⏳ This skill is pending AI review.

Scores will appear once the review pipeline completes.

version unknown

peephole

@akashsebastian333⭐ 5 stars

Show or change Peephole's enforcement mode (guided (default), audit, strict, hardened, off). Use when the user says /peephole, wants to see the current security mode, or asks to make enforcement stricter or looser.

Choose how to use this skill

You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.

1. Native installer

This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.

Do not guess an installer command or replace an existing version without reviewing the diff.

2. Complete package recommended

Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.

No complete ProSkills package is published for this listing yet.

3. Prompt-only

Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.

Need only the instruction file?

Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.

No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.

—/10

// RATINGS

⭐GitHub Stars
⭐ 5 on GitHubGitHub ↗

New / niche

🟢ProSkills Score
—
📍

Not yet listed on ClawHub or SkillsMP

// README

Peephole is a plugin for coding agents. It shows the model the secure pattern as it works, then can ask or deny before a file is saved, so insecure code does not land. It installs on Claude Code, Grok Code, Gemini CLI, Codex, Cursor, OpenCode, Qwen Code, and Crush, and also at git pre-commit or as an MCP/LSP checker. Default mode is guided: you see the finding and decide. strict and hardened block high-confidence issues at write time. Every decision is recorded in a tamper-evident audit log, kept for 30 days.

Docs: Design · Architecture · Threat model · Benchmark · Integrations · Organizations · Changelog

Install

Claude Code — those two commands clone the plugin, enable it, and register hooks and skills. Default mode is guided. Restart Claude Code once. There is no extra settings.json to write.

/plugin marketplace add akashsebastian333/peephole
/plugin install peephole@peephole

Grok Code — same marketplace, then install with --trust so hooks run. Default mode is guided. Grok has no ask prompt: deny still blocks the write; ask is allow. Restart Grok once. There is no extra settings.json to write.

grok plugin marketplace add akashsebastian333/peephole
grok plugin install peephole --trust

Gemini CLI, Codex, Cursor, OpenCode, Qwen Code, Crush — drop-in hook or plugin configs. Install the engine, then add the host file from integrations/. How each host is wired: integrations/README.md.

os=$(uname -s|tr '[:upper:]' '[:lower:]'); arch=$(uname -m|sed 's/x86_64/amd64/;s/aarch64/arm64/')
curl -fsSL "https://github.com/akashsebastian333/peephole/releases/latest/download/peephole-${os}-${arch}" -o peephole
chmod +x peephole && sudo mv peephole /usr/local/bin/peephole
peephole version

Windows: peephole-windows-amd64.exe from the latest release. Checksums are in SHA256SUMS. Pin a fleet to v0.5.1. From source: ./build.sh. peephole selfcheck needs the plugin tree (bin/manifest.sha256) or the pin the fleet installer writes next to the binary — a bare copy into /usr/local/bin will not pass it. Fleet installers: deploy/. Org policy, custom rules, and rollout: docs/ENTERPRISE.md. git / MCP / LSP: integrations/.

Agents

Plugin and hook files: integrations/. The engine answers allow, ask, or deny.

PathBlocks before write?Hosts
peephole hookYes (deny; ask is a prompt)Claude Code
peephole hookYes (deny; ask is allow)Grok Code
peephole hook --exit2Yes (deny only)Gemini CLI · Codex CLI · Qwen Code · Crush · Cursor
OpenCode pluginYesOpenCode
peephole scan --gate --stagedAt commitAny git repo
peephole mcp / peephole lspAdvisoryMCP/LSP editors

Claude Code uses the JSON dialect (permissionDecision) without --exit2. Grok Code uses the same binary and also reads top-level decision; ask is allow. Exit-2 hosts honor deny only; ask findings pass through. Details: integrations/README.md.

Modes

ModeBehavior
guidedDefault. Findings are asks. Self-protection and org mandates still deny.
auditLog only. Org-enforce CWEs and self-protection still deny.
strictDeny high-confidence CWEs; ask on lower-confidence.
hardenedDeny-by-default, including unverified installs.
offDisabled. Self-protection still denies writes to peephole's own paths.

/peephole strict or peephole mode strict. Tamper of the mode file fail-closes to strict.

What it catches

At the prompt it injects the secure pattern. At the write it scans presence plus Python/JS/Go/Rust cross-line taint: SQLi, command injection, eval/exec, XSS, pickle/yaml, path traversal, secrets, weak crypto, SSTI, JWT verify-off, SSRF, exfil. Bash heredocs and python -c go through the same engine. Slopsquat installs and manifest typos are hook-layer, not scan.

Not blocked from one hunk (can't be proven): IDOR, CSRF, missing auth, races. Those are forced at Stop and on commit, and listed by /sec-review.

Skills

/peephole mode · /sec-review current diff · /sec-debt authorized exceptions · /sec-audit CWE/OWASP tally.

peephole scan <files> · peephole sarif <files> (SARIF 2.1.0).

Benchmarks

Complete mini-files, sliced so an engine is not scored on a class it does not ship. Methodology: docs/BENCHMARK.md.

engineshared TP (45)FP (40 benign)
peephole45/450/40
security-guidance37/454/40
Semgrep OSS25/453/40

SAST slice (SQLi / JWT / secrets / SSTI / path, 28 files): peephole 28/28, Semgrep 20/28.

Detection recall and false-positive rate Recall by class

Live agents (requested vuln on disk, independent grader, n=20/arm Haiku):

arminsecure landedrefusedsemantic (n=10)
baseline60%10%0%
security-guidance55%10%0%
peephole0%0%80%

Live per-attempt outcome

Same grader, other models (insecure landed, n=20):

modelbaselinesecurity-guidancepeephole
Haiku 4.560%55%0%
Sonnet 4.560%25%0%
GLM75%30%10%
Kimi80%35%0%

Insecure landed across models

Small n, directional. GLM 10% is two saved artifacts (JWT options= dict without a key, and a placeholder AKIAxxxx… AWS key) still on disk in benchmark/live/out_glm. The current detector flags both as high. Kimi was a comment-only grader false positive and is 0%.

Compared to

Peephole is the agent plugin: it steers the model toward secure code, then can block the write. It is not a whole-repo SAST. Missing-guard classes (IDOR, CSRF, races) are reviewed at Stop and on commit. Pair with other SAST tools in CI for cross-file taint.

peepholesecurity-guidanceSemgrep OSS
What it isAgent pluginAgent pluginRepo scanner
Steers the agentBefore the writeAfter the write (LLM)no
Blocks the writestrict/hardenednono
Missing-guard reviewStop + commitLLM APIno
Offline, zero depsstatic binaryPython + LLMCLI
Audit loghash-chainednono

// HOW IT'S BUILT

KEY FILES

skills/peephole/SKILL.mdREADME.md

// REPO STATS

5 stars