Golden Thread's security is three layers you control: a level that decides what Claude may run without asking, your fingerprint on the actions that matter, and every protection as its own switch. Everything below comes from gt's own settings registry.
/gt:gt-settings lockdown <level>Set my security level to trust local.
Switch me to paranoid.
gt writes only its own allow rules into Claude Code's settings, backs the file up first and logs every change. The levels cut prompts; they are not a wall around your computer. Open any level.
/gt:gt-settings lockdown strict/gt:gt-settings lockdown trust-local/gt:gt-settings lockdown trust-network/gt:gt-settings lockdown insecure/gt:gt-settings lockdown paranoidNot sure? Choose trust-local. It removes the prompts for looking at things and running tests, which people click through without reading, and keeps every prompt that matters: the network, installs, deletes and pushes.
gt_unlock.py enroll touchidHelp me set up gt unlock with Touch ID.
Turn on gt unlock.
enroll totp).gt_unlock.py enroll touchidgt_unlock.py policy enablegt_unlock.py statusAdd push_fingerprint for a fingerprint before every push from the repos you name, and commit_fingerprint to have every commit signed by a key in your Mac's Secure Enclave. Both are in the switches below.
/gt:gt-settings <name> <value>Turn on sandbox mode.
Require my fingerprint before every push.
What "follow" means: a Paranoid part or a single-use permit set to follow does whatever its parent switch says. Every Paranoid part follows paranoid, and every permit follows paranoid.action_tokens, which follows paranoid. Set a part to on or off only to override its parent.
The level is a starting point, not a package. Change any switch below and the panel writes the commands for your custom setup. Each is one command, any time; with gt unlock on, loosening one needs you present.
unlockgt unlock: agents need your presence (TOTP + Touch ID / Windows Hello) for LOTR, secrets, publishing and gt's guards.
default off · options: off | onpush_fingerprintA fingerprint (gt unlock step-up) before every git push from the repos in push_fingerprint_repos.
default off · options: off | onpush_fingerprint_seal_tokenWith push_fingerprint on, also seal the GitHub push token behind gt:publish (the lock).
default off · options: off | oncommit_fingerprintA fingerprint on every commit: a Secure Enclave key signs it (gt_sign.py), in the repos in push_fingerprint_repos.
default off · options: off | onaccept_reviewHow an accept of a #conflict version is reviewed: only the presence dialog, or the whole change shown first and bound to its hash.
default dialog · options: dialog | fullsandbox_modegt sandbox mode: fence Claude's shell and file tools off the vault and gt's state; reach the vault through gt's MCP and write queue.
default off · options: off | onsandbox_vault_readsUnder sandbox mode, whether Claude's shell and file tools may also READ the vault.
default deny · options: deny | allowprotected_pathsPrompt before Write/Edit to core-rules, global-memory, local packs, gt hooks or settings.json; refuse overwriting a Source.
default ask · options: off | asksymlink_writes_outside_vaultWhether a vault tool may append through a link that points OUTSIDE the vault.
default refuse · options: refuse | allowtest_gateRefuse a `git commit` of code whose tests have not been seen to pass.
default auto · options: off | warn | auto | blockcommit_checksRefuse a `git commit` whose staged content no passing gt_check.py run covers.
default off · options: off | onforeign_checkout_guardDeny git commit/push inside a checkout you declared as another machine's.
default on · options: off | onparanoidLock gt's installed code so it cannot be changed behind your back.
default off · options: off | onparanoid.os_lockParanoid part: OS lock on installed gt files.
default off · options: off | on | followparanoid.code_write_gateParanoid part: presence check before the code is unlocked.
default off · options: off | on | followparanoid.bash_guardParanoid part: guard for shell commands that write to that code.
default off · options: off | on | followparanoid.signed_manifestParanoid part: signed list of the code, checked before each hook runs.
default off · options: off | on | followparanoid.plugin_dirsParanoid part: plugin cache and marketplace under protected paths.
default off · options: off | on | followparanoid.require_unlockParanoid part: refuse to turn paranoid on until unlock is set up.
default off · options: off | on | followparanoid.action_tokensSingle-use action tokens: the master for every action below.
default off · options: off | on | followparanoid.action_tokens.disk_readSingle-use token for disk_read: one disk_read of one file.
default off · options: off | on | followparanoid.action_tokens.disk_listSingle-use token for disk_list: one disk_list of one folder.
default off · options: off | on | followparanoid.action_tokens.net_fetchSingle-use token for net_fetch: one net_fetch of one URL.
default off · options: off | on | followparanoid.action_tokens.disk_writeSingle-use token for disk_write: one disk_write of exact content to one path.
default off · options: off | on | followparanoid.action_tokens.lotr_readSingle-use token for lotr_read: one LOTR call_read (connection + op + args).
default off · options: off | on | followparanoid.action_tokens.lotr_writeSingle-use token for lotr_write: one LOTR call_write.
default off · options: off | on | followparanoid.action_tokens.lotr_consentSingle-use token for lotr_consent: one LOTR call_consent (consent is still asked as well).
default off · options: off | on | followparanoid.action_tokens.vault_readSingle-use token for vault_read: one gt-vault vault_read, vault_search or vault_list.
default off · options: off | on | followparanoid.action_tokens.vault_writeSingle-use token for vault_write: one queued vault write or batch, or one vault operation tool call.
default off · options: off | on | followparanoid.action_tokens.secrets_unsealSingle-use token for secrets_unseal: one secret unseal through gt unlock.
default off · options: off | on | followparanoid.action_tokens.git_pushSingle-use token for git_push: one git push (repo + refs).
default off · options: off | on | followparanoid.action_tokens.git_commitSingle-use token for git_commit: one git commit (repo + tree hash).
default off · options: off | on | followparanoid.action_tokens.publishSingle-use token for publish: one release publish step.
default off · options: off | on | followparanoid.action_tokens.grant_addSingle-use token for grant_add: creating one timed grant.
default off · options: off | on | followparanoid.action_tokens.plan_boundSingle-use token for plan_bound: one confirmation that mints an approved plan's tokens up front.
default off · options: off | on | followio_toolsOffer the I/O brokers' tools (disk_read / disk_list / net_fetch) in the gt-vault MCP server, whatever vault_mcp says (0.21.0; on by default).
default on · options: on | offio_write_presenceEvery disk_write needs a fresh confirmation (or a live timed grant for that repo); this cannot be switched off (0.21.0, item #20 stage 3).
default on · options: onio_write_ciWhether disk_write may write CI workflow files (.github/workflows and the like); only you can lift it (0.21.0, item #20 stage 3).
default never · options: never | allowio_read_allowFolders the disk-read broker (disk_read / disk_list) opens without a prompt, beside the vault and every project's source.md repo (0.21.0).
default empty · options: a list you chooseio_fetch_allowDomains the network-fetch broker (net_fetch) opens without a prompt (subdomains included); also where the owner lists localhost or a private address on purpose (0.21.0).
default empty · options: a list you chooseio_read_max_bytesThe most one disk_read call returns (default 1048576 = 1 MB); a bigger file is paged with next_offset (0.21.0).
default 1048576 · options: a list you chooseio_fetch_max_bytesThe most one net_fetch call returns (default 1048576 = 1 MB); the rest is dropped and the result says truncated (0.21.0).
default 1048576 · options: a list you chooseio_write_max_bytesThe most one disk_write call writes (default 1048576 = 1 MB) (0.21.0).
default 1048576 · options: a list you choosecomponent_updatesWhat to do when INSTALLED hooks/scripts differ from what is checked in.
default report · options: off | report | confirm | autoaddon_fixesWhat happens to the fixes a checker proposes: ignored, listed for you, or applied.
default propose · options: off | propose | applyagent_splitLOTR agents: separate reader and writer agents (split), or one read/write agent per task (combined).
default split · options: split | combined