Your agent reads your email. Don't let it run what the email says.
clickfix-guard is a small open-source hook for coding agents. It checks every shell command before it runs and stops the common download-and-run moves. This page explains why it exists and what to do when it blocks something.
What just happened
Your agent tried to run something that came from a download, an email, a web page or an issue, and clickfix-guard stopped it. Content from those places is data, not a program for the agent to run.
Often the agent was simply following setup instructions it read somewhere. Sometimes those instructions were planted. The guard does not try to tell the two apart; it stops the move either way.
What to do
- If you, the human, really want it: read the script, then run it yourself in your terminal.
- If it is an official installer you trust, add it to ~/.config/clickfix-guard/allow.txt. In Claude Code the agent will then ask you instead of refusing; the allowlist never lets anything run on its own. The README shows the format.
- If you did not expect the agent to run anything, look at what it was reading when it tried. That text is the thing to distrust.
What ClickFix is
ClickFix is a phishing trick. A page or an email tells you to fix something (a broken captcha, a missing font, a failed update) by pasting a command into Terminal. The command downloads and runs malware. It is one of the main ways macOS stealers, such as the AMOS family, get installed.
Coding agents now read email, issues, READMEs and web pages, and they are good at following setup instructions. The same trick works on them, with no human in the loop to hesitate. Now the agent does the pasting.
Researchers have shown it against a coding agent. In 0DIN's proof of concept against Claude Code (June 25, 2026), a repository's README led the agent to a setup script, and that script fetched a reverse shell from a DNS TXT record.
clickfix-guard would not have stopped that exact chain. The payload was fetched inside a script, into a variable, and a command-line check does not see that. The guard stops the common direct moves: the pasted one-liner, the downloaded script, the installer, the quarantine strip.
What it blocks, and what it is not
Blocks
- A download piped into a shell or interpreter: curl ... | bash, wget -qO- ... | python3, bash <(curl ...).
- A download, then running the same file.
- Files macOS flagged as downloaded (com.apple.quarantine), even after they were copied elsewhere.
- Running files from the Downloads folder.
- Gatekeeper bypass: xattr -d com.apple.quarantine, spctl --master-disable.
- Installers and disk images: installer -pkg, hdiutil attach, opening a .dmg.
- AppleScript shell escapes: osascript do shell script.
Is not
- Not a sandbox. It reads the command line. An agent that knows it exists, or a script written to disk and run later, can get past it.
- Not phishing protection in general. It does not stop an agent typing a password into a fake page, sending data out, or paying a fake invoice.
- Layer it. For sessions that read untrusted input, also use your agent's own sandbox.
Source and full rules: better-isms/clickfix-guard on GitHub. What gets past it today: KNOWN-BYPASSES.md.
Install
/plugin marketplace add better-isms/clickfix-guard
/plugin install clickfix-guard@clickfix-guardCodex and Grok: see the README.
There is deliberately no curl-pipe-bash installer. Clone with git, read the script (one bash file), and pin a tag.