probe3
by ucsandman · ★ 22 · updated 3 days ago
Permission override, subagent visibility, agent.spawn model rewrite, turn.step routing, prompt context injection
Install
git clone https://github.com/ucsandman/Agnostic-AIclaude --plugin-dir ./Agnostic-AI/labs/claude-mods/lab/probe3Then run /reload-plugins or start a new session. Requires Claude Code 2.1.287+.
What it hooks into
From an automated scan with claude plugin validate, not a security review. Mods run with your permissions; read the code before installing.
- Events
tool.checktool.callturn.stepagent.spawnsession.startagent.offerprompt.submitturn.complete- API calls
$.agent.list$.fs.write$.session.id$.session.messages$.session.repo$.session.usage$.settings.read- Can see
every tool callsubagent spawnsevery prompt- Reach
- level 2 of 3 writes filesreads settingsreads the transcript
Origin
- How it got here
- Automated scan of public GitHub repos, via the CC0 dataset awesome-claude-code-mods (scan of ).
- Repository
- github.com/ucsandman/Agnostic-AI
- Path in repo
labs/claude-mods/lab/probe3- Author
- @ucsandman
- License
- MIT
- First published
- Last pushed
- First listed here
Name and description come from the mod's own manifest. We link to the code; we don't host it, and it stays under its author's license.
More from ucsandman/Agnostic-AI
bender
ucsandman/Agnostic-AI
REALITY BENDER: intercepts a harmless tool result and alters what Claude receives; prints REAL vs RECEIVED
blackbox
ucsandman/Agnostic-AI
BLACK BOX RECORDER: structured per-session timeline of prompts, model steps, tool calls, subagents and denials; /blackbox prints it
claude-runtime
ucsandman/Agnostic-AI
Shared Claude runtime adapter: normalises function-hook events into ClaudeRuntimeEvent, exposes $.runtime (emit bus, supports, judge, snapshot) to other plugins, and writes a JSONL event log
costclaw-live
ucsandman/Agnostic-AI
COSTCLAW LIVE: per-request cost, cache decay and repeated-read detection while the session runs, and it serves the Nth identical Read of an unchanged file from its own cache instead of paying for it
guardian
ucsandman/Agnostic-AI
GUARDIAN: executable policy that protects lab/demos/protected/** from Write/Edit/Bash, whatever CLAUDE.md says
harness-mods
ucsandman/Agnostic-AI
Harness Mod layer: heartbeat/canary, native usage, rewrite explanations, measured subagent accounting, supervisor routing, secret redaction. Modes per guard in ~/.claude/mods/mods-config.json (classic | shadow_mod | mod).
matrix
ucsandman/Agnostic-AI
MATRIX: freezes a harmless tool call before it runs, shows what Claude intended, asks you, then continues or denies. /matrix on|off
probe-ui
ucsandman/Agnostic-AI
Interactive UI probe: ui.render components, toast, status, log, pane, command register
probe2
ucsandman/Agnostic-AI
Interception probe: deny, rewrite, replace result, delay, throw, register tool, classify
prodguard
ucsandman/Agnostic-AI
PRODUCTION GUARD: ambient project/environment context + a transport-independent policy core (DashClaw evidence classifier + offlocal policy engine) enforced natively on tool.call and tool.check. Blocks, asks, or contains before the command runs. /prodguard
spike-compact
ucsandman/Agnostic-AI
Spike: does $.session.compact() work from a plugin, and what does the session.compact event carry?
spike-describe
ucsandman/Agnostic-AI
Spike: does a tool.describe rewrite reach the model, does agent.offer hide a type, does prompt.suggest fire?