⏳ This skill is pending AI review.
Scores will appear once the review pipeline completes.
peephole
Show or change Peephole's enforcement mode (guided (default), audit, strict, hardened, off). Use when the user says /peephole, wants to see the current security mode, or asks to make enforcement stricter or looser.
Choose how to use this skill
You do not need every option. Choose the path your AI client supports. The stable page stays the same; versioned files are immutable.
1. Native installer
This listing has no registered native installer command. Use the complete package or source fallback below, depending on what your client supports.
Do not guess an installer command or replace an existing version without reviewing the diff.
2. Complete package recommended
Download the ZIP when available. It includes SKILL.md plus the references, security notes and version metadata.
No complete ProSkills package is published for this listing yet.3. Prompt-only
Copy the prompt above when the agent can read the stable page or when you want to adopt the workflow without installing a skill.
Need only the instruction file?
Download SKILL.md only if your client requires a single file. The complete ZIP is safer for a full installation because it preserves the references and release context.
No path installs or executes anything by itself. Your agent still needs access to the project files. Before updating, compare the installed version and review the diff.
// RATINGS
Not yet listed on ClawHub or SkillsMP
// README
Peephole is a plugin for coding agents. It shows the model the secure
pattern as it works, then can ask or deny before a file is saved, so
insecure code does not land. It installs on Claude Code, Grok Code, Gemini CLI,
Codex, Cursor, OpenCode, Qwen Code, and Crush, and also at git pre-commit or
as an MCP/LSP checker. Default mode is guided: you see the finding and decide.
strict and hardened block high-confidence issues at write time.
Every decision is recorded in a tamper-evident audit log, kept for 30 days.
Docs: Design · Architecture · Threat model · Benchmark · Integrations · Organizations · Changelog
Install
Claude Code — those two commands clone the plugin, enable it, and register
hooks and skills. Default mode is guided. Restart Claude Code once. There is
no extra settings.json to write.
/plugin marketplace add akashsebastian333/peephole
/plugin install peephole@peephole
Grok Code — same marketplace, then install with --trust so hooks run.
Default mode is guided. Grok has no ask prompt: deny still blocks the write;
ask is allow. Restart Grok once. There is no extra settings.json to write.
grok plugin marketplace add akashsebastian333/peephole
grok plugin install peephole --trust
Gemini CLI, Codex, Cursor, OpenCode, Qwen Code, Crush — drop-in hook or
plugin configs. Install the engine, then add the host file from
integrations/. How each host is wired:
integrations/README.md.
os=$(uname -s|tr '[:upper:]' '[:lower:]'); arch=$(uname -m|sed 's/x86_64/amd64/;s/aarch64/arm64/')
curl -fsSL "https://github.com/akashsebastian333/peephole/releases/latest/download/peephole-${os}-${arch}" -o peephole
chmod +x peephole && sudo mv peephole /usr/local/bin/peephole
peephole version
Windows: peephole-windows-amd64.exe from the
latest release.
Checksums are in SHA256SUMS. Pin a fleet to v0.5.1. From source: ./build.sh.
peephole selfcheck needs the plugin tree (bin/manifest.sha256) or the pin
the fleet installer writes next to the binary — a bare copy into /usr/local/bin
will not pass it. Fleet installers: deploy/. Org policy, custom
rules, and rollout: docs/ENTERPRISE.md. git / MCP / LSP:
integrations/.
Agents
Plugin and hook files: integrations/. The engine answers
allow, ask, or deny.
| Path | Blocks before write? | Hosts |
|---|---|---|
peephole hook | Yes (deny; ask is a prompt) | Claude Code |
peephole hook | Yes (deny; ask is allow) | Grok Code |
peephole hook --exit2 | Yes (deny only) | Gemini CLI · Codex CLI · Qwen Code · Crush · Cursor |
| OpenCode plugin | Yes | OpenCode |
peephole scan --gate --staged | At commit | Any git repo |
peephole mcp / peephole lsp | Advisory | MCP/LSP editors |
Claude Code uses the JSON dialect (permissionDecision) without --exit2.
Grok Code uses the same binary and also reads top-level decision; ask is
allow. Exit-2 hosts honor deny only; ask findings pass through. Details:
integrations/README.md.
Modes
| Mode | Behavior |
|---|---|
guided | Default. Findings are asks. Self-protection and org mandates still deny. |
audit | Log only. Org-enforce CWEs and self-protection still deny. |
strict | Deny high-confidence CWEs; ask on lower-confidence. |
hardened | Deny-by-default, including unverified installs. |
off | Disabled. Self-protection still denies writes to peephole's own paths. |
/peephole strict or peephole mode strict. Tamper of the mode file fail-closes to strict.
What it catches
At the prompt it injects the secure pattern. At the write it scans presence plus
Python/JS/Go/Rust cross-line taint: SQLi, command injection, eval/exec, XSS,
pickle/yaml, path traversal, secrets, weak crypto, SSTI, JWT verify-off, SSRF,
exfil. Bash heredocs and python -c go through the same engine. Slopsquat
installs and manifest typos are hook-layer, not scan.
Not blocked from one hunk (can't be proven): IDOR, CSRF, missing auth, races.
Those are forced at Stop and on commit, and listed by /sec-review.
Skills
/peephole mode · /sec-review current diff · /sec-debt authorized exceptions · /sec-audit CWE/OWASP tally.
peephole scan <files> · peephole sarif <files> (SARIF 2.1.0).
Benchmarks
Complete mini-files, sliced so an engine is not scored on a class it does not ship. Methodology: docs/BENCHMARK.md.
| engine | shared TP (45) | FP (40 benign) |
|---|---|---|
| peephole | 45/45 | 0/40 |
| security-guidance | 37/45 | 4/40 |
| Semgrep OSS | 25/45 | 3/40 |
SAST slice (SQLi / JWT / secrets / SSTI / path, 28 files): peephole 28/28, Semgrep 20/28.

Live agents (requested vuln on disk, independent grader, n=20/arm Haiku):
| arm | insecure landed | refused | semantic (n=10) |
|---|---|---|---|
| baseline | 60% | 10% | 0% |
| security-guidance | 55% | 10% | 0% |
| peephole | 0% | 0% | 80% |

Same grader, other models (insecure landed, n=20):
| model | baseline | security-guidance | peephole |
|---|---|---|---|
| Haiku 4.5 | 60% | 55% | 0% |
| Sonnet 4.5 | 60% | 25% | 0% |
| GLM | 75% | 30% | 10% |
| Kimi | 80% | 35% | 0% |

Small n, directional. GLM 10% is two saved artifacts (JWT options= dict
without a key, and a placeholder AKIAxxxx… AWS key) still on disk in
benchmark/live/out_glm. The current detector flags both as high. Kimi was a
comment-only grader false positive and is 0%.
Compared to
Peephole is the agent plugin: it steers the model toward secure code, then can block the write. It is not a whole-repo SAST. Missing-guard classes (IDOR, CSRF, races) are reviewed at Stop and on commit. Pair with other SAST tools in CI for cross-file taint.
| peephole | security-guidance | Semgrep OSS | |
|---|---|---|---|
| What it is | Agent plugin | Agent plugin | Repo scanner |
| Steers the agent | Before the write | After the write (LLM) | no |
| Blocks the write | strict/hardened | no | no |
| Missing-guard review | Stop + commit | LLM API | no |
| Offline, zero deps | static binary | Python + LLM | CLI |
| Audit log | hash-chained | no | no |
// HOW IT'S BUILT
KEY FILES