Deep Field Labs
Guardrails for AI coding agents
Free, open-source plugins for Claude Code that stop API keys leaking, warn before destructive commands, and keep code on the versions you actually run. We built them for our own work. Use them as they are, or have us set them up for your team.
Agents open new ways for things to go wrong. These close the ones we kept running into.
Keys stay on your machine
Blocks API keys and passwords in prompts, file writes, commits, web requests and tool calls before they leave. Logs anything exposed, with a link to rotate it. Stores fingerprints only, never the keys.
See what a command will do
Scores every shell command for risk. Before a destructive one runs, you see it in plain English, such as "deletes 312 files, 2 not tracked by git", and a recovery point is saved first.
Code for the versions you have
Reads your lockfile so the agent writes for the library versions you actually have installed, and flags deprecated APIs as they're written, not after the build breaks.
Seven more in the same repository: spend tracking, review digests, session notes, onboarding docs, prompt tests, proof behind "done", and safe document editing. MIT licensed, no tracking, no network calls.
# in Claude Code
/plugin marketplace add deepfieldstudios/deep-field-labs
/plugin install secret-shield@deep-field-labs
Fixed price, agreed before we start. Scope moves, the rate doesn't.
Agent guardrails setup
For teams starting to use Claude Code who want it safe from day one.
- Guardrail plugins installed and tuned to your stack
- Team permission rules and project instructions written for your repos
- Secret handling reviewed: what agents can see, and where keys should live
- One hour with your team on working safely with agents
Or email us. The price is fixed on the first call, which is free.
AI for your files, set up safely
For businesses that live in spreadsheets and documents and want AI to help without risking the only copy.
- Claude set up so every document is saved before it's changed
- Three workflows built for jobs you do every week, such as reconciling, list clean-up or contract changes
- Changes explained in plain words, and anything can be undone
- One hour of training for you and your team
Or email us. The price is fixed on the first call, which is free.
The plugins protect one machine. Teams need to see across all of them.
- One secrets register. Every key exposed to an agent, across the team, with who rotates it and when.
- One policy. Set the rules once and every developer's agent follows them.
- An audit trail. Evidence of what agents were allowed to do, ready for a security review.
Only fingerprints and metadata ever leave a machine. Never code, prompts or keys.
Join the founding list
We're building this with a small group of teams. Tell us how many developers you have and what you'd need it to do, and you'll get early access.
Join by emailOr book a call to talk it through.
Using agents on real work?
Start with the free plugins. Call when you want it done properly across the team.