude Code, start with /plugin marketplace add ulukaya/pawl. The complete step-by-step install guide for Claude Code is on the HOL plugin page.
- Is pawl free?
- Pricing for pawl is published on its HOL plugin page when the maker schedules a launch.
- Who publishes pawl?
- pawl is published by Ulukaya and listed on HOL.
- Is pawl available now?
- pawl availability is listed on its HOL plugin page.
Install Guidance
Install in Claude Code
Install through the Claude Code plugin marketplace.
- 1
Add the marketplace
Run this inside a Claude Code session.
claude code - 2
Install the plugin
Use the plugin name and the marketplace name shown by the previous command.
claude code - 3
Scripted alternative
Non-interactive equivalent for scripts and CI pipelines. Add --scope project to pin the install to one repository.
shell
Plugin Manifest
{
"name": "pawl",
"version": "0.4.1",
"description": "Deterministic gates for coding agents: stops deleting home, root or drives (even from inside scripts), destructive git, unbounded waits, repeated tool calls, no-op edits, transcript re-reads, cross-conversation snooping and leaky or bot-sounding sends; strips zero-width characters; approves provably read-only shell commands. Plain Python, no model calls, no prompt cost.",
"license": "Apache-2.0",
"keywords": [
"safety",
"guardrails",
"hooks",
"git",
"deterministic"
],
"skills": "./",
"hooks": "./hooks/codex.json",
"interface": {
"displayName": "pawl",
"developerName": "Ulukaya",
"shortDescription": "Deterministic gates for coding agents",
"longDescription": "Deterministic gates for coding agents: stops deleting home, root or drives (even from inside scripts), destructive git, unbounded waits, repeated tool calls, no-op edits, transcript re-reads, cross-conversation snooping and leaky or bot-sounding sends; strips zero-width characters; approves provably read-only shell commands. Plain Python, no model calls, no prompt cost.",
"category": "Coding",
"websiteURL": "https://github.com/ulukaya/pawl",
"privacyPolicyURL": "https://github.com/ulukaya/pawl/blob/main/PRIVACY.md",
"termsOfServiceURL": "https://github.com/ulukaya/pawl/blob/main/LICENSE",
"defaultPrompt": [
"Which pawl gates are active, and what does each one stop?",
"Explain why pawl asked before my last command."
],
"logo": "./assets/logo.svg"
},
"repository": "https://github.com/ulukaya/pawl",
"holManifestOrigin": "repository",
"registryIndexVersion": 5
}Marketplace Source
- Repo URL
- https://github.com/ulukaya/pawl
- Marketplace path
- Unknown
- Source path
- .
- Install policy
- Unspecified
Skills
1 SKILL.md file ship with this plugin. Preview, copy, or download each one, then install them with the Skills CLI.
pawl
skills/pawl/SKILL.md
Deterministic gates for agent harnesses. Use when a call is denied, prompted or blocked with a [PAWL blast|egress|prose|budget|git|pin|teardown|tamper|poll|loop|no-op|reread|fence|creds|verify] or [IDLE TASK] reason, or before sending a message, discarding git work, installing from a URL, waiting on a background task, fixing a bug with a reproducer, or growing an always-loaded prompt file.
SKILL.md content is not in this snapshot. Open the raw file to copy it from the source repository.
File Inventory
.claude-plugin/plugin.json
file
2,365 bytes
8b96084181eeee00…
.codex-plugin/plugin.json
plugin-manifest
1,538 bytes
35801b71741b5d56…
AGENTS.md
file
2,058 bytes
b6a51fae0faacdf2…
assets/logo.svg
asset
1,511 bytes
8e993fdd5ca7d3c6…
CLAUDE.md
file
11 bytes
336cc4fbf19beaad…
hooks/child_env_test.py
file
2,062 bytes
00db9a63fe20e30e…
hooks/child_env.py
file
1,261 bytes
0f4d544030a45d03…
hooks/codex_gates_test.py
file
8,832 bytes
6f382b0ab228d89f…
hooks/codex.json
file
705 bytes
9fb51d3fd0f9fe70…
hooks/demo_test.py
file
6,896 bytes
f1b0be4442892504…
hooks/demo.py
file
13,323 bytes
7d1253c0e86da5ab…
hooks/e2e_test.py
file
16,856 bytes
7c45aa75b4bb4211…
hooks/egress_heredoc.py
file
4,659 bytes
d55bbcfc69882a6f…
hooks/egress_payload_test.py
file
2,948 bytes
5cecfe2efea89597…
hooks/egress_payload.py
file
12,737 bytes
6c7a5accaaca98ab…
hooks/egress_rules.default.json
file
659 bytes
512a1cd5b4d2ed4d…
hooks/egress_scope_test.py
file
20,026 bytes
c54514131d269efc…
hooks/egress_scope.py
file
2,467 bytes
3e866340d6294ad4…
hooks/egress_shell.py
file
13,821 bytes
ae1fa2a2f2a6a4f1…
hooks/gates.py
file
10,198 bytes
8110a1e5edb2c405…
hooks/guard_hooks_test.py
file
8,377 bytes
2307ea34953f016d…
hooks/harness_test.py
file
12,938 bytes
f452330c0fb1c833…
hooks/harness_vocab.py
file
3,636 bytes
34913adfa37913f4…
hooks/harness.py
file
12,371 bytes
672213a1e8221ab5…
hooks/heredoc_gates_test.py
file
8,120 bytes
1fe8cf89a99dd147…
hooks/hooks_test.py
file
15,711 bytes
8d52484aa6c46a95…
hooks/hooks.json
file
609 bytes
58c41fc24aeebf44…
hooks/oscillation_stop_test.py
file
2,379 bytes
20cae6b3b3deb414…
hooks/other_hooks_test.py
file
9,399 bytes
669ae40778b10b99…
hooks/pawl_test.py
file
4,481 bytes
411e721471d117d5…
hooks/pawl.py
file
12,345 bytes
d2bf752f8a7df9e8…
hooks/py_body.py
file
6,391 bytes
678ae6839ef580a5…
hooks/replay_test.py
file
10,632 bytes
f233aeb0fb4a5f7d…
hooks/replay.py
file
10,995 bytes
6410dd099a557ad5…
hooks/send_gates_test.py
file
3,606 bytes
89e8bb10162a284a…
hooks/send_gates.py
file
12,591 bytes
0cb3c7e798e34f2a…
hooks/shell_view_test.py
file
11,521 bytes
d66950e475731da2…
hooks/shell_view.py
file
15,072 bytes
fb0b6d28362a3eb5…
hooks/verify_hooks_test.py
file
1,512 bytes
92f2e1ce967f8958…
plugin.json
file
1,167 bytes
cb54b27527472566…
README.md
file
26,487 bytes
29c4a543427e5f84…
SECURITY.md
file
1,466 bytes
96e9d83e3e808e4d…
skills/pawl/references/bite-check.md
skill
713 bytes
a2bbbb215dfc0103…
skills/pawl/references/blast-radius-guard.md
skill
1,396 bytes
eaa2b885394e159e…
skills/pawl/references/check-tamper-guard.md
skill
1,693 bytes
2611b7170bd2d6a2…
skills/pawl/references/circuit-breaker.md
skill
743 bytes
41ac98fa39e57d08…
skills/pawl/references/conversation-fence.md
skill
1,723 bytes
e813cba2eb7ca32c…
skills/pawl/references/credential-fence.md
skill
1,415 bytes
98cbca17ff9ae4b0…
skills/pawl/references/destructive-git-guard.md
skill
2,094 bytes
d46a99f52e37fa1e…
skills/pawl/references/egress-firewall.md
skill
658 bytes
3eb89cd54a2ac5f0…
skills/pawl/references/idle-task-gate.md
skill
1,256 bytes
23d8c153e811d2c4…
skills/pawl/references/install-pin-guard.md
skill
1,191 bytes
3b106f3fb6aa9ff0…
skills/pawl/references/noop-edit-guard.md
skill
1,112 bytes
821396c752774df8…
skills/pawl/references/oscillation-breaker.md
skill
1,766 bytes
18c9aa8c3ca7825e…
skills/pawl/references/poll-loop-guard.md
skill
1,377 bytes
c10673dcde37cd76…
skills/pawl/references/prompt-budget.md
skill
524 bytes
d3d2c0ac397ec782…
skills/pawl/references/prose-gate.md
skill
747 bytes
c0259691489c6390…
skills/pawl/references/ratchet.md
skill
582 bytes
069cdf26ad0252e5…
skills/pawl/references/readonly-pass.md
skill
2,280 bytes
2df73d15c6fc6246…
skills/pawl/references/report.md
skill
651 bytes
f5f4345ce3dc09b3…
skills/pawl/references/repro-fence.md
skill
550 bytes
c236b13f728406bf…
skills/pawl/references/reread-guard.md
skill
1,351 bytes
472fcde403908e69…
skills/pawl/references/send-budget.md
skill
1,086 bytes
506c36fe65abfc9b…
skills/pawl/references/send-gates.md
skill
4,036 bytes
84d962a27183369e…
skills/pawl/references/teardown-guard.md
skill
1,899 bytes
2811de62cdf8639f…
skills/pawl/references/verify-gate.md
skill
1,167 bytes
90b8cc84f99d229c…
skills/pawl/references/zero-width-sanitizer.md
skill
1,074 bytes
df3a346f600a26d3…
skills/pawl/SKILL.md
skill
5,047 bytes
61b41880e06ee4e9…