promptsign
by Sergey Vasilevskiy · ★ 0 · updated 2 days ago
Verifies signatures on the instruction files Claude Code loads, meaning CLAUDE.md, skills, and agent definitions, before they reach model context. It re-checks a skill bundle before the Skill tool runs it. Sigstore keyless, offline verification against a pinned trust root, no telemetry.
Install
/plugin marketplace add PromptSign/promptsign-plugin/plugin install promptsign@promptsignThen run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
skill.promptprompt.contextplugin.register- API calls
$.env.get$.process.run$.ui.toast- Can see
every skillthe system prompt- Reach
- level 2 of 3 runs processesreads env varsdraws
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/PromptSign/promptsign-plugin
- Path in repo
- repository root
- Author
- Sergey Vasilevskiy @PromptSign
- License
- Apache-2.0
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.