{"_id":"@akasecurity/claude-tools","_rev":"2-151baa1c4594c760008088ab8b21d238","name":"@akasecurity/claude-tools","dist-tags":{"latest":"0.5.1"},"versions":{"0.4.1":{"name":"@akasecurity/claude-tools","version":"0.4.1","keywords":["claude","claude-code","security","ai-safety","mcp","hooks"],"license":"MIT","_id":"@akasecurity/claude-tools@0.4.1","maintainers":[{"name":"suhailsalim","email":"suhailpsalim@outlook.com"},{"name":"venu-akasecurity","email":"venu@akasecurity.io"},{"name":"jscott_aka","email":"jscott@akasecurity.io"},{"name":"pmontiel","email":"pmontiel@akasecurity.io"},{"name":"alsoknownaswill","email":"will@akasecurity.io"}],"homepage":"https://github.com/akasecurity/claude-tools","bugs":{"url":"https://github.com/akasecurity/claude-tools/issues"},"bin":{"aka-claude-tools":"bin/aka-claude-tools"},"dist":{"shasum":"bebca50cb3f610287d8facf2f74680303ac65f30","tarball":"https://registry.npmjs.org/@akasecurity/claude-tools/-/claude-tools-0.4.1.tgz","fileCount":35,"integrity":"sha512-cpS/MU4GOuzF4fpMNX/NJx8OjkABq0b/Sc9PnAgyc4uivuuQJsMLCfwKNgUvsrGiea0P+P8rZxb//UTy86uHFg==","signatures":[{"sig":"MEUCIQD+FMpTo1ueMjzNc7D0CMx9cBlVDkcyYEnMNkDv3nh00wIgXiaVeKxTZj4r0PfRNEdB7BnY9E1JW0qg8YSbCRNpWsU=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@akasecurity%2fclaude-tools@0.4.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":386644},"gitHead":"5d9daa2e315b7f478708a1d0c14fdfe7cb01823c","scripts":{"typecheck":"tsc --noEmit"},"_npmUser":{"name":"jscott_aka","email":"jscott@akasecurity.io"},"repository":{"url":"git+https://github.com/akasecurity/claude-tools.git","type":"git"},"_npmVersion":"10.8.2","description":"Security defaults for Claude Code — clean context, locked-down credentials, guarded egress.","directories":{},"_nodeVersion":"20.20.2","publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.1.0","typescript":"^5.6.0"},"_npmOperationalInternal":{"tmp":"tmp/claude-tools_0.4.1_1784103597637_0.9343974635211993","host":"s3://npm-registry-packages-npm-production"}},"0.5.1":{"_id":"@akasecurity/claude-tools@0.5.1","bin":{"aka-claude-tools":"bin/aka-claude-tools"},"bugs":{"url":"https://github.com/akasecurity/claude-tools/issues"},"dist":{"shasum":"e450cffd008cd6bd5e5ba11877d692c5e534bd75","tarball":"https://registry.npmjs.org/@akasecurity/claude-tools/-/claude-tools-0.5.1.tgz","fileCount":47,"integrity":"sha512-cFVP8S9jt+74yTyDrnCU/9i3eirqmfEPnQprrtoNhLk//r1I6ayNTntnVZnx7NB1AjDbdPNV0W+2MWJKqDE7hg==","signatures":[{"sig":"MEYCIQDszaPEMwxujnU4OSHfGz6U/3MqCocRI9/UK880H927iAIhAO4p1SGWrCJSvGs4uBRQVmTa6L8Jh6HQyvOkPcpNtEy9","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"},{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIEusFdhHJj/SxvI6k7cegb0S353sDPV+PG0no4Ar3hW7AiEA9nRvgc2U2XlqTBGSGVvNmtgL99fuO4YchKfnJw7A9aQ="}],"attestations":{"url":"https://registry.npmjs.org/-/npm/v1/attestations/@akasecurity%2fclaude-tools@0.5.1","provenance":{"predicateType":"https://slsa.dev/provenance/v1"}},"unpackedSize":601924},"name":"@akasecurity/claude-tools","gitHead":"7c39a7c4f4ff13eb82f072e6cf4ca93869a261bb","license":"MIT","scripts":{"typecheck":"tsc --noEmit"},"version":"0.5.1","_npmUser":{"name":"GitHub Actions","email":"npm-oidc-no-reply@github.com","trustedPublisher":{"id":"github","oidcConfigId":"2cc52c0e-4632-400b-9299-d5ec446cbe2a"}},"homepage":"https://github.com/akasecurity/claude-tools","keywords":["claude","claude-code","security","ai-safety","mcp","hooks"],"repository":{"url":"git+https://github.com/akasecurity/claude-tools.git","type":"git"},"_npmVersion":"11.19.0","description":"Security defaults for Claude Code — clean context, locked-down credentials, guarded egress.","directories":{},"maintainers":[{"name":"suhailsalim","email":"suhailpsalim@outlook.com"},{"name":"venu-akasecurity","email":"venu@akasecurity.io"},{"name":"jscott_aka","email":"jscott@akasecurity.io"},{"name":"pmontiel","email":"pmontiel@akasecurity.io"},{"name":"alsoknownaswill","email":"will@akasecurity.io"}],"_nodeVersion":"24.21.0","dependencies":{"bun":"1.4.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"devDependencies":{"@types/bun":"^1.4.2","typescript":"^7.0.2"},"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/claude-tools_0.5.1_1790894550313_0.8113295486902634"}}},"time":{"created":"2026-07-15T08:19:57.481Z","modified":"2026-10-01T22:42:31.657Z","0.4.1":"2026-07-15T08:19:57.793Z","0.5.1":"2026-10-01T22:42:30.416Z"},"bugs":{"url":"https://github.com/akasecurity/claude-tools/issues"},"license":"MIT","homepage":"https://github.com/akasecurity/claude-tools","keywords":["claude","claude-code","security","ai-safety","mcp","hooks"],"repository":{"url":"git+https://github.com/akasecurity/claude-tools.git","type":"git"},"description":"Security defaults for Claude Code — clean context, locked-down credentials, guarded egress.","maintainers":[{"name":"suhailsalim","email":"suhailpsalim@outlook.com"},{"name":"venu-akasecurity","email":"venu@akasecurity.io"},{"name":"jscott_aka","email":"jscott@akasecurity.io"},{"name":"pmontiel","email":"pmontiel@akasecurity.io"},{"name":"alsoknownaswill","email":"will@akasecurity.io"}],"readme":"# aka-claude-tools\n\n<p align=\"center\"><img src=\"media/banner.svg\" alt=\"aka-claude-tools: clean context, locked doors, guarded exits for Claude Code. MIT · needs jq + bun.\" width=\"100%\"></p>\n\n![version](https://img.shields.io/github/v/tag/akasecurity/claude-tools?label=version&color=blue)\n![license](https://img.shields.io/badge/license-MIT-green)\n\n**Make Claude Code safer to use.** Clean context, locked-down credentials, guarded\negress. The security defaults Claude Code doesn't ship with, layered onto a profile\nof its own in a few minutes.\n\nNew to this? Hand the repo to Claude and it sets you up. Comfortable in a terminal?\nRead every hook first. It's all plain shell and TypeScript, MIT, and the guards scan\nlocally: nothing is uploaded to run them.\n\n> Also known as `aka-claude-tools` (the npm package, Homebrew formula, and CLI name). Repo: `akasecurity/claude-tools`. The guard-hooks plugin installs as `claude-tools@akasecurity`.\n\nFrom [akasecurity](https://akasecurity.io) · MIT · needs `jq` + `bun`.\n\n---\n\n## What it guards against\n\nA coding agent runs shell commands and reaches the network on your behalf. This kit\nadds the guardrails for the obvious foot-guns:\n\n- **Reading your credentials** (SSH keys, cloud tokens, `.env` files, keychains) → denied.\n- **`curl … | bash`** and friends (piping a web script straight into your shell) → blocked.\n- **Editing your shell startup files** (a common way things quietly persist) → blocked.\n- **Secrets leaving in a web request** → matched on your machine and blocked.\n- **Secrets already in the model's context** (a file it read, a page it fetched, a search\n  result, an MCP response) → redacted before the model sees them; fetched or MCP content\n  carrying a prompt-injection phrase like \"ignore previous instructions\" is flagged too.\n- **Context filling with noise** (chatty command output) → summarized before it reaches the model.\n- **A kit file quietly edited, or a security setting reverted** → flagged at the next\n  session start, with `--audit` to see exactly what changed.\n\nNineteen small pieces, eleven on by default and eight opt-in. Each stands alone. Take what you want.\n\n**claude-tools is safe defaults for the harness; [ai-tc](https://github.com/akasecurity/ai-tc) is the detection engine.** The secret scan here is a shallow fallback — pattern and key-shape matching on egress. It does not detect PII, PHI, or cardholder data, and it does not redact. When you need deep content detection with an audit trail, add ai-tc; the installer offers it. The two compose: posture from claude-tools, detection from ai-tc.\n\n## Quick start\n\nTwo ways in, same result: a hardened profile launched by its own name (default\n`aka-claude` — a shell alias plus a PATH shim). Bare `aka` is deliberately left to the\n[AI Traffic Control](https://github.com/akasecurity) CLI, which shares the `aka`\nnamespace: its git-style dispatcher makes `aka claude` launch this profile.\n\n**Hand it to Claude.** In a logged-in Claude Code session, say:\n\n> Set up aka-claude-tools from github.com/akasecurity/claude-tools.\n> Read its agent-install.md and set up a hardened profile for me.\n\nIt reads the guide, checks what you already have, migrates it cleanly, and runs the\ninstaller. Nothing to type.\n\n**Or install via a package manager:**\n\n```bash\n# npm / npx (macOS + Linux)\nnpx @akasecurity/claude-tools\n\n# Homebrew (macOS + Linux)\nbrew tap akasecurity/tap\nbrew install akasecurity/tap/aka-claude-tools\naka-claude-tools\n```\n\nThe npm package brings its own `bun` as a dependency, so command-guard/leak-guard/mcp-guard/statusline/rtk-safe\nwork even with no system `bun` on PATH. That bundled `bun` needs its postinstall script, which\nnpm 12 blocks by default (`npm i -g` prints an install-scripts warning); allow it with\n`npm i -g --allow-scripts=bun @akasecurity/claude-tools`. When the bundled `bun` can't run, the\ninstaller ignores it and treats `bun` as missing: it offers to install `bun` interactively, and\nunder `--apply` or a non-interactive run it aborts before registering any hook that needs `bun`.\n**If your hooks ended up registered with that bundled bun** (the\ninstaller warns you when this happens), run this kit's uninstall before removing or upgrading the\n`@akasecurity/claude-tools` package, or install a system `bun` and re-run the installer first —\notherwise `npm uninstall -g` / `npm update -g` can leave the hooks pointing at a path that no longer\nexists.\n\n**Or clone and run:**\n\n```bash\ngit clone git@github.com:akasecurity/claude-tools.git\ncd claude-tools\n./install.sh             # interactive\n./install.sh --defaults  # accept the recommended ten\n```\n\nNothing runs on clone. Read the code first if you like. The installer asks where to put\nthe profile, what to name the launcher, and which pieces to enable, and migrates your\ncurrent config in (paths rewritten), so the new profile is a working copy of your setup,\nnot a bare sandbox. Prefer a walkthrough? See the [safe-setup carousel](media/decks/safe-setup.pdf).\n\n### Install as a Claude Code plugin (guards into your active profile)\n\n`claude plugin marketplace add akasecurity/marketplace` then `claude plugin install claude-tools@akasecurity` installs the guard hooks (command-guard, leak-guard, mcp-guard) into your **active** profile.\n\n- **Requires `bun`.** The guards run under bun. They **fail open** — if bun is missing they never\n  block your work; instead you get one clear \"guards INACTIVE\" notice at session start. Install bun\n  (https://bun.sh) to activate them.\n- **Plugin ≠ the full kit.** A plugin can't ship the credential-read denies, the `rtk-safe` output\n  rewriter (it needs a `permissions.allow` settings merge a plugin manifest can't apply), or the\n  status line. For the fully hardened, isolated profile, install the full kit — see\n  [Quick start](#quick-start) (npm, Homebrew, or `./install.sh`).\n\n## See it actually block something\n\nA guard you haven't watched fire is one you're only assuming works. Launch the profile\n(`aka-claude`) and try:\n\n- ask it to read `~/.ssh/id_rsa` → it **refuses**\n- check the status bar → context and rate-limit gauges show\n- run `curl … | bash` → **blocked**\n\n<p align=\"center\">\n  <img src=\"media/control-ssh-refused.svg\" alt=\"secure-settings refusing to read ~/.ssh/id_rsa\" width=\"100%\"><br>\n  <img src=\"media/control-statusline.svg\" alt=\"status line showing live context fill and rate-limit gauges\" width=\"100%\"><br>\n  <img src=\"media/control-curl-bash-blocked.svg\" alt=\"command-guard blocking curl piped into bash\" width=\"100%\">\n</p>\n\n## What's inside\n\n<p align=\"center\"><img src=\"media/whats-inside.svg\" alt=\"What's inside: additions grouped by what they do (graphic not yet refreshed for this release's count).\" width=\"100%\"></p>\n\nNineteen additions; the menu is driven entirely by\n[`config/additions.json`](config/additions.json), the single source both install paths read.\nPrefer a visual tour? See the [what's-inside carousel](media/decks/whats-inside.pdf).\n\n| Addition | What it does | Default |\n|---|---|---|\n| `secure-settings` | Denies reads of SSH keys, cloud creds, `.env`, keychains; blocks writes to shell startup files; no auto-loaded MCP servers. | ● on |\n| `sandbox` | Enables Claude Code's native OS-level sandbox, so Bash and every other tool run confined, not just the Read tool. Claude Code's own sandbox already merges `secure-settings`'s Read-deny credential paths into its filesystem restrictions at runtime, so this addition doesn't duplicate that list itself. While selected it owns `sandbox.enabled` (a manual edit back to `false` is warned about and set back to `true` on the next apply — deselect the addition to actually turn the sandbox off). Changes Bash behaviour in every session; needs `bwrap` and `socat` on PATH on Linux (macOS always supported; skipped elsewhere with a notice). | ○ opt-in |\n| `leak-guard` | Scans what the agent sends to the web and blocks anything shaped like a secret. Scanned locally, nothing uploaded to check it. | ● on |\n| `command-guard` | Blocks `curl…\\|bash`, edits to your shell startup files, and credentials being shipped out. An opt-in `CT_TRUSTED_BOOTSTRAP_URLS` allowlist can exempt specific installer-script URLs from the `curl\\|bash` block (see [Configuring the opt-in env keys](#configuring-the-opt-in-env-keys) below). | ● on |\n| `mcp-guard` | Applies your MCP server allow/deny lists (`CT_MCP_ALLOW` / `CT_MCP_DENY`) and blocks MCP tool inputs carrying anything shaped like a secret. It runs on every MCP call, so it checks key shapes and your org markers only; trufflehog stays on the Bash and web egress guards, for latency. The plugin install scans only; the lists come with the full kit. | ● on |\n| `post-guard` | Redacts anything shaped like a secret from what a file read, a web fetch, a web search, or an MCP tool call returns, rewriting the output before the model sees it — a PostToolUse hook, so it rewrites rather than blocks. Also warns, via Claude Code's `systemMessage` channel and to the model itself as additional context (never blocks), when fetched, searched, or MCP-returned content carries a prompt-injection phrase like \"ignore previous instructions\". An MCP resource block's own text is scanned like any other text; only image data and a resource's binary blob field are never scanned. | ● on |\n| `prompt-guard` | Scans what YOU just typed, not a tool call: prompt-injection phrasing, a credential paired with a send/upload instruction, and encoded blobs that decode to a shell command. Warns only — never blocks, never edits your prompt, never adds anything to the model's context. | ○ opt-in |\n| `rtk-safe` | Compresses supported standalone commands, including `grep`/`rg` — native flags, exit codes and regex dialect are preserved, but long result sets are **summarised**: you get the first ~25 matches plus an exact count of what was hidden and a `rtk recall` handle to retrieve it. Requires stable [`rtk`](https://github.com/rtk-ai/rtk) ≥ 0.49.0; otherwise leaves commands unchanged. Leaves `head`, `-h`/`--help`, and anything with a shell operator or substitution untouched, and preserves project scripts and interpreter selection. `rg`'s auto-approval requires `command-guard`. | ● on |\n| `statusline` | A status bar with live context-fill and rate-limit gauges. | ● on |\n| `shell-audit` | On-demand, read-only scan of your shell startup for hardcoded creds, risky hooks, and stale aliases. | ● on |\n| `wrap-up` | A `/wrap-up` command that summarizes, verifies, and stages a commit for review. Never commits on its own. | ○ opt-in |\n| `secure-deep-research` | Privacy-aware web research with per-claim adversarial verification before a cited synthesis. Sensitive topics are gated and routed through your own search instance. | ○ opt-in |\n| `harness-pointer` | A small nudge pointing the agent at the right CLI for your environment. Ships empty. | ○ opt-in |\n| `notify-osc` | A desktop notification when it's genuinely your turn — stays quiet while a background task (agent or shell) is still running. Auto-detects your terminal (Ghostty, kitty, WezTerm, iTerm2); works over SSH. | ○ opt-in |\n| `error-reporting-off` | Sets `DISABLE_ERROR_REPORTING` to opt out of Sentry error reporting. | ● on |\n| `feedback-off` | Sets `DISABLE_FEEDBACK_COMMAND` to disable the `/feedback` command. | ● on |\n| `feedback-survey-off` | Sets `CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY` to disable session quality surveys. | ● on |\n| `telemetry-off` | Sets `DISABLE_TELEMETRY`. Opt-in because it disables Remote Control (driving the CLI from a claude.ai session). | ○ opt-in |\n| `autoupdater-off` | Sets `DISABLE_AUTOUPDATER` to stop background updates; `claude update` still works. | ○ opt-in |\n\n`statusline` also has its own opt-in **sidecar**: set `CLAUDE_TOOLS_STATUS_SIDECAR_DIR` and it\nwrites `<dir>/<session_id>.json` with the session's context-window usage, model, and cwd — plus Claude Code's rate-limit windows (`rate_limits`: five-hour and seven-day usage and reset time) when it supplies them — fields\nClaude Code hands only to the status line — so a local tool can read them without scraping the\nrendered bar. Written atomically and only when a value actually changes; leaving the variable\nunset means no file and no change in behavior. Example, in `settings.json`:\n\n```json\n{ \"env\": { \"CLAUDE_TOOLS_STATUS_SIDECAR_DIR\": \"~/.cache/claude-status\" } }\n```\n\n### Configuring the opt-in env keys\n\nFour of the additions above read per-environment policy from\n[`shared/aka-claude-tools.config.example`](shared/aka-claude-tools.config.example) (copied to\n`aka-claude-tools.config` in your profile on first install): `leak-guard` and `command-guard`\n(`CT_EGRESS_PATTERNS`), `harness-pointer` (`CT_BLOCKED_CMDS`), `mcp-guard` (`CT_MCP_ALLOW` /\n`CT_MCP_DENY`), and `command-guard`'s bootstrap allowlist (`CT_TRUSTED_BOOTSTRAP_URLS`). Every\nkey ships empty, so those policy tiers are inactive until you set one. The guards' built-in\nchecks run regardless: `mcp-guard`'s secret scan of every MCP tool input is always on, as are\nthe credential scans and structural blocks in `leak-guard` and `command-guard`. Edit the file,\nthen re-run `./install.sh` to compile it into the sidecars the hooks read at runtime.\n\n- **`CT_MCP_ALLOW` / `CT_MCP_DENY`** (mcp-guard) — comma-separated MCP **server** names (the\n  segment after `mcp__` in a tool name, e.g. `mcp__searxng__web_search` → `searxng`), matched\n  case-insensitively. `CT_MCP_DENY` always blocks a listed server; a non-empty `CT_MCP_ALLOW`\n  also blocks every server not on it.\n- **`CT_TRUSTED_BOOTSTRAP_URLS`** (command-guard) — space-separated `https://host/path/` prefixes\n  (trailing slash required; the host needs at least two labels, and path segments use only\n  `A-Z a-z 0-9 . _ ~ -`, never `.` or `..`). The **only** exempted shape is `curl <-f/-s/-S in\n  any combination, or --fail/--silent/--show-error, plus --tlsv1.2 and --proto '=https'> <an\n  https URL under one of these prefixes> | bash` (or `| sh`) — one pipe, nothing else on the\n  line. `--proto` takes its value as a separate word (`--proto '=https'`); the joined\n  `--proto=https` form is not accepted. The URL in the command must have at least one path\n  segment under the prefix, so a bare host root such as `https://sh.rustup.rs` is never\n  exempted; allowlist installers served from a real path. For example, with\n  `CT_TRUSTED_BOOTSTRAP_URLS=\"https://get.example.dev/install/\"`, this exact command is\n  allowed:\n\n  ```bash\n  curl --proto '=https' --tlsv1.2 -sSf https://get.example.dev/install/setup.sh | sh\n  ```\n\n  Anything wider, including a plain `-L`/`--location` redirect-follow, still blocks. Residual risks worth\n  knowing: curl still reads `~/.curlrc` by default, which can inject flags (including\n  `--location`) invisibly to this allowlist; the sidecar's staleness check only detects that\n  `aka-claude-tools.config` changed since compile, not that the sidecar's rules still match what\n  that config would produce; and a `pathPrefix` of exactly `/` allowlists the **entire host**, not\n  just an install-script directory, so scope it as narrowly as the installer's real URL layout\n  allows.\n\nFull format details and worked examples for all three keys live as comments directly in\n[`shared/aka-claude-tools.config.example`](shared/aka-claude-tools.config.example) — read it before\nsetting any of them.\n\n## Local security-event audit log\n\n`command-guard`, `leak-guard`, `mcp-guard`, and `prompt-guard` each write one line\nper block, alert, or prompt-injection notice to a local, append-only log:\n`<profile>/logs/security-<YYYY-MM>.jsonl` (one file per UTC month, created at mode\n`0700`, each file at `0600`). Read it with:\n\n```bash\n./install.sh --audit-log [--month YYYY-MM] [PROFILE_DIR]\n```\n\nwhich prints a count of any unparseable lines skipped, counts by kind and rule, then\nthe last 20 events. Profile resolution matches the other read-only modes: the\npositional `PROFILE_DIR`, else `CT_CONFIG_DIR`, else the default profile\n(`~/.claude`).\n\n**Privacy.** A line never carries a full prompt, command, or tool output, only a\nredacted snippet capped at 200 characters, run through the same secret-pattern scan\nthe guards use on egress. `--audit-log` re-renders every event through that same\nredaction pass again on read, so a hand-edited or corrupted line already on disk\ncan't hand a raw value back to you either. Writing the log never changes a guard's\ndecision: a write failure (a read-only profile, a symlinked `logs/`) is swallowed\nsilently, the same as any other logging failure.\n\n**Off with ai-tc.** When [ai-tc](https://github.com/akasecurity/ai-tc) is present\nand enabled for the profile, this log turns off entirely. ai-tc keeps its own audit\ntrail, so claude-tools steps aside instead of double-logging the same decision.\n\n## Integrity check\n\nThe installer writes an integrity manifest, `<profile>/.aka-integrity.json`: a\nsha256 of every kit-managed hook, library file, and launcher shim, plus a hash of\nthe kit-managed slice of `settings.json` (its own hook registrations, the deny\nrules it shipped, `sandbox.enabled`, and `statusLine` — never your own hooks,\nallow/ask rules, or env keys). An internal `SessionStart` hook, not a selectable\naddition (it rides alongside any other bun-based hook, the way the plugin's own\npreflight check does), re-checks the profile against that manifest on every\nlaunch, resume, clear, compact, and fork. When something has drifted, it prints\none line to stderr:\n\n```\nclaude-tools: N kit file(s) changed or missing, settings drift; run aka-claude-tools --audit\n```\n\nFor the detail, run:\n\n```bash\n./install.sh --audit [PROFILE_DIR]\n```\n\nwhich lists exactly what changed, went missing, or turned up unexpected under\n`hooks/lib/`, names any kit-managed setting that drifted (a missing deny rule, a\nhook registration, `statusLine`, or `sandbox.enabled`), and warns separately when\n`disableAllHooks` or `permissions.defaultMode: \"bypassPermissions\"` is set — both\nturn the kit's guards off without changing anything the manifest hashes. Exits 0\nclean, 1 on drift or a missing manifest.\n\nThis is **detection, not a boundary**: anything able to rewrite a kit file can\nrewrite the manifest alongside it, so it catches careless edits and accidental\ndrift, not a determined attacker. Like the audit log, it never blocks — a\n`SessionStart` hook can only print, and the check fails silent on its own\ninternal error — and it runs regardless of ai-tc; only the audit log defers to\nai-tc's own trail.\n\n## Profiles\n\nA profile is its own `CLAUDE_CONFIG_DIR`: its own settings, hooks, and history, launched\nby name. Run several side by side: `claude` your everyday basics, `aka-claude` fully\nhardened, `work` work-only tools, `play` planning experiments. One Claude Code binary.\nThe launcher is both a shell alias and an executable PATH shim at\n`<profile>/bin/<name>` (the managed rc block adds that bin dir to `PATH`), so scripts\nand other shells can exec it too — and with the AI Traffic Control CLI installed,\n`aka claude` runs it via git-style external-subcommand dispatch.\n\n- **Pick per profile.** Choose pieces from the menu, or set `CT_ADDITIONS` to the ids you want for a scripted run.\n- **Upgrade in place.** As the kit updates, re-run. It finds the kit-managed profiles and **layers the current additions in place**: retired rules reconciled, renamed hooks re-registered, your own settings left intact.\n- **Remove cleanly.** Drop one piece by re-running without it (deselecting uninstalls it). Don't like any of it? Delete the profile. Your real setup never changed.\n- **Installed via npm and the hooks are wired to its bundled `bun`?** (The installer warns at apply time when this is the case.) Run this kit's uninstall *before* `npm uninstall -g` / `npm update -g` moves or removes that binary — otherwise the hooks point at a missing path, exit silently (127), and stop guarding without telling you.\n\n<p align=\"center\"><img src=\"media/isolated-profile.svg\" alt=\"A config dir is a whole Claude Code in a folder: try the kit in a fresh ~/.claude-aka or harden your real ~/.claude, and run several profiles side by side, each its own launcher.\" width=\"100%\"></p>\n\n## What stays on your machine\n\nThe guards run **locally**: secrets are matched on your machine, nothing is uploaded to\ncheck them. By default the kit silences the nonessential traffic that doesn't touch Remote\nControl: `error-reporting-off`, `feedback-off`, and `feedback-survey-off` are on.\n`telemetry-off` and `autoupdater-off` stay opt-in, so **Remote Control and auto-update\nkeep working**. Flip any of them to taste. (The optional status line fetches weather and\nyour usage; deselect it to opt out.)\n\nThey're **defense-in-depth, not a sandbox**: they raise the cost of a mistake, they don't\nmake exfiltration impossible. They don't see `ssh` / `git push`, a runtime's own requests,\nor a `$VAR`-referenced (non-literal) secret. The real boundary is the credential deny-list,\nno auto-loaded MCP servers, and not running with `bypassPermissions`. The guards **fail\nclosed** if their pattern file is missing or corrupt.\n\nFound a security issue? Please report it privately, see [`SECURITY.md`](SECURITY.md).\n\n## Installing via your agent?\n\nIf you're a coding agent reading this to set up a profile, don't improvise. Follow\n[`agent-install.md`](agent-install.md). It's the deterministic spec: enumerate existing\nprofiles with `./install.sh --enumerate`, migrate cleanly, then drive `./install.sh --apply`\nand `./install.sh --alias` (install.sh is the only sanctioned shell-rc writer). Use\n`--no-auth-inherit` when the profile is for a different account. A machine-readable\nmap of the repo lives at [`llms.txt`](llms.txt).\n\n## Beyond Claude Code\n\nThis is the Claude Code kit. A Codex counterpart is in the works, plus an agent\n**harness** that drives a disciplined, probe-gated engineering loop inside a profile.\n\n## Requirements\n\n`jq` and `bun` (the guards and status line run on bun). Optional:\n[`trufflehog`](https://github.com/trufflesecurity/trufflehog) for stronger secret detection,\n[`rtk`](https://github.com/rtk-ai/rtk) for the rewrite addition. The installer checks each\nand offers to install it (with your consent) via your package manager. macOS or Linux.\n\n## Acknowledgments\n\n- [PAI (Personal AI Infrastructure)](https://github.com/danielmiessler/PAI) by Daniel\n  Miessler: early inspiration for the egress-guard and command-rewriting concepts.\n- [trailofbits/claude-code-config](https://github.com/trailofbits/claude-code-config):\n  reference for the secure permission defaults and the maintainer-self-PR workflow.\n\nThe implementations here are our own. Built for\n[Claude Code](https://docs.claude.com/en/docs/claude-code).\n\n## License\n\n[MIT](LICENSE).\n\nThe guard hooks run on a vendored copy of guard-core (`config/hooks/lib/guard-core.js`,\nalso shipped in the plugin), from guard-core, MIT, Copyright (c) 2026\nWilliam Lin. Its licence text travels in that file's header; `tools/vendor-guard-core.sh`\nre-adds the header on every re-vendor.\n","readmeFilename":"README.md"}