by cn0xroot
Claude Code Monitor : Monitor & audit every action Claude Code takes on your computer.
# Add to your Claude Code skills
git clone https://github.com/cn0xroot/CC-MonitorGuides for using ide extensions skills like CC-Monitor.
See how CC-Monitor compares with popular alternatives.
CC-Monitor is an open-source ide extensions skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by cn0xroot. Claude Code Monitor : Monitor & audit every action Claude Code takes on your computer. It has 53 GitHub stars.
CC-Monitor's catalog security scan is still queued. You can run an instant dependency and prompt-injection check now with the "Scan for vulnerabilities" button above.
Clone the repository with "git clone https://github.com/cn0xroot/CC-Monitor" and add it to your Claude Code skills directory (see the Installation section above).
CC-Monitor is primarily written in JavaScript. It is open-source under cn0xroot on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other IDE Extensions skills you can browse and compare side by side. Open the IDE Extensions category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh CC-Monitor against similar tools.
No comments yet. Be the first to share your thoughts!
Top skills in this category by stars
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
The deep catalog scan for this skill is still queued. Run an instant dependency check now instead.
English | 简体中文
Ever let an AI agent write code for you and had no idea what it actually did to your machine along the way? Give this a try. It monitors what Claude Code does on your machine — file reads/writes, shell command execution, network access — and blocks or asks for confirmation on high-risk operations, so an AI coding agent can't quietly damage your system or leak data. Everything is audit-logged. The technical design doc is available in English and Chinese. For what risks installing this actually carries, what third-party modules it depends on, and where your data actually goes, see SECURITY.md (Chinese).
Every release — what was added, changed and fixed — is recorded in CHANGELOG.md (Chinese); the current release is v2.0.
🧪 Experimental features (
devbranch):mastermonitors Claude Code only. Thedevbranch is extending the detection surface to other AI coding agents — Codex CLI, Gemini CLI, Cursor, OpenCode, ZCode, Antigravity CLI and Grok CLI plug into the same rules, approval desk and audit log through their own hooks / plugin; the system-layer eBPF probe recognises every agent's process tree via an "agent registry" and gains file-level syscalls (write / delete / rename / mkdir), listening-port observation, directory-fd tracking (relative paths fromrm -r/mkdir -presolved to absolute ones), session attribution for kernel events and explicitCC-Monitor run --binding; AI Tap parses Claude Code / Antigravity CLI / Codex session files. Everything except Claude Code is in an experimental / testing stage (implemented from each vendor's docs or source; Antigravity CLI has had one real-machine round, the rest have not been verified on real installs) — not recommended for production. See the dev branch README, MULTI-AGENT.md (usage and internals) and DESIGN-multi-agent.md (design), both in Chinese. To try it:git checkout dev, orgit worktree add ../CC-Monitor-dev devand run it with a separateCC_MONITOR_HOMEand port so the master install is untouched.
rm -rf, reverse shells, writing SSH keys…), medium-risk ones pop a confirmation
prompt, low-risk ones are logged silently — you're not babysitting every single action.CC-Monitor tail gives you a live, syntax-highlighted view (command name,
arguments, strings, pipes each get their own color) with one command.file_path; Bash commands split
into sub-commands with paths resolved, cd tracked, and redirects / rm/cp/tee-style
writes recognized) is resolved to an absolute path and compared against the current project
directory. Anything outside is tiered by location (hidden home-dir config/credentials, other
users' homes, system directories, other project directories) × read/write: writes to sensitive
locations prompt for confirmation, everything else is logged. Review them with CC-Monitor workdir or
the "Cross-workdir operations" home-page card.connect() call
directly — no TLS termination, no CA certificate to install — with a connection detail table,
GeoIP lookups, and a WebGL2 world map in the Web UI.| Home overview |
|---|
![]() |
| Session list drilldown | Event type breakdown |
|---|---|
![]() |
![]() |
| Blocked high-risk operations | Audit log |
|---|---|
![]() |
![]() |
git clone https://github.com/cn0xroot/CC-Monitor.git
cd CC-Monitor
./install.sh
install.sh runs 5 steps in order: the ccstatusline terminal statusline, hook
registration, Web UI dependencies, a system-layer probe check, and the GeoIP database —
each one idempotent and independently skippable (--skip-ccstatusline / --skip-geoip),
never overwriting anything you already have configured. Then run ./start.sh to launch
the Web UI.
If you only want the core interception/audit capability and don't need the Web UI or any of that, this one step is enough on its own:
python3 install.py
It does exactly one thing — registers the hooks into Claude Code's
~/.claude/settings.json. No npm or Python dependencies get installed (cc_monitor/
itself is standard-library-only Python). Once that's done, the CC-Monitor tail/rules/stats/verify CLI commands already work; the Web UI is an entirely
optional, separate add-on you can install later whenever you want it. For the exact
flags each script takes, what install.sh's 5 steps actually do, and installing to a
system path (make install), see the Installation section below.
Once installed, you decide how strict the tool is. There are three levels, and exactly one is active at any time.
Think of it as a guard at the door:
| Level | What the guard does | Color |
|---|---|---|
| Enforcing | Stops anyone suspicious outright, asks you about the borderline cases, notes down the rest | Purple |
| Permissive | Writes everyone down, but stops nobody and never interrupts you | Green |
| Off | The guard went home and took the notebook with them | Yellow |
In concrete terms:
rm -rf /, reverse
shells, or writing into ~/.ssh. Medium-risk matches pop a confirmation and only proceed
if you say so. Everything else is logged silently.Permissive and Off are the easy pair to confuse. Neither one will stop you. The difference is whether there's anything to look at afterwards. Permissive keeps the log filling; Off leaves a blank stretch you can never go back and inspect. So if you just want fewer interruptions, pick Permissive, not Off.
You can switch from the command line:
CC-Monitor audit start # Enforcing
CC-Monitor audit permissive # Permissive (the old name, pause, still works)
CC-Monitor audit stop # Off
CC-Monitor audit status # Show the current level
Or in the browser, on the left of the home page toolbar: three levels side by side, click one to switch, and the active one is highlighted in its color. Switching to Off asks once more first, because that's the level that leaves a gap in the audit trail. A matching status pill also sits permanently in the top bar, so you can tell the current level without going back to the home page.
One thing to know: the system-layer probe is not controlled by this switch. As long as the probe is running it keeps recording command execution and network connections at the kernel level, whichever level you pick. That's deliberate. The probe's whole value is observing independently of the hooks, so shutting it off alongside them would defeat the point.
webui/ is a standalone Node.js service that provides a browser UI:
cd webui
npm install
node server.js # listens on http://127.0.0.1:9999 by default, localhost-only