Claude Code Security Plugin
Claude Code installs packages on its own when it runs npx, npm install, pip install or claude mcp add. The SkillTotal plugin checks each npm, PyPI or MCP package before the command runs. The check uses the open-source SkillTotal engine and runs on your machine.
Scan a component — free →What happens when the agent installs something
- Malicious indicators. The command is denied, and the agent sees the reason.
- High or critical risk. Claude Code asks you to approve the install first.
- Custom registry or direct archive URL (
--registry,--index-url,--extra-index-url). Claude Code always asks you. SkillTotal can only scan the copy on the public registry, and that may not be the copy that gets installed. - Clean. The package installs as usual, and the agent gets a one-line note with its score.
- CLI missing or fails to start. The install runs unchecked and nothing is blocked. Claude Code shows a warning on each one.
Packages from GitHub (github:owner/repo, git+https://github.com/...) are scanned from the repository.
Set it up
Inside Claude Code, run:
/plugin marketplace add pezhik/skilltotal
/plugin install skilltotal@skilltotalThen run /reload-plugins or restart Claude Code. Until you do, the hook does not check commands in the session where you installed it.
The plugin calls the SkillTotal CLI, so install that too:
pip install skilltotalYou need version 0.56.3 or later, installed where Claude Code can find it. If skilltotal --version works in the terminal Claude Code uses, you're set.
To see it work without installing anything, ask the agent to run:
npm install --registry https://registry.example.invalid left-padClaude Code stops and asks you, with SkillTotal's reason. Nothing installs unless you approve it.
What it reads
The hook runs before each command the agent sends through the Bash or PowerShell tool. On Windows, Claude Code runs most commands through PowerShell, so both are covered.
It looks for packages that these commands would install:
npx,bunx,pnpm dlxnpm,pnpm,yarnorbunwithaddorinstallpip,uv,uvx,pipxclaude mcp add … -- <command>
Other commands pass straight through.
It reads a command the way the shell would, including sudo, env, bash -c '...', cmd /c, $(...), groups like (npm i y) and chains like cd x && npm i y. In PowerShell it also reads & { ... }, iex '...', Start-Process npm -ArgumentList ... and powershell -EncodedCommand.
Where it stops
The hook only sees what the command spells out. If a command builds the package name at run time, or the agent downloads a script and runs it, the install gets past the hook. For code you don't trust, run the agent in a container.
All checks for one command share a 20-second budget, which you can change with SKILLTOTAL_HOOK_BUDGET. If a package isn't checked in time, or its check fails, the install is not blocked, and the agent is told the package wasn't checked.
Verdicts are cached for 24 hours. They are redone when the engine version changes.
Also in the plugin
/skilltotal:scan <target>scans a component on demand.- The plugin registers the SkillTotal MCP server (
skilltotal mcp) with three tools:scan_component,diff_components(what changed between two versions) andlist_rules.
FAQ
- Does it send my code anywhere?
- No. The check runs in the SkillTotal CLI on your machine. The CLI downloads the package from its public registry and analyzes it locally. The package's code is not uploaded anywhere, and you don't need an account.
- Does it slow the agent down?
- Commands that don't install anything pass straight through. For install commands, all checks share a 20-second budget, and a package that isn't checked in time is let through with a note to the agent. Verdicts are cached for 24 hours, so a repeat install of the same package doesn't wait on a new scan.
- What happens if the CLI isn't installed?
- Installs run unchecked and nothing is blocked. Claude Code shows a warning on each one, so a broken setup doesn't look like a clean check.
- Does it work on Windows?
- Yes. Claude Code on Windows runs most commands through PowerShell, and the hook checks both the Bash and PowerShell tools.
- Does it run the package or call an LLM?
- No. The engine is deterministic (regex and AST analysis). It never executes the code it analyzes and never calls an LLM.