schreibse/claude-code-mods/tree/main/mr-banner
关于这个 mod
Claude Code模组
个人Claude Code mods:函数钩子的插件,可以重新设计脚本的样式,在周围添加行 提示并对工具调用做出反应。在 Claude Code 2.1.287+、Linux 上构建和使用。
模组
|模组 |它有什么作用 |命令 |需求|
|---|---|---|---|
| [安静的bash](安静的bash/)| One 行工具行(✓ <description>,失败时为红色 ✗ exit N,编辑时为 +N −M,调用持续时间 ≥10 s)。隐藏每个工具的结果块(Bash 输出、编辑差异、WebFetch、MCP 和代理结果;交互式工具、SendUserFile 和图像读取保留其结果)、完成的只读行(Read/Grep/Glob,并调用引擎以只读方式运行,如 ls 或 git status)、折叠工具组(除非 one 失败)和超时GitLab 管道等待通知。读取、发送或写入 PNG 的行下的内联 PNG 缩略图,包括相对路径 | /quiet 将这一切带回来; /thumb [big] <path> 显示PNG | ImageMagick (magick) 用于缩略图;带有 kitty 图形的终端(请参阅 herdr)|
| 安静旋转器 |普通的旋转词(thinking、writing、running)和 Took 1m 4s 而不是异想天开的词 | – | – |
| [使用百分比](使用百分比/)|提示下行:ctx 34% \| 5h 41% \| wk 86%,黄色来自80%,红色来自95%。在 Nx 存储库中,中间还有内存(claude.slice 使用 + app.slice 压力),右侧是会话自己的 nx serve 项目 (▶ admin api) 和分支的管道(ci ⏳ test、等待手动作业时的 ⏸)| – | gh / glab 已登录管道; systemd claude.slice 用于内存 |
| 提醒日志 |统计 Claude Code 在每个会话中为模型注入的提醒;删除令牌计数器和重复提交归因块 | /reminders 打印最近 30 天的计数 | – |
| 横幅先生 |创建、合并、批准或审核的每个 MR✗ exit NQ 下带有链接的彩色卡片 | – | GitLab MCP 服务器名为 gitlab 或 glab / gh |
| coderabbit-band |在提示上方带有打开的 CodeRabbit 线程(按严重性)和当前分支的 GitLab MR 的挑剔,并带有链接。仅当某些内容打开时显示 | /coderabbit 隐藏它直到计数改变 | glab 已登录;亚搏体育app远程|
| 编辑 |提示和工具输出中的秘密以 ‹secret:…› 令牌的形式到达模型;只有 Write/Edit 将它们恢复为实际值。请参阅redact | – | PATH 上的 betterleaks || 内存防护 |运行 Node 工具的 Bash 命令进入内存上限的 claude-cmd.slice 范围。拒绝,消息中已修复:nx affected``--parallel=1,没有 --parallel=1,pnpm 脚本有 :lite 双胞胎,没有工作帽的玩笑,带有无括号模式的 pkill -f/QXZKQZXALQ,ci:local,以及切片位于上方时的大量运行75 % 或在压力下。请参阅 mem-guard | – | systemd 用户 claude-cmd.slice,请参阅 mem-guard |
| 移交 |技能加mod:handover技能将冷会话的one语句切换写入~/.claude/handover.md;提示上方的条带会显示它,并且在 ✓ <description>Q(或同一文件夹中的新会话,在 14 天内)之后,它会在提示中等待一次作为建议,使用 Tab | 获取。 /handover-copy 复制它并隐藏乐队 | – |
| herdr-通知 |当 Claude 等待权限、答案或新提示时,GNOME 弹出窗口(Notification 挂钩,而不是插件)。当该窗格是 herdr 中聚焦的 one 时跳过。单击它会升起 Ghostty 并聚焦该会话的 herdr 窗格。挂钩:"Notification": [{"matcher": "permission_prompt\|idle_prompt\|elicitation_dialog", "hooks": [{"type": "command", "command": "bash \"$HOME/.claude/skills/herdr-notify/notify.sh\""}]}] | – | herdr、幽灵、notify-send、jq |
模型准确地看到了没有它们的情况:模组改变了绘制的内容,除了
提醒日志,它会删除 two 类型的注入提醒,编辑,隐藏秘密,以及内存保护,
它在 systemd 范围内运行 Node 命令,并拒绝一些命令并出现 mem-guard: … 错误。
Three 模组自行喊出:
- mr-banner,当 GitLab MCP 注释或批准答案没有 MR 链接时,调用
gitlabMCP 服务器上的get_merge_request用于链接和标题。gh/QXZKQZXBAQ 命令 无需额外费用。 - coderabbit-band 为 GitLab
origin遥控器轮询glab:60 计时器检查分支, 并且每分钟运行一次获取(glab mr view加上 MR 讨论的所有页面) 15 分钟后的git push,每 5 分钟,而乐队显示一些东西,每 15 分钟,否则, 一旦线程被解析后 5 s。 - 使用百分比,在 Nx 存储库中,轮询每个 10:
ps和pwdx的nx serve进程,以及docker inspect每个服务器运行的容器一次,以读取其撰写项目文件夾。 当 HEAD 移动时,会获取管道 (gh run list/glab ci get),15 在git push之后, 运行时每分钟,否则每 5 分钟。
安装
Claude Code 在会话开始时加载 ~/.claude/skills/ 下的每个插件文件夹。
- 空
~/.claude/skills: 直接克隆到其中:
h
git clone https://github.com/schreibse/claude-code-mods ~/.claude/skills
```-
**那里现有的技能:** 克隆到其他地方并链接您想要的模组:
```s
h
git clone https://github.com/schreibse/claude-code-mods ~/src/claude-code-mods
ln -s ~/src/claude-code-mods/quiet-bash ~/.claude/skills/quiet-bash # per mod
新的会议将他们吸收起来;正在运行的 one 需要 /exit 和 claude --continue。
**保留模组:**删除或取消链接其文件夹。 尝试使用 one 进行单个会话:
claude --plugin-dir ~/src/claude-code-mods/<mod>。
此存储库是技能文件夹本身,因此 .gitignore 会忽略所有内容并重新包含每个内容
mod:新的 mod 需要 !/<name>/ 行,否则 git 将看不到它。生成.claude-plugin/types/
由引擎控制并且保持不被追踪。
编辑:秘密作为令牌
betterleaks 在到达模型之前扫描每个提示和工具结果。它标记的每个值
变成 ‹secret:xxxxxxxx› 并在以后出现的任何地方保持隐藏,即使是扫描仪所在的位置
就不会再认出来了。
|模特的来电|会发生什么 | |---|---| |使用令牌编写、编辑、NotebookEdit |真实值被写入文件 | |写入将删除文件保存的秘密 |拒绝:使用编辑| |带有令牌的代理、SendMessage、TodoWrite |作为令牌传递| |任何其他带有令牌的工具(Bash、WebFetch、MCP …)|拒绝,所以价值永远不会离开 | | mod 不再知道的令牌(重启后)|拒绝,从未错误恢复|
截短输出。 在 Read、Grep 或 Bash 运行之前,每个文件的调用名称(Bash:每个单词
这是一个现有文件,最多扫描 10 (1 MB),因此 cut -c1-60 .env,
cut -d= -f2 或从 PEM 密钥读取几行仍然作为令牌返回。多线
秘密被逐行隐藏。
Bash 单词根据每个段运行的目录进行解析 (cd sub && cut -c1-40 .env),
~/、$HOME/ 和 ${HOME}/ 扩展到主目录。
规则。 betterleaks 的默认值加上 redact/betterleaks.toml:Sentry DSN 密钥和客户端
对于通用规则来说秘密太短。包含 dev、local、test 的客户端密钥,
example、changeme 或 placeholder 保持可见,因此本地开发客户端可以继续在命令中工作。
不包括:
- 图像;输出后面没有文件,剪短(
git show HEAD:.env | cut …,printenv | cut …);转录文件的结构化工具记录,保留真实值 (模型不会读取它们)。 - 缩短的预扫描会错过全局 (
cut -c1-40 *.env) 和带空格的引用路径。 - 短于 8 字符的值永远不会隐藏。
- 通过 Write/Edit 恢复到文件中的值可以被读回转换(
base64、rev、xxd)或发送(curl -T file)。 redact 无意中将秘密保留在模型上下文之外; 它不是针对试图获取它们的模型的沙箱。 - 引用
‹secret:…›令牌的子代理报告会像任何其他工具调用一样被拒绝 携带one。
保管库位于会话内存中:/exit 忘记了它。
状态行显示 redacted N: N 对保管库条目进行计数,因此 PEM 密钥每行计数一次。
Toast 为其隐藏的每个新值命名规则。如果没有 betterleaks,状态行会显示off (no betterleaks) 并没有隐藏任何内容。失败的 betterleaks 运行会留下该调用
未编辑(已在保管库中的值保持隐藏):每个失败条纹 one toast,状态
说 off (betterleaks),然后再次扫描下一个呼叫。
mem-guard:Bash 的内存规则
每个命名 Node 工具的 Bash 命令(node、npx、pnpm、npm、yarn、nx、jest、
vitest、playwright、tsc、/exitQ)运行为
systemd-run --user --scope --slice=claude-cmd.slice -p MemoryMax=30% -p MemorySwapMax=4% -- bash -c '…',
因此,溢出会随着退出 137 而终止,而不是关闭桌面。领先cd … &&停留
在包装器外部,因此 shell 的目录仍然会移动。
这些规则读取命令的每个部分运行的内容(在 &&、|、;、&、$( ) 之后,内部)
bash -c '…',跟随 cd),从来没有说过它只提到过,所以提交消息说
pkill -f 通过。未研究:xargs、make、eval、脚本。
假设此设置;消息将其命名为:
claude-cmd.slice用户单元。如果没有它,systemd 会使切片不受其自身的限制: 每个命令的上限仍然为 RAM 的 30 %,但余量检查没有任何可测量的内容并且保持关闭状态:
i
# ~/.config/systemd/user/claude-cmd.slice
[Slice]
MemoryMax=30%
MemorySwapMax=4%
```systemd
将百分比转换为计算机 RAM 的字节(在 27 GiB 上:8.2G 和 1.1G),因此
同一装置适用于任何机器。检查机器得到了什么:
`systemd-run --user --scope -q -p MemoryMax=30% -- sh -c 'cat /sys/fs/cgroup$(cut -d: -f3 /proc/self/cgroup)/memory.max'`
- 其重型脚本具有 `:lite` 双胞胎的存储库(`lint:affected:lite`、`typecheck:lite`、
`test:affected:lite`)和慢速 `ci:local` 脚本。
## 使用百分比:未涵盖
- 在 GitHub 上,仅显示分支的最新工作流程运行。
- 使用 SSH 主机别名 (`git@work:org/repo`) 的远程读取为 `ci no login (work)`
您已登录。
- 当服务器在会话的根目录中或在其容器中运行时,该服务器算作会话的服务器
compose 项目就在那里。 one 结账上的 Two 会话都可以看到其服务器。
## herdr:图像和链接
在 herdr 下(在 Ghostty 中),quiet-bash 的缩略图只绘制它们的
替代文本以及 mr-banner、coderabbit-band 和 Claude 自己的输出中的链接不可点击。
**原因:** Claude Code 仅针对 `XTVERSION` 答案为的终端打开 kitty 图形
`kitty` (≥ 0.28) 或以 `ghostty` 开头,且超链接仅适用于其识别的终端。牧人
转发两者,但用自己的名字应答,因此 Claude Code 将两者都关闭。
**修复:**在 Claude Code 启动之前仅在 herdr 内部强制启用两者(它在启动时读取它们):
```s
h
# ~/.bashrc.d/herdr-terminal.sh
if [ -n "$HERDR_ENV" ]; then
export CLAUDE_CODE_FORCE_TERMINAL_IMAGES=1
export FORCE_HYPERLINK=1
fi
还要在~/.config/herdr/config.toml中打开herdr的kitty图形直通(默认关闭):
l
[experimental]
kitty_graphics = true
然后herdr server reload-config,打开一个新 herdr 窗格(旧窗格保留旧环境)
并在那里启动Claude Code。检查一下:/thumb /path/to/some.png 应该画出图。
herdr-link-toast(herdr 插件,不是 Claude Code mod)
herdr 在后台打开一个 ctrl+clicked 链接,没有反馈,并忽略 file:// 链接
总共。 herdr-link-toast 打开 http(s) 与 xdg-open 的链接并显示
吐司。它还会打开 Quiet-bash 缩略图标题中的路径,该标题链接到
`http://localhost/open-file/<
安装
请先查看作者 README 确认 marketplace 和插件名称;命令可能随仓库结构改变。
claude plugin marketplace add schreibse/claude-code-mods claude plugin install mr-banner
原文 / README
claude-code-mods
Personal Claude Code mods: plugins of function hooks that restyle the transcript, add rows around the prompt and react to tool calls. Built and used on Claude Code 2.1.287+, Linux.
Mods
| Mod | What it does | Commands | Needs |
|---|---|---|---|
| quiet-bash | One-line tool rows (✓ <description>, red ✗ exit N on failure, +N −M on edits, duration for calls ≥10 s). Hides every tool's result block (Bash output, Edit diffs, WebFetch, MCP and Agent results; interactive tools, SendUserFile and image Reads keep theirs), finished read-only rows (Read/Grep/Glob, and calls the engine ran read-only like ls or git status), collapsed tool groups unless one failed, and timed-out GitLab pipeline-wait notices. Inline PNG thumbnails under rows that read, sent or wrote a PNG, relative paths included | /quiet brings it all back; /thumb [big] <path> shows a PNG | ImageMagick (magick) for thumbnails; a terminal with kitty graphics (see herdr) |
| quiet-spinner | Plain spinner words (thinking, writing, running) and Took 1m 4s instead of the whimsical ones | – | – |
| usage-percent | Row under the prompt: ctx 34% \| 5h 41% \| wk 86%, yellow from 80 %, red from 95 %. In Nx repos also memory in the middle (claude.slice usage + app.slice pressure) and on the right the session's own nx serve projects (▶ admin api) and the branch's pipeline (ci ⏳ test, ⏸ when it waits on a manual job) | – | gh / glab logged in for the pipeline; systemd claude.slice for memory |
| reminder-log | Tallies the reminders Claude Code injects for the model, per session; drops the token counter and repeated commit attribution blocks | /reminders prints the tally of the last 30 days | – |
| mr-banner | Colored card with a link under each MR/PR created, merged, approved or reviewed | – | GitLab MCP server named gitlab, or glab / gh |
| coderabbit-band | Band above the prompt with the open CodeRabbit threads (by severity) and nitpicks of the current branch's GitLab MR, with a link. Shows only when something is open | /coderabbit hides it until the counts change | glab logged in; GitLab remote |
| redact | Secrets in prompts and tool output reach the model as ‹secret:…› tokens; only Write/Edit turn them back into the real value. See redact | – | betterleaks on PATH |
| mem-guard | Bash commands that run Node tools go into a memory-capped claude-cmd.slice scope. Refused, with the fix in the message: nx affected/run-many without --parallel=1, a pnpm script that has a :lite twin, jest without a worker cap, pkill -f/pgrep -f with an unbracketed pattern, ci:local, and heavy runs while the slice is above 75 % or under pressure. See mem-guard | – | a systemd user claude-cmd.slice, see mem-guard |
| handover | Skill plus mod: the handover skill writes a one-sentence handover for a cold session to ~/.claude/handover.md; a band above the prompt shows it, and after /clear (or a new session in the same folder, within 14 days) it waits once in the prompt as a suggestion, taken with Tab | /handover-copy copies it and hides the band | – |
| herdr-notify | GNOME popup when Claude waits for a permission, an answer or a new prompt (a Notification hook, not a plugin). Skipped while that pane is the focused one in herdr. Clicking it raises Ghostty and focuses that session's herdr pane. Hook: "Notification": [{"matcher": "permission_prompt\|idle_prompt\|elicitation_dialog", "hooks": [{"type": "command", "command": "bash \"$HOME/.claude/skills/herdr-notify/notify.sh\""}]}] | – | herdr, Ghostty, notify-send, jq |
The model sees exactly what it would without them: the mods change what is drawn, except
reminder-log, which drops two kinds of injected reminders, redact, which hides secrets, and mem-guard,
which runs Node commands inside a systemd scope and refuses some with a mem-guard: … error.
Three mods call out on their own:
- mr-banner, when a GitLab MCP note or approval answers without the MR's link, calls
get_merge_requeston thegitlabMCP server for the link and title.gh/glabcommands cost nothing extra. - coderabbit-band polls
glabfor GitLaboriginremotes: a 60 s timer checks the branch, and a fetch (glab mr viewplus all pages of the MR's discussions) runs every minute for 15 min after agit push, every 5 min while the band shows something, every 15 min otherwise, and once 5 s after a thread is resolved. - usage-percent, in Nx repos, polls every 10 s:
psandpwdxfornx serveprocesses, anddocker inspectonce per container a server runs in, to read its compose project directory. The pipeline (gh run list/glab ci get) is fetched when HEAD moves, 15 s after agit push, every minute while it runs and every 5 min otherwise.
Install
Claude Code loads every plugin folder under ~/.claude/skills/ at session start.
- Empty
~/.claude/skills: clone straight into it:git clone https://github.com/schreibse/claude-code-mods ~/.claude/skills - Existing skills there: clone elsewhere and link the mods you want:
git clone https://github.com/schreibse/claude-code-mods ~/src/claude-code-mods ln -s ~/src/claude-code-mods/quiet-bash ~/.claude/skills/quiet-bash # per mod
New sessions pick them up; a running one needs /exit and claude --continue.
Leave a mod out: delete or unlink its folder. Try one for a single session:
claude --plugin-dir ~/src/claude-code-mods/<mod>.
This repo is the skills folder itself, so .gitignore ignores everything and re-includes each
mod: a new mod needs a !/<name>/ line or git won't see it. .claude-plugin/types/ is generated
by the engine and stays untracked.
redact: secrets as tokens
betterleaks scans every prompt and tool result before it reaches the model. Each value it flags
becomes ‹secret:xxxxxxxx› and stays hidden wherever it appears later, even where the scanner
would not recognise it again.
| The model's call | What happens | |---|---| | Write, Edit, NotebookEdit with a token | the real value is written to the file | | Write that would drop a secret the file holds | refused: use Edit | | Agent, SendMessage, TodoWrite with a token | passed on as the token | | Any other tool with a token (Bash, WebFetch, MCP …) | refused, so the value never leaves | | A token the mod no longer knows (after a restart) | refused, never restored wrongly |
Cut-short output. Before Read, Grep or Bash runs, every file the call names (Bash: each word
that is an existing file, up to 10 of 1 MB) is scanned whole, so cut -c1-60 .env,
cut -d= -f2 or a Read of a few lines from a PEM key still come back as tokens. Multi-line
secrets are hidden line by line.
Bash words resolve against the directory each segment runs in (cd sub && cut -c1-40 .env),
and ~/, $HOME/ and ${HOME}/ expand to the home directory.
Rules. betterleaks' defaults plus redact/betterleaks.toml: Sentry DSN keys, and client
secrets too short for the generic rules. A client secret containing dev, local, test,
example, changeme or placeholder stays visible, so local dev clients keep working in commands.
Not covered:
- images; output with no file behind it, cut short (
git show HEAD:.env | cut …,printenv | cut …); the transcript file's structured tool records, which keep real values (the model does not read them). - the cut-short pre-scan misses globs (
cut -c1-40 *.env) and quoted paths with spaces. - values shorter than 8 characters are never hidden.
- a value restored into a file by Write/Edit can be read back transformed (
base64,rev,xxd) or sent (curl -T file). redact keeps secrets out of the model's context by accident; it is not a sandbox against a model trying to get them. - a subagent's report that quotes a
‹secret:…›token is refused like any other tool call carrying one.
The vault lives in session memory: /exit forgets it.
The status line shows redacted N: N counts vault entries, so a PEM key counts once per line.
A toast names the rule for each new value it hides. Without betterleaks the status line says
off (no betterleaks) and nothing is hidden. A betterleaks run that fails leaves that call
unredacted (values already in the vault stay hidden): one toast per failure streak, the status
says off (betterleaks), and the next call scans again.
mem-guard: memory rules for Bash
Every Bash command that names a Node tool (node, npx, pnpm, npm, yarn, nx, jest,
vitest, playwright, tsc, ngc) runs as
systemd-run --user --scope --slice=claude-cmd.slice -p MemoryMax=30% -p MemorySwapMax=4% -- bash -c '…',
so an overrun dies with exit 137 instead of taking the desktop down. Leading cd … && stay
outside the wrapper, so the shell's directory still moves.
The rules read what each part of a command runs (after &&, |, ;, &, $( ), inside
bash -c '…', following cd), never words it only mentions, so a commit message saying
pkill -f passes. Not looked into: xargs, make, eval, scripts.
Assumes this setup; the messages name it:
- a
claude-cmd.sliceuser unit. Without it systemd makes the slice with no limit of its own: each command is still capped at 30 % of RAM, but the headroom check has nothing to measure and stays off:
systemd turns a percentage into bytes of the machine's RAM (on 27 GiB: 8.2G and 1.1G), so the same unit fits any machine. Check what a machine gets:# ~/.config/systemd/user/claude-cmd.slice [Slice] MemoryMax=30% MemorySwapMax=4%systemd-run --user --scope -q -p MemoryMax=30% -- sh -c 'cat /sys/fs/cgroup$(cut -d: -f3 /proc/self/cgroup)/memory.max' - repos whose heavy scripts have a
:litetwin (lint:affected:lite,typecheck:lite,test:affected:lite) and a slowci:localscript.
usage-percent: not covered
- On GitHub only the newest workflow run of the branch is shown.
- A remote using an SSH host alias (
git@work:org/repo) reads asci no login (work)though you are logged in. - A server counts as the session's when it runs inside the session's root, or in a container whose compose project lives there. Two sessions on one checkout both see its servers.
herdr: images and links
Under herdr (here inside Ghostty), quiet-bash's thumbnails draw only their alt text, and links in mr-banner, coderabbit-band and Claude's own output aren't clickable.
Cause: Claude Code turns on kitty graphics only for terminals whose XTVERSION answer is
kitty (≥ 0.28) or starts with ghostty, and hyperlinks only for terminals it recognises. herdr
forwards both, but answers with its own name, so Claude Code turns both off.
Fix: force both on, inside herdr only, before Claude Code starts (it reads them at startup):
# ~/.bashrc.d/herdr-terminal.sh
if [ -n "$HERDR_ENV" ]; then
export CLAUDE_CODE_FORCE_TERMINAL_IMAGES=1
export FORCE_HYPERLINK=1
fi
Also turn on herdr's kitty graphics passthrough (off by default) in ~/.config/herdr/config.toml:
[experimental]
kitty_graphics = true
Then herdr server reload-config, open a new herdr pane (old panes keep the old environment)
and start Claude Code there. Check it: /thumb /path/to/some.png should draw the picture.
herdr-link-toast (a herdr plugin, not a Claude Code mod)
herdr opens a ctrl+clicked link in the background with no feedback, and ignores file:// links
altogether. herdr-link-toast opens http(s) links with xdg-open and shows a
toast. It also opens the path in quiet-bash's thumbnail captions, which link to
http://localhost/open-file/<path> because file:// isn't clickable in herdr. Such a link opens
only when the path ends in .png; any other gets a "Could not open link" toast. Needs python3.
Install:
herdr plugin link ~/.claude/skills/herdr-link-toast
Without herdr, in plain kitty or Ghostty, none of this is needed. Terminals without the kitty graphics protocol show the thumbnail's alt text (its path).
Developing
Each mod is .claude-plugin/plugin.json, hooks/hooks.json and hooks/register.ts(x), plus
types/index.d.ts when it keeps session state. Per mod:
claude plugin validate <mod> # what it hooks and calls, and what the engine would refuse
claude plugin test <mod> # its *.test.ts(x)
tsc -p <mod> # once the engine has laid .claude-plugin/types/
Edits in ~/.claude/skills hot-reload into running sessions that loaded the mod.

