Chock policies as Cursor plugins — guard policies ship a real beforeShellExecution deny hook.
An agent running in your editor can already touch your shell, your git history, and your CI
config. You want it to move fast without being the reason a stray terraform destroy
actually happens. Telling it to be careful in a prompt is not a guarantee; a plugin that can
refuse the command is closer to one — a matched destructive command is denied in the editor
before it runs, witnessed on a real Cursor install (2026-08-24), with benign commands in the
same session still allowed.
Cursor reads this repository as a plugin marketplace via .cursor-plugin/marketplace.json:
# Team marketplace: Dashboard -> Plugins -> Add Marketplace -> Import from Repo
# https://github.com/open-coder-ai/chock-cursor-plugins
# Local install of one plugin (developer flow):
# copy cursor/<plugin-id>/ to ~/.cursor/plugins/local/<plugin-id>/ and reload Cursor
Guard policies ship the hook, a guard script, and a stdlib-only adapter, and are
session-enforced: the hook returns Cursor's permission: "deny" response and the command is
refused. This needs python3 and a usable bash on PATH — without them the hook fails
open, and every guard's description says so verbatim. Advisory policies are a skill the
client reads; nothing stops a violation. See PLUGINS.md for the full list:
each policy, its version, and whether it enforces or advises in this client.
Every file here is compiled from policy sources in chock-catalog by chock. Pull requests against this repository are closed automatically — open them against the catalog instead.
- Generated only: CI regenerates from the pinned catalog and fails on any difference.
- Byte-identical guards: guard scripts and the hook adapter are verbatim copies of their framework sources.
- Best-effort, not a boundary: guards are pattern-based filters; see SECURITY.md.
- Tested upstream, and gated: every policy ships an eval suite
(
base/<policy>/evals/suite.yaml) in the catalog, and the publish workflow runschock checkandchock check --only evalsbefore packaging anything — a policy whose evals fail cannot reach this repository. The tests live in the catalog because the policy source does; this repository is compiled output. - This README is the exception: the one hand-written file in this repository, so it alone sits outside the generated-only guarantee.
Nothing above asks for trust that cannot be checked. This rebuilds the published tree from source and compares it with what is committed here:
git clone https://github.com/open-coder-ai/chock-cursor-plugins dist
git clone --branch v0.7.0 https://github.com/open-coder-ai/chock framework
git clone https://github.com/open-coder-ai/chock-catalog catalog
pip install ./framework
chock plugin build --repo catalog --policies-dir base --format cursor --out-dir dist
chock marketplace build --dist dist --tree cursor
git -C dist diff --exit-code && git -C dist status --porcelainSilence from both git commands means this repository is byte-identical to a fresh build
from the catalog. --branch v0.7.0 is the framework release this tree was published from.
chock-market.lock records a sha256 per published plugin directory, so one package can be
checked without rebuilding the rest.
If you are listing these plugins in a marketplace, pin both a tag and the full commit SHA. The tag names the release; the SHA is what holds the reviewed bytes still.
| You want to | Go to |
|---|---|
| Fix or add a policy | chock-catalog — it reaches every client from there, including this one |
| Report that a guard did or did not block on your Cursor version | an issue on chock, which records the witnessed-blocking claims these packages carry; "it fails open where you say it fails closed" is the most useful result you can send |
| Report a bug in how packages are generated | chock, where the emitter lives |
| Fix this README | here — it is the one hand-written file in the repository |
| agentseam | the primitives — one handler API and a verified capability matrix across 16 agents |
| chock | the compiler — one policy into git hooks, CI gates and native pre-tool hooks |
| chock-catalog | the policies — 39, each labelled enforced or advisory, with replayed evals |
| context-report | the evidence — a signed report of whether an agent artifact actually works |
| chock-threat-intel | the threat ledger the catalog's policies answer to |
| chock-{claude,cursor,copilot,codex}-plugins | the catalog, packaged for each agent's plugin format (generated) |
| chock-quickstart · chock-example | template repos: what chock init leaves behind, and a full adoption |
Apache-2.0, same as the framework and the catalog.
