--- description: Show what ctxguard has been blocking and substituting --- ``` python3 "${CLAUDE_PLUGIN_ROOT}/scripts/ctxguard.py" audit -n 40 python3 "${CLAUDE_PLUGIN_ROOT}/scripts/ctxguard.py" status ``` The audit log records rule ids, tool names and aliases — never plaintext, so it is safe to read inside a session. Read it for false positives: a rule that keeps firing on harmless content is a rule that will get the whole plugin switched off. Fixes, in order of preference: add the value to `allowlist` / `allowlist_substrings` in `policy.json`, narrow the rule, or add it to `disabled_secret_rules`.