Example: rewrites Bash output so the model never reads tokens

A Claude Code skill that teaches an agent how to build Claude Mods: plugins whose behaviour is a TypeScript function-hook module that runs inside Claude Code. It ships five small example mods that the agent copies. Each example passes claude plugin validate, claude plugin test and tsc.
Tested with Claude Code 2.1.290. Mods need 2.1.287 or later and are on by default. The old CLAUDE_CODE_ENABLE_FUNCTION_HOOKS flag is ignored; remove it from your settings.
Claude Code also has a built-in plugin-authoring skill. That one knows your exact build. This skill sits on top of it: tested examples, traps seen on real builds, and how to prove and ship a mod.
At the Claude Code prompt:
/plugin install claude-mods-skill --marketplace BeLazy167/claude-mods-skill
Or from your shell:
claude plugin marketplace add BeLazy167/claude-mods-skill
claude plugin install claude-mods-skill@claude-mods-skill
Then ask Claude to build a mod. The creating-mods skill loads on its own.
skills/creating-mods/SKILL.md: the workflow, which example to copy, quick reference, loader rules, sharing.skills/creating-mods/references/gotchas.md: version-tagged traps from real builds.skills/creating-mods/references/examples.md: Anthropic and community mods worth reading.examples/:| Example | Shows |
|---|---|
hello-mod | Block a tool call; fail-closed .catch; smoke.sh proves the deny |
redact-output | Rewrite Bash output before the model reads it |
branch-band | Git branch above the prompt; $.process.run on a timer; $.state |
notes-pane | /note and /notes; a pane with a Button; $.store |
dice-tool | A tool the model can call |
Try one for a session: claude --plugin-dir examples/notes-pane.
The mods API changes between releases. After a Claude Code update, run:
scripts/check.sh
It validates, tests and type-checks every example against your build.
hooks/register.ts 25 lines1import type { Register } from 'claude-code'
2
3// ponytail: three token shapes only; widen the list for your own secrets.
4const TOKEN = /\b(sk-[A-Za-z0-9_-]{16,}|ghp_[A-Za-z0-9]{20,}|AKIA[0-9A-Z]{16})\b/g
5
6const redact = (text: string) => text.replace(TOKEN, '[redacted]')
7
8export const register: Register = (on) => {
9 on('tool.call', { tool: 'Bash' }, async ($, e, next) => {
10 const ran = await next(e)
11 // A deny or an error has no stdout to clean.
12 if (ran.deny !== undefined || ran.isError) return ran
13
14 const stdout = redact(ran.result.stdout)
15 if (stdout === ran.result.stdout) return ran
16
17 $.ui.status('redact-output: hid a token from the model')
18 // Answer with a new { result }. Leaving out ref and text makes core map it again.
19 return { result: { ...ran.result, stdout } }
20 })
21 // If the hook throws, the raw output would reach the model. Refuse instead.
22 // The command already ran; the deny only keeps its output from the model.
23 .catch(() => ({ deny: 'redact-output: could not check the output' }))
24}
25