SLOPSHOPPER

ssh-guard

Refuses ssh/scp/rsync to hosts listed in memory decommissioned_hosts.md; "# decommissioned-ok" overrides.

newguardprocess
A shopper browsing a rack in a slop shop
README

claude-code-kit

Formerly ai-prompts. Old links and clones redirect to this repo.

Skills, mods, subagents, hooks, slash commands and guides for Claude Code — installable by your agent (INSTALL.md).

Project-agnostic guides and executable agents for setting up Claude Code with 70-90% token reduction.

This library contains reusable prompts for implementing global Claude Code optimization across any project. Share with other developers or use to recreate your setup.


🤖 Install with an agent

Point your coding agent at INSTALL.md:

Read https://github.com/escapeboy/claude-code-kit/blob/master/INSTALL.md and install what fits my setup.

The agent inspects your environment, proposes a selection (starter, code intelligence, delivery, multi-agent, mods, security, unattended, stack-specific), installs it from the latest release tag after your yes, without overwriting your files, and verifies the result. llms.txt is the index agents use to find their way around.


📁 Contents

01-global-optimization

Set up global optimization (ONE-TIME, applies to ALL projects)

  • guide.md - Step-by-step installation guide
  • setup-agent.md - Executable agent for automated setup
  • checklist.md - Verification checklist
  • skills/ - Complete SKILL.md files for all 18 global skills (installed to ~/.claude/skills/)
  • optimize/ - /optimize — max token efficiency mode (multi-file: thin core + references/)
  • context/ - /ctx — memory management (multi-file: thin core + references/)
  • cache-inspector/ - /cache-inspector — cache monitoring (multi-file: thin core + references/)
  • update-docs/ - /update-docs — documentation refresh (multi-file: thin core + references/)
  • init-project/ - /init-project — new project setup (multi-file: thin core + references/)
  • agent-ready/ - /agent-ready — AI-agent-readiness audit + selective remediation (multi-file: scanner script + ROI/implementation references)
  • continuity/ - /continuity — repo-local resume→work→finalize lifecycle + evidence-weighted .continuity/STATE.md (multi-file: lint/scaffold script + format reference)
  • self-improve/ - /self-improve — closing-the-loop for the skill library: mine recurring feedback → bounded edit → tiered eval gate (deterministic skill-lint.py + trigger accuracy + LLM judge + with/without-skill behavioral eval via claude plugin eval) → converge (multi-file: linter + behavior-stats.py + deepeval_tier3.py scripts, rubric/behavior-eval/integration/deepeval-setup references)
  • video-digest/ - /video-digest — video or recording → short digest, related notes, fact-checked memory candidates
  • code-research/ - /code-research — multi-agent grounded audit of a local or git codebase into a cross-linked knowledge base (multi-file: per-phase references/)
  • agent-team/ - /agent-team — Agent Teams presets: pr-review, debug, feature, custom
  • codebase-memory/ - codebase-memory-mcp knowledge-graph queries: callers, call chains, dead code, Cypher
  • confidence-check/ - /confidence-check — ≥90% readiness gate before implementation (+ confidence.ts reference implementation)
  • decision-classify/ - /decision-classify — Mechanical / Taste / User Challenge classification to cut interruptions
  • sprint-orchestrate/ - /sprint-orchestrate — Think → Plan → Build → Review → Test → Ship → Reflect with decision gates (--from-design, --no-merge for callers like /company)
  • company/ - /company — an IT company for one task: clarify → research → split into parts → staff teams with fitting models → deliver through sprint-orchestrate; two stops for the user (multi-file: org-design, roster, briefs, workflows, memory references; back office in the company-hq mod)
  • sync-features/ - /sync-features — sync a project's feature inventory into Serena memories and auto-memory
  • ui-ux-review/ - /ui-ux-review — audit UI code for design consistency and accessibility (multi-file: examples + sample report)
  • system-prompts/ - Global system prompt files
  • global-optimization.md - Core optimization rules
  • symbol-first-protocol.md - Symbol-first exploration protocol

Time: 2-3 hours (one-time) Benefit: 70-90% token reduction on ALL future projects ROI: Pays for itself in 2-3 sessions

02-project-activation

Activate optimization for a specific project (10-15 min per project)

  • guide.md - Project activation walkthrough
  • activation-agent.md - Executable agent for Serena activation
  • memory-templates/ - Sample memory files
  • architecture-template.md - Project structure template
  • conventions-template.md - Coding patterns template

Time: 10-15 minutes per project Benefit: Project-specific memories for 60-70% session savings Required: After global setup, before starting work

03-custom-skills

Create custom slash commands (skills)

  • guide.md - How to write skills
  • skill-template.md - Blank template to copy
  • examples/ - Working examples
  • example-simple-skill.md - Simple single-action skill
  • example-complex-skill.md - Multi-action skill with integration
  • pwa.md - PWA features skill (service worker, manifest, offline, push notifications)
  • module-mcp/ - /module:mcp — Add a Laravel MCP server to any project (dual transport, domain tools, auth)
  • module-assistant/ - /module:assistant — Add an AI assistant chat panel (Livewire, PrismPHP tools, local agent support)

Use when: You want custom commands like /deploy or /migrate, or full modules like /module:mcp and /module:assistant Benefit: Encapsulate common workflows, reduce repetition; module skills bootstrap entire features

04-research-integration

Research and integrate new Claude API features

Use when: New Claude API features released, quarterly reviews Benefit: Keep documentation current, adopt new optimizations

05-token-optimization

Deep dive into token reduction techniques

Use when: Analyzing token usage, optimizing specific workflows Benefit: Understand and maximize savings, track ROI

06-advanced-patterns

Advanced techniques for complex scenarios

Use when: Complex projects, team coordination, critical decisions, cost visibility Benefit: Handle advanced scenarios with proven patterns; understand where tokens go

07-custom-commands

Custom slash commands for specialized workflows

  • debug.md - Debug Agent for systematic debugging
  • i18n.md - Internationalization management
  • qa.md - QA automation with browser testing
  • content-review.md - Content audit for accuracy, consistency, grammar, and translations
  • retro.md - Sprint retrospective with git analytics, shipping metrics, per-author breakdowns, and actionable insights

Use when: Specialized workflows, testing, debugging, sprint retrospectives, content quality assurance Benefit: Encapsulate complex workflows into simple commands

08-ui-ux-development

Production-ready UI/UX implementation with Claude Code

  • ui-ux-pro-skill.md - Complete UI/UX Pro Max skill documentation
  • 50+ UI styles (Glassmorphism, Minimalism, Brutalism, etc.)
  • 21 color palettes with accessibility guidance
  • 50 font pairings
  • shadcn/ui MCP integration
  • dashboard-workflow-guide.md - Step-by-step dashboard implementation
  • Real API data integration
  • Empty states and loading patterns
  • Security best practices (XSS prevention)
  • Dark mode and multilingual support
  • browser-testing-guide.md - Systematic browser testing
  • Chrome DevTools via Claude in Chrome MCP
  • Network, console, visual verification
  • Responsive and accessibility testing

Use when: Building dashboards, admin panels, landing pages, SaaS interfaces Benefit: 40-60% token savings, production-ready code with security and accessibility Time: 60-90 minutes per dashboard (vs 3-4 hours manual)

09-laravel-mcp-integration

Connect Claude Code with Laravel's MCP ecosystem

Use when: Working on Laravel 11.x/12.x projects with Claude Code Benefit: Project-aware assistance via Laravel Boost + package discovery via LaraPlugins.io Setup: 5 minutes per project (composer install + MCP registration)

10-subagents

Create custom AI agents with specialized knowledge and tools

  • README.md - Subagent system overview
  • guide.md - Complete subagent creation guide + all v2.1.83 frontmatter fields + production agents
  • plan-challenger (Opus) — adversarial plan review across 5 dimensions with refutation check
  • output-evaluator (Haiku) — LLM-as-Judge: APPROVE/NEEDS_REVIEW/REJECT before commit
  • loop-monitor (Haiku) — watchdog for autonomous sessions: stall/runaway/loop detection
  • examples/ - Working subagent examples
  • code-reviewer.md - Read-only code review agent
  • laravel-specialist.md - Laravel development agent
  • debugger.md - Debugging specialist
  • test-generator.md - Test generation agent

Use when: Repetitive specialized tasks, team standardization, cost optimization Benefit: Reusable agents with controlled tool access and model selection Setup: 5-10 minutes per agent definition

11-mobile-development

Mobile development with Claude Code across all major platforms

Use when: Developing iOS (Swift/SwiftUI), Android (Kotlin/Compose), React Native, or Flutter apps Benefit: Platform-specific MCP integration, build/test automation, device control Setup: 5-10 minutes per platform (MCP installation + CLAUDE.md template)

12-desktop-development

Desktop development with Claude Code for macOS, Tauri, and Electron

Use when: Building macOS native (SwiftUI/AppKit), Tauri (Rust + Web), or Electron (Node.js + Chromium) desktop apps Benefit: Platform-specific MCP integration, build/package automation, code signing and notarization workflows Setup: 5-10 minutes per platform (MCP installation + CLAUDE.md template)

14-webmcp

WebMCP — structured browser tools for AI agents (W3C Draft, Chrome 146 Canary)

  • guide.md - WebMCP integration guide
  • What WebMCP solves (89% token savings vs screenshot-based approaches)
  • WebMCP vs MCP comparison (frontend vs backend)
  • navigator.modelContext API reference with code examples
  • Implementation patterns (read-only, form actions, declarative HTML)
  • Integration with Chrome MCP and Playwright MCP
  • CLAUDE.md template for WebMCP-enabled projects
  • Current limitations and browser support matrix

Use when: Building web applications that AI agents will interact with Benefit: Structured tool access instead of DOM scraping; 89% token reduction Status: Early Preview — Chrome 146 Canary only, spec actively changing


13-security-hardening

Protect Claude Code workflows from MCP attacks, prompt injection, and accidental data loss

  • guide.md - Complete security hardening guide
  • MCP vetting checklist + community-vetted safe list
  • Known CVEs (2025-2026) with versions and mitigations
  • Prompt injection defense hooks (PreToolUse + PostToolUse)
  • 6 production safety rules with settings.json + hook implementations
  • permissions.deny hardening templates (global + project-level)
  • Agent Skills supply chain risks and scanning
  • hooks/ - Production hook library (actual scripts, copy-paste ready)
  • dangerous-actions-blocker.py — blocks rm -rf /-class commands in any spelling, force-push to main, DROP TABLE, over-broad pkill/killall, edits to key files
  • pre-commit-secrets.py — scans staged content for API keys / private keys / DB URLs before every git commit
  • block-interactive-sudo.py — refuses sudo that would hang on a password prompt
  • tests/ — two-sided matrices (must-block AND must-pass) · WHY.md — the failure behind each hook
  • README with settings.json wiring and the PreToolUse hook contract
  • Productivity hooks (package-version checker, session-start memory loader, shell-habits) live in 01-global-optimization/hooks/

Use when: Team environments, production codebases, regulated industries, before adding new MCP servers Benefit: Prevent data exfiltration, block destructive operations, audit MCP supply chain Time: 15-30 minutes for initial hardening; 5 minutes per new MCP added

16-autonomous-agents

Run Claude Code unattended — cron agents, heartbeat watchdogs, and session journaling

  • guide.md - Autonomous & scheduled agents guide
  • The three primitives: headless cron runs, /loop, and hooks — and when each applies
  • Daily journaling agent recipe (~120 production runs/month): idempotent in-place note editing, replace-vs-append sections, self-contained cron briefs
  • Heartbeat watchdog protocol: exact HEARTBEAT_OK token, 200-token failure budget, probe allowlist — born from sessions killed for drifting into investigations
  • Watchdog patterns: stall / token-runaway / repeated-action-loop detection
  • Anti-pattern table — each entry cost a real incident
  • heartbeat-template.md - Copy-paste HEARTBEAT protocol file
  • session-summary-hook.py - Stop hook: Haiku-summarized session entries appended to a daily note (~$0.001/session)

Use when: Scheduled health checks, automated journaling, any unattended Claude Code run Benefit: Agents that complete within budget instead of drifting; a daily work journal nobody has to write Time: 30-60 minutes for the first cron agent

17-mods

Claude Code mods (v2.1.287+) — TypeScript hooks inside the engine

  • guide.md - What mods can do that settings hooks cannot, anatomy, events and engine API, patterns that held up, testing
  • marketplace/ - Example marketplace ai-prompts-mods: 13 mods with tests — context-meter, cache-guard, spend-ledger, subagent-models, secret-redactor, ssh-guard, deploy-verify, ci-watch, cleanup-tracker, aside, fleet-status, lang-guard, company-hq

Use when: A policy must hold on every tool call or subagent spawn, output must be rewritten before the model sees it, or you want live UI (meters, panes, status) Benefit: Secrets out of transcripts, model routing that plugin updates cannot undo, cache and spend visible while you work Time: 10 minutes to install the set; 1-2 hours to write your first mod


🚀 Quick Start

First Time Setup (2-3 hours)

Option 1: Automated (Recommended)

# Navigate to Claude Code
cd ~/.claude

# Use the setup agent
# Copy contents of 01-global-optimization/setup-agent.md
# Paste into Claude Code conversation
# Agent will create all files automatically

Option 2: Manual

# Follow the step-by-step guide
# Read: 01-global-optimization/guide.md
# Create files as instructed
# Verify with: 01-global-optimization/checklist.md

Activate for Your Project (10-15 min)

# Navigate to your project
cd ~/projects/your-project

# Use the activation agent
# Copy contents of 02-project-activation/activation-agent.md
# Paste into Claude Code conversation
# Agent will activate Serena and create memories

Start Optimized Work

# In your project directory
/optimize "Your task here"

# Or use /init-project for new projects
/init-project --full

📊 Expected Outcomes

Token Reduction Targets

ScenarioBaselineOptimizedSavings
Simple task (bug fix)22,000 tokens1,600 tokens93%
Medium task (new feature)31,000 tokens8,500 tokens73%
Complex task (module creation)85,000 tokens18,000 tokens79%

Conservative target: 30-50% overall reduction Aggressive target: 50-70% with full optimization Maximum achieved: 80-90% with prompt caching on large contexts

Cost Savings

Per session (average medium task):

  • Baseline: $0.93 (31,000 tokens @ $3/M)
  • Optimized: $0.26 (8,500 tokens @ $3/M)
  • Savings: $0.67 per session (72%)

Monthly (30 sessions):

  • Baseline: $27.90
  • Optimized: $7.80
  • Savings: $20.10 per month

Annual (360 sessions):

  • Baseline: $334.80
  • Optimized: $93.60
  • Savings: $241.20 per year

Multiple projects (3 projects, 60 sessions/month):

  • Annual savings: $723.60

🛠️ What Gets Created

Global Files (in ~/.claude/)

Agents (orchestration):

  • agents/pm-orchestrator.md - Central coordinator
  • agents/plan-challenger.md - Adversarial plan review (Opus)
  • agents/output-evaluator.md - Code quality judge before commit (Haiku)
  • agents/loop-monitor.md - Autonomous session watchdog (Haiku)

Hooks (automation):

  • hooks/dangerous-actions-blocker.py - Blocks destructive commands and protected files
  • hooks/pre-commit-secrets.py - Scans staged files for API keys before commit
  • `hooks/block-interactive-sudo.p
Source 1 files
hooks/register.ts 78 lines
1import type { EngineInterface, Register } from 'claude-code'
2
3// "Check the retired-hosts list before SSH" as a rule instead of a habit. The
4// list (option hosts_file) is read at session start, never copied here.
5const OVERRIDE = '# decommissioned-ok'
6const SSH_OPTS_WITH_VALUE = new Set('bcDEeFIiJLlmOopQRSWw'.split('').map(c => `-${c}`))
7
8export type Retired = { keys: string[]; title: string }
9
10// Each "## <name> — <ip> (<aliases>)" header is one retired host.
11export const parseRetired = (md: string): Retired[] =>
12  md.split('\n').filter(l => l.startsWith('## ') && /\d+\.\d+\.\d+\.\d+/.test(l)).map(l => {
13    const title = l.slice(3).trim()
14    const keys = new Set<string>()
15    for (const ip of title.match(/\b\d{1,3}(?:\.\d{1,3}){3}\b/g) ?? []) keys.add(ip)
16    const paren = /\(([^)]*)\)/.exec(title)?.[1] ?? ''
17    for (const p of paren.split(/[,\s]+/)) if (/^[a-z0-9][a-z0-9.-]*[a-z0-9]$/i.test(p) && /[.-]/.test(p)) keys.add(p.toLowerCase())
18    return { keys: [...keys], title }
19  })
20
21const stripUser = (h: string) => h.replace(/^[^@]*@/, '').replace(/^\[|\]$/g, '')
22
23// Hosts a shell command connects to, from ssh/sftp/mosh arguments and
24// scp/rsync `host:path` operands.
25export const targets = (command: string): string[] => {
26  const out = new Set<string>()
27  for (const seg of command.split(/&&|\|\||[;|\n]/)) {
28    const words = seg.trim().split(/\s+/).filter(Boolean)
29    const i = words.findIndex(w => /^(ssh|sftp|mosh)$/.test(w.replace(/^.*\//, '')))
30    if (i >= 0) {
31      for (let j = i + 1; j < words.length; j++) {
32        const w = words[j]!
33        if (SSH_OPTS_WITH_VALUE.has(w)) { j++; continue }
34        if (w.startsWith('-')) continue
35        out.add(stripUser(w))
36        break
37      }
38    }
39    if (words.some(w => /^(scp|rsync)$/.test(w.replace(/^.*\//, '')))) {
40      for (const w of words) {
41        const m = /^(?:[^@\s:/]+@)?([A-Za-z0-9.-]+):/.exec(w)
42        if (m && !w.includes('://')) out.add(m[1]!)
43      }
44    }
45  }
46  return [...out]
47}
48
49async function resolveHost($: EngineInterface, host: string): Promise<string> {
50  const ran = await $.process.run(['ssh', '-G', host], { timeoutMs: 5000 })
51  return /^hostname (\S+)/m.exec(ran.stdout)?.[1]?.toLowerCase() ?? host.toLowerCase()
52}
53
54export const register: Register = (on, options) => {
55  let retired: Retired[] = []
56
57  on('session.start', async ($, e, next) => {
58    const home = (await $.env.get('HOME')) ?? ''
59    const path = String(options.hosts_file ?? '~/.claude/decommissioned_hosts.md').replace(/^~(?=\/)/, home)
60    if (await $.fs.exists(path)) retired = parseRetired(await $.fs.read(path))
61    return next(e)
62  })
63
64  on('tool.call', { tool: 'Bash' }, async ($, e, next) => {
65    if (retired.length === 0 || e.command.includes(OVERRIDE)) return next(e)
66    for (const host of targets(e.command)) {
67      const resolved = await resolveHost($, host)
68      const hit = retired.find(r => r.keys.includes(host.toLowerCase()) || r.keys.includes(resolved))
69      if (hit) {
70        return {
71          deny: `ssh-guard: ${host}${resolved !== host.toLowerCase() ? ` (${resolved})` : ''} is a decommissioned host: "${hit.title}" (${String(options.hosts_file)}). If you really mean it (e.g. pulling data before the wipe), add \`${OVERRIDE}\` to the command after the user agrees.`,
72        }
73      }
74    }
75    return next(e)
76  }).catch(($, e, next) => next(e)) // a guard that cannot read hosts must not block every ssh
77}
78