{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=lgoyal6/guard-effectiveness@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"People install hooks and permission rules to stop an agent doing something, and then nobody checks whether the guard actually stops it, or what it does instead. This reconciles three answers for every guard configured on a machine, and the gap between them IS the finding. WHAT IT DECLARES: PreToolUse and PostToolUse hooks with their matchers and timeouts, across Claude Code user, local, project and enterprise settings and every installed plugin's own hooks.json, plus permissions allow/deny/ask rules and the readable approval keys in a Codex config.toml. WHAT IT CAN ACTUALLY DO, read out of the hook script's own SOURCE: does it ever emit deny, only ask, only allow, or nothing at all; does an exception path exit 0 without deciding and so fail OPEN; is the deny it does contain sitting behind a flag the configured command never passes; does its matcher regex match any tool name the harness dispatches. WHAT IT ACTUALLY DID: session transcripts record every hook firing structurally - the command, the event, the exi","distribution":{"digest":"sha256:921920e16d4915b399ed5ac9c3ef51d4b8aaeb66f12a8190c44767caa1383173","mediaType":"application/vnd.modiqo.rote-flow","size":49106,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0.json"},"name":"guard-effectiveness","owner":{"kind":"user","slug":"lgoyal6"},"parameters":[{"description":"Absolute directory to search for project-scoped guard declarations (.claude/settings.json, .claude/settings.local.json). A process.exec step runs in rote's own workspace, not the caller's shell, so a relative path would scan rote's workspace, find no project-scoped settings anywhere, and report a confident clean about the wrong tree; a relative value is refused with exit 2 and a message naming the fix.","example":"/Users/you/src","input":{"allowCustom":true,"choices":[],"label":"Root"},"name":"root","required":true,"type":"string"},{"description":"Absolute path to the home directory holding the harness config and the session transcripts (.claude/, .codex/). Empty means \u0024HOME. Absolute for the same reason as root, and refused if relative.","example":"/Users/you","input":{"allowCustom":true,"choices":[],"label":"Agent home"},"name":"agent_home","required":false,"type":"string"},{"default":"4","description":"How many directory levels below root to search for project-scoped settings files. Larger values cost time on a big tree and change nothing about the user-level guards.","example":"3","input":{"allowCustom":true,"choices":[],"label":"Depth"},"name":"depth","required":false,"type":"string"},{"default":"0","description":"Only read session transcripts modified within this many days. 0 reads all of them, which is the honest default because a narrow window makes a guard that fired last month look like a guard that never fired - the single most costly false positive this play can produce.","example":"30","input":{"allowCustom":true,"choices":[],"label":"Since days"},"name":"since_days","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/lgoyal6/guard-effectiveness@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.79.0"},"publishedAt":"2026-09-04T08:45:04.302168+00:00","reference":"lgoyal6/guard-effectiveness@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["bash","python3","find","wc","tr","mktemp","rm"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":1,"installs":0},"steps":{"count":3,"names":["analyze","discover","verify"]},"title":"guard-effectiveness","type":"play","version":"0.1.0","visibility":"public"}