SLOPSHOPPER

secret-redactor

Hides tokens, keys and passwords in tool output as ‹secret:N›, restores them in later tool calls, blocks reading key files.

newguardtoaststatus
A shopper browsing a rack in a slop shop
Preview · a replayed session in a sandbox
claude · ~/work/app · secret-redactor
› fix the failing auth test and add an audit log call ╭────────────────────────────────────────────╮ │ secret-redactor │ ⏺ Read(src/auth.ts) │ secret-redactor: hid 1 secret(s) from Bash │ ⎿ Read 6 lines │ output │ ⏺ Update(src/auth.ts) ╰────────────────────────────────────────────╯ ⎿ Added 2 lines, removed 1 line ⏺ Bash(bun test) ⎿ 3 pass, 1 fail ● Done. refresh now rejects expired claims and logs an audit event. ✻ Worked for 42s · done 4:20 PM ────────────────────────────────────────────────────────────────────────────────────────────────────────────────────── › ? for shortcuts ⚠ secret-redactor: hidden: 1
README

claude-code-kit

Formerly ai-prompts. Old links and clones redirect to this repo.

Skills, mods, subagents, hooks, slash commands and guides for Claude Code — installable by your agent (INSTALL.md).

Project-agnostic guides and executable agents for setting up Claude Code with 70-90% token reduction.

This library contains reusable prompts for implementing global Claude Code optimization across any project. Share with other developers or use to recreate your setup.


🤖 Install with an agent

Point your coding agent at INSTALL.md:

Read https://github.com/escapeboy/claude-code-kit/blob/master/INSTALL.md and install what fits my setup.

The agent inspects your environment, proposes a selection (starter, code intelligence, delivery, multi-agent, mods, security, unattended, stack-specific), installs it from the latest release tag after your yes, without overwriting your files, and verifies the result. llms.txt is the index agents use to find their way around.


📁 Contents

01-global-optimization

Set up global optimization (ONE-TIME, applies to ALL projects)

  • guide.md - Step-by-step installation guide
  • setup-agent.md - Executable agent for automated setup
  • checklist.md - Verification checklist
  • skills/ - Complete SKILL.md files for all 18 global skills (installed to ~/.claude/skills/)
  • optimize/ - /optimize — max token efficiency mode (multi-file: thin core + references/)
  • context/ - /ctx — memory management (multi-file: thin core + references/)
  • cache-inspector/ - /cache-inspector — cache monitoring (multi-file: thin core + references/)
  • update-docs/ - /update-docs — documentation refresh (multi-file: thin core + references/)
  • init-project/ - /init-project — new project setup (multi-file: thin core + references/)
  • agent-ready/ - /agent-ready — AI-agent-readiness audit + selective remediation (multi-file: scanner script + ROI/implementation references)
  • continuity/ - /continuity — repo-local resume→work→finalize lifecycle + evidence-weighted .continuity/STATE.md (multi-file: lint/scaffold script + format reference)
  • self-improve/ - /self-improve — closing-the-loop for the skill library: mine recurring feedback → bounded edit → tiered eval gate (deterministic skill-lint.py + trigger accuracy + LLM judge + with/without-skill behavioral eval via claude plugin eval) → converge (multi-file: linter + behavior-stats.py + deepeval_tier3.py scripts, rubric/behavior-eval/integration/deepeval-setup references)
  • video-digest/ - /video-digest — video or recording → short digest, related notes, fact-checked memory candidates
  • code-research/ - /code-research — multi-agent grounded audit of a local or git codebase into a cross-linked knowledge base (multi-file: per-phase references/)
  • agent-team/ - /agent-team — Agent Teams presets: pr-review, debug, feature, custom
  • codebase-memory/ - codebase-memory-mcp knowledge-graph queries: callers, call chains, dead code, Cypher
  • confidence-check/ - /confidence-check — ≥90% readiness gate before implementation (+ confidence.ts reference implementation)
  • decision-classify/ - /decision-classify — Mechanical / Taste / User Challenge classification to cut interruptions
  • sprint-orchestrate/ - /sprint-orchestrate — Think → Plan → Build → Review → Test → Ship → Reflect with decision gates (--from-design, --no-merge for callers like /company)
  • company/ - /company — an IT company for one task: clarify → research → split into parts → staff teams with fitting models → deliver through sprint-orchestrate; two stops for the user (multi-file: org-design, roster, briefs, workflows, memory references; back office in the company-hq mod)
  • sync-features/ - /sync-features — sync a project's feature inventory into Serena memories and auto-memory
  • ui-ux-review/ - /ui-ux-review — audit UI code for design consistency and accessibility (multi-file: examples + sample report)
  • system-prompts/ - Global system prompt files
  • global-optimization.md - Core optimization rules
  • symbol-first-protocol.md - Symbol-first exploration protocol

Time: 2-3 hours (one-time) Benefit: 70-90% token reduction on ALL future projects ROI: Pays for itself in 2-3 sessions

02-project-activation

Activate optimization for a specific project (10-15 min per project)

  • guide.md - Project activation walkthrough
  • activation-agent.md - Executable agent for Serena activation
  • memory-templates/ - Sample memory files
  • architecture-template.md - Project structure template
  • conventions-template.md - Coding patterns template

Time: 10-15 minutes per project Benefit: Project-specific memories for 60-70% session savings Required: After global setup, before starting work

03-custom-skills

Create custom slash commands (skills)

  • guide.md - How to write skills
  • skill-template.md - Blank template to copy
  • examples/ - Working examples
  • example-simple-skill.md - Simple single-action skill
  • example-complex-skill.md - Multi-action skill with integration
  • pwa.md - PWA features skill (service worker, manifest, offline, push notifications)
  • module-mcp/ - /module:mcp — Add a Laravel MCP server to any project (dual transport, domain tools, auth)
  • module-assistant/ - /module:assistant — Add an AI assistant chat panel (Livewire, PrismPHP tools, local agent support)

Use when: You want custom commands like /deploy or /migrate, or full modules like /module:mcp and /module:assistant Benefit: Encapsulate common workflows, reduce repetition; module skills bootstrap entire features

04-research-integration

Research and integrate new Claude API features

Use when: New Claude API features released, quarterly reviews Benefit: Keep documentation current, adopt new optimizations

05-token-optimization

Deep dive into token reduction techniques

Use when: Analyzing token usage, optimizing specific workflows Benefit: Understand and maximize savings, track ROI

06-advanced-patterns

Advanced techniques for complex scenarios

Use when: Complex projects, team coordination, critical decisions, cost visibility Benefit: Handle advanced scenarios with proven patterns; understand where tokens go

07-custom-commands

Custom slash commands for specialized workflows

  • debug.md - Debug Agent for systematic debugging
  • i18n.md - Internationalization management
  • qa.md - QA automation with browser testing
  • content-review.md - Content audit for accuracy, consistency, grammar, and translations
  • retro.md - Sprint retrospective with git analytics, shipping metrics, per-author breakdowns, and actionable insights

Use when: Specialized workflows, testing, debugging, sprint retrospectives, content quality assurance Benefit: Encapsulate complex workflows into simple commands

08-ui-ux-development

Production-ready UI/UX implementation with Claude Code

  • ui-ux-pro-skill.md - Complete UI/UX Pro Max skill documentation
  • 50+ UI styles (Glassmorphism, Minimalism, Brutalism, etc.)
  • 21 color palettes with accessibility guidance
  • 50 font pairings
  • shadcn/ui MCP integration
  • dashboard-workflow-guide.md - Step-by-step dashboard implementation
  • Real API data integration
  • Empty states and loading patterns
  • Security best practices (XSS prevention)
  • Dark mode and multilingual support
  • browser-testing-guide.md - Systematic browser testing
  • Chrome DevTools via Claude in Chrome MCP
  • Network, console, visual verification
  • Responsive and accessibility testing

Use when: Building dashboards, admin panels, landing pages, SaaS interfaces Benefit: 40-60% token savings, production-ready code with security and accessibility Time: 60-90 minutes per dashboard (vs 3-4 hours manual)

09-laravel-mcp-integration

Connect Claude Code with Laravel's MCP ecosystem

Use when: Working on Laravel 11.x/12.x projects with Claude Code Benefit: Project-aware assistance via Laravel Boost + package discovery via LaraPlugins.io Setup: 5 minutes per project (composer install + MCP registration)

10-subagents

Create custom AI agents with specialized knowledge and tools

  • README.md - Subagent system overview
  • guide.md - Complete subagent creation guide + all v2.1.83 frontmatter fields + production agents
  • plan-challenger (Opus) — adversarial plan review across 5 dimensions with refutation check
  • output-evaluator (Haiku) — LLM-as-Judge: APPROVE/NEEDS_REVIEW/REJECT before commit
  • loop-monitor (Haiku) — watchdog for autonomous sessions: stall/runaway/loop detection
  • examples/ - Working subagent examples
  • code-reviewer.md - Read-only code review agent
  • laravel-specialist.md - Laravel development agent
  • debugger.md - Debugging specialist
  • test-generator.md - Test generation agent

Use when: Repetitive specialized tasks, team standardization, cost optimization Benefit: Reusable agents with controlled tool access and model selection Setup: 5-10 minutes per agent definition

11-mobile-development

Mobile development with Claude Code across all major platforms

Use when: Developing iOS (Swift/SwiftUI), Android (Kotlin/Compose), React Native, or Flutter apps Benefit: Platform-specific MCP integration, build/test automation, device control Setup: 5-10 minutes per platform (MCP installation + CLAUDE.md template)

12-desktop-development

Desktop development with Claude Code for macOS, Tauri, and Electron

Use when: Building macOS native (SwiftUI/AppKit), Tauri (Rust + Web), or Electron (Node.js + Chromium) desktop apps Benefit: Platform-specific MCP integration, build/package automation, code signing and notarization workflows Setup: 5-10 minutes per platform (MCP installation + CLAUDE.md template)

14-webmcp

WebMCP — structured browser tools for AI agents (W3C Draft, Chrome 146 Canary)

  • guide.md - WebMCP integration guide
  • What WebMCP solves (89% token savings vs screenshot-based approaches)
  • WebMCP vs MCP comparison (frontend vs backend)
  • navigator.modelContext API reference with code examples
  • Implementation patterns (read-only, form actions, declarative HTML)
  • Integration with Chrome MCP and Playwright MCP
  • CLAUDE.md template for WebMCP-enabled projects
  • Current limitations and browser support matrix

Use when: Building web applications that AI agents will interact with Benefit: Structured tool access instead of DOM scraping; 89% token reduction Status: Early Preview — Chrome 146 Canary only, spec actively changing


13-security-hardening

Protect Claude Code workflows from MCP attacks, prompt injection, and accidental data loss

  • guide.md - Complete security hardening guide
  • MCP vetting checklist + community-vetted safe list
  • Known CVEs (2025-2026) with versions and mitigations
  • Prompt injection defense hooks (PreToolUse + PostToolUse)
  • 6 production safety rules with settings.json + hook implementations
  • permissions.deny hardening templates (global + project-level)
  • Agent Skills supply chain risks and scanning
  • hooks/ - Production hook library (actual scripts, copy-paste ready)
  • dangerous-actions-blocker.py — blocks rm -rf /-class commands in any spelling, force-push to main, DROP TABLE, over-broad pkill/killall, edits to key files
  • pre-commit-secrets.py — scans staged content for API keys / private keys / DB URLs before every git commit
  • block-interactive-sudo.py — refuses sudo that would hang on a password prompt
  • tests/ — two-sided matrices (must-block AND must-pass) · WHY.md — the failure behind each hook
  • README with settings.json wiring and the PreToolUse hook contract
  • Productivity hooks (package-version checker, session-start memory loader, shell-habits) live in 01-global-optimization/hooks/

Use when: Team environments, production codebases, regulated industries, before adding new MCP servers Benefit: Prevent data exfiltration, block destructive operations, audit MCP supply chain Time: 15-30 minutes for initial hardening; 5 minutes per new MCP added

16-autonomous-agents

Run Claude Code unattended — cron agents, heartbeat watchdogs, and session journaling

  • guide.md - Autonomous & scheduled agents guide
  • The three primitives: headless cron runs, /loop, and hooks — and when each applies
  • Daily journaling agent recipe (~120 production runs/month): idempotent in-place note editing, replace-vs-append sections, self-contained cron briefs
  • Heartbeat watchdog protocol: exact HEARTBEAT_OK token, 200-token failure budget, probe allowlist — born from sessions killed for drifting into investigations
  • Watchdog patterns: stall / token-runaway / repeated-action-loop detection
  • Anti-pattern table — each entry cost a real incident
  • heartbeat-template.md - Copy-paste HEARTBEAT protocol file
  • session-summary-hook.py - Stop hook: Haiku-summarized session entries appended to a daily note (~$0.001/session)

Use when: Scheduled health checks, automated journaling, any unattended Claude Code run Benefit: Agents that complete within budget instead of drifting; a daily work journal nobody has to write Time: 30-60 minutes for the first cron agent

17-mods

Claude Code mods (v2.1.287+) — TypeScript hooks inside the engine

  • guide.md - What mods can do that settings hooks cannot, anatomy, events and engine API, patterns that held up, testing
  • marketplace/ - Example marketplace ai-prompts-mods: 13 mods with tests — context-meter, cache-guard, spend-ledger, subagent-models, secret-redactor, ssh-guard, deploy-verify, ci-watch, cleanup-tracker, aside, fleet-status, lang-guard, company-hq

Use when: A policy must hold on every tool call or subagent spawn, output must be rewritten before the model sees it, or you want live UI (meters, panes, status) Benefit: Secrets out of transcripts, model routing that plugin updates cannot undo, cache and spend visible while you work Time: 10 minutes to install the set; 1-2 hours to write your first mod


🚀 Quick Start

First Time Setup (2-3 hours)

Option 1: Automated (Recommended)

# Navigate to Claude Code
cd ~/.claude

# Use the setup agent
# Copy contents of 01-global-optimization/setup-agent.md
# Paste into Claude Code conversation
# Agent will create all files automatically

Option 2: Manual

# Follow the step-by-step guide
# Read: 01-global-optimization/guide.md
# Create files as instructed
# Verify with: 01-global-optimization/checklist.md

Activate for Your Project (10-15 min)

# Navigate to your project
cd ~/projects/your-project

# Use the activation agent
# Copy contents of 02-project-activation/activation-agent.md
# Paste into Claude Code conversation
# Agent will activate Serena and create memories

Start Optimized Work

# In your project directory
/optimize "Your task here"

# Or use /init-project for new projects
/init-project --full

📊 Expected Outcomes

Token Reduction Targets

ScenarioBaselineOptimizedSavings
Simple task (bug fix)22,000 tokens1,600 tokens93%
Medium task (new feature)31,000 tokens8,500 tokens73%
Complex task (module creation)85,000 tokens18,000 tokens79%

Conservative target: 30-50% overall reduction Aggressive target: 50-70% with full optimization Maximum achieved: 80-90% with prompt caching on large contexts

Cost Savings

Per session (average medium task):

  • Baseline: $0.93 (31,000 tokens @ $3/M)
  • Optimized: $0.26 (8,500 tokens @ $3/M)
  • Savings: $0.67 per session (72%)

Monthly (30 sessions):

  • Baseline: $27.90
  • Optimized: $7.80
  • Savings: $20.10 per month

Annual (360 sessions):

  • Baseline: $334.80
  • Optimized: $93.60
  • Savings: $241.20 per year

Multiple projects (3 projects, 60 sessions/month):

  • Annual savings: $723.60

🛠️ What Gets Created

Global Files (in ~/.claude/)

Agents (orchestration):

  • agents/pm-orchestrator.md - Central coordinator
  • agents/plan-challenger.md - Adversarial plan review (Opus)
  • agents/output-evaluator.md - Code quality judge before commit (Haiku)
  • agents/loop-monitor.md - Autonomous session watchdog (Haiku)

Hooks (automation):

  • hooks/dangerous-actions-blocker.py - Blocks destructive commands and protected files
  • hooks/pre-commit-secrets.py - Scans staged files for API keys before commit
  • `hooks/block-interactive-sudo.p
Source 1 files
hooks/register.ts 125 lines
1import type { Register } from 'claude-code'
2
3// CLAUDE.md: `op read` puts the plaintext secret into the transcript. This mod
4// swaps secrets in tool results for ‹secret:N› before the model or the
5// transcript sees them, and puts the real value back into the arguments of the
6// next tool call that uses the placeholder. The table lives only in this
7// module's memory: a new session (or a reload) starts empty, by design.
8
9const PATTERNS: RegExp[] = [
10  /-----BEGIN [A-Z ]*PRIVATE KEY-----[\s\S]*?-----END [A-Z ]*PRIVATE KEY-----/g,
11  /\bops_[A-Za-z0-9_-]{20,}/g, // 1Password service account
12  /\bsk-ant-[A-Za-z0-9_-]{20,}/g,
13  /\bsk-[A-Za-z0-9]{20,}/g,
14  /\bgh[pousr]_[A-Za-z0-9]{30,}/g,
15  /\bgithub_pat_[A-Za-z0-9_]{40,}/g,
16  /\bglpat-[A-Za-z0-9_-]{20,}/g,
17  /\bxox[abprs]-[A-Za-z0-9-]{10,}/g,
18  /\bAKIA[0-9A-Z]{16}\b/g,
19  /\bsntry[su]_[A-Za-z0-9+/=_-]{20,}/g,
20  /\beyJ[A-Za-z0-9_-]{10,}\.[A-Za-z0-9_-]{10,}\.[A-Za-z0-9_-]{10,}/g, // JWT
21]
22// Value is the last capture group.
23const KEYED: RegExp[] = [
24  /(Bearer\s+)([A-Za-z0-9._~+/=-]{20,})/g,
25  /^(\s*(?:export\s+)?[A-Z0-9_]*(?:TOKEN|SECRET|API_KEY|APIKEY|PASSWORD|PASSWD|PASS|PWD|PRIVATE_KEY)[A-Z0-9_]*\s*=\s*['"]?)([^\s'"#]{8,})/gm,
26  /("(?:api_?key|token|secret|password|passwd|access_token|refresh_token|client_secret)"\s*:\s*")([^"]{8,})/gi,
27  // Prose in notes and memories: "password `x`", "парола: x". The value needs a
28  // digit or a symbol, so "password field" is left alone.
29  /((?:password|passwd|парола)\W{0,4}[`'"]?)((?=[^\s`'"]*[\d!@#$%^&*])[^\s`'"]{6,})/gi,
30]
31
32const BLOCKED_READ = [/\/\.config\/op\/sa-token$/, /\.pem$/, /\/\.ssh\/id_[A-Za-z0-9_-]+$/, /\/\.claude\/alert\.env$/]
33const SKIP_TOOLS = new Set(['Agent', 'Task', 'Workflow'])
34// Real values go back only into local tools. A placeholder in a web or MCP
35// call (e.g. from injected page text) is sent as the placeholder.
36const RESTORE_TOOLS = new Set(['Bash', 'Read', 'Edit', 'Write', 'NotebookEdit', 'Grep', 'Glob'])
37
38export class Vault {
39  private byValue = new Map<string, string>()
40  private byLabel = new Map<string, string>()
41
42  label(value: string): string {
43    let l = this.byValue.get(value)
44    if (!l) {
45      l = `‹secret:${this.byValue.size + 1}›`
46      this.byValue.set(value, l)
47      this.byLabel.set(l, value)
48    }
49    return l
50  }
51
52  get size() {
53    return this.byValue.size
54  }
55
56  redact(text: string): string {
57    let out = text
58    for (const re of PATTERNS) out = out.replace(re, m => this.label(m))
59    for (const re of KEYED) out = out.replace(re, (_m, pre: string, v: string) => (v.startsWith('‹secret:') ? pre + v : pre + this.label(v)))
60    return out
61  }
62
63  restore(text: string): string {
64    return text.replace(/‹secret:\d+›/g, l => this.byLabel.get(l) ?? l)
65  }
66}
67
68// Applies f to every string inside a JSON-like value; returns the same object
69// when nothing changed, so callers can tell.
70export const mapStrings = (v: unknown, f: (s: string) => string): unknown => {
71  if (typeof v === 'string') return f(v)
72  if (Array.isArray(v)) {
73    const out = v.map(x => mapStrings(x, f))
74    return out.some((x, i) => x !== v[i]) ? out : v
75  }
76  if (v && typeof v === 'object') {
77    let changed = false
78    const out: Record<string, unknown> = {}
79    for (const [k, x] of Object.entries(v)) {
80      out[k] = mapStrings(x, f)
81      if (out[k] !== x) changed = true
82    }
83    return changed ? out : v
84  }
85  return v
86}
87
88export const isBlockedPath = (path: string) => BLOCKED_READ.some(re => re.test(path))
89
90export const register: Register = on => {
91  const vault = new Vault()
92
93  on('tool.call', async ($, e, next) => {
94    const tool = String(e.tool)
95    if (SKIP_TOOLS.has(tool)) return next(e)
96
97    if (tool === 'Read' && 'file_path' in e && typeof e.file_path === 'string' && isBlockedPath(e.file_path)) {
98      return { deny: `secret-redactor: ${e.file_path} holds a credential; reading it is blocked. Use \`op run -- <cmd>\` or the tool that needs it.` }
99    }
100
101    // Put real values back into the arguments Claude wrote with placeholders.
102    const restored = (RESTORE_TOOLS.has(tool) ? mapStrings(e, s => (s.includes('‹secret:') ? vault.restore(s) : s)) : e) as typeof e
103    const ran = await next(restored)
104    if (ran.deny !== undefined) return ran
105
106    const before = vault.size
107    let result = mapStrings(ran.result, s => vault.redact(s))
108    // `op read` prints the bare secret, which no pattern can recognise.
109    if (tool === 'Bash' && 'command' in e && /\bop\s+read\b/.test(String(e.command)) && result && typeof result === 'object') {
110      const r = result as { stdout?: string }
111      const line = r.stdout?.trim()
112      if (line && !line.includes('\n') && line.length >= 8 && !line.startsWith('‹secret:')) {
113        result = { ...r, stdout: r.stdout!.replace(line, vault.label(line)) }
114      }
115    }
116    if (result === ran.result) return ran
117
118    $.ui.status(`hidden: ${vault.size}`)
119    if (vault.size > before) $.ui.toast(`secret-redactor: hid ${vault.size - before} secret(s) from ${tool} output`)
120    // Without ref/text, core maps the redacted record for the model and the transcript.
121    return { result, context: ran.context } as typeof ran
122    // Before the tool ran, let it run; after, withhold the output rather than leak it.
123  }).catch(($, e, next) => (next.called ? { deny: 'secret-redactor: could not scan this output for secrets, so it is withheld. Re-run it.' } : next(e)))
124}
125