← Blog
AGENTS4 min read

Working rules that used to be prose now run as a Claude Code mod

Oct 9, 2026DekimuAI-generated

Two Claude Code mods in our monorepo now enforce working rules that used to be prose in a markdown file. dekimu-harness denies destructive commands, holds app-repo merges and deploys for a Telegram tap, and routes review agents to the top model tier. merge-sentinel refuses a merge until every workflow run on the pull request's head commit has finished green.

Why move a rule out of the instructions file?

An instructions file is read once, at the start of a session, by a model that may or may not weigh it against the command in front of it. A hook inside the tool runs on every call. The destructive-op gate, the commit-boundary review trigger and the .env edit guard each existed first as a Python settings hook or a paragraph of CLAUDE.md; the mod, which first merged on October 8, puts them in one place that loads the same way everywhere.

Mods arrived in Claude Code 2.1.287. They run in the terminal, the VS Code extension and headless claude -p lanes, which matters because our scheduled automation uses the last of those.

What does the tap gate hold?

A merge or push to main in an app repo, an npm publish, a GitHub release or a production deploy is held until the founder taps Approve on a Telegram card. The command has to lead with a short reason, which becomes the card's text; without one, the call is denied along with the protocol for adding it.

Everything unreadable denies. A rejection, an expired card or a state the mod cannot parse all end the same way, and each card id is unique per invocation so an earlier approval can never be inherited by a later command. The monorepo itself is deliberately not carded.

Prose about a command is not a command.

That line is from the mod's own scanner notes, and it shaped the matcher: quoted text and heredoc bodies are stripped before a command is checked, so a commit message that mentions rm -rf does not trip the gate.

How does merge-sentinel decide a PR is ready?

It reads the pull request, then lists every workflow run on the head commit. The merge goes through only if the PR is open, not a draft and mergeable, and every run is completed with a success, skipped or neutral result. A queued re-run, a still-pending Vercel status or a run that has not yet registered all hold the merge, with the reasons printed.

It also refuses git worktree add with a relative path, because a loop that resolved .worktrees after a cd once created nested checkouts across a set of sibling repos. The allowed shape is an absolute path under the repo root's own .worktrees directory. The v0.1.1 release went through three adversarial review cycles and ships with 27 tests.

What this does not do

A mod runs unsandboxed as the user, so ours are reviewed by pull request and loaded by path, never installed from a marketplace. merge-sentinel is a guardrail against honest mistakes, not a boundary: a command wrapped in bash -c is invisible to it, and the README says so. The older Python hooks stay wired in parallel until the mod has a clean week of sessions.

AGENTS

This post was drafted by an AI system from Dekimu's public engineering record and published with automated checks, without per-post human editing.

← Back to blog
Working rules that used to be prose now run as a Claude Code mod — Dekimu Blog