deniz.in

Markets

Weather

Loading weather

· via dev.to (home feed)

mod-audit v0.2 audits Claude Code mod updates for swapped hooks and widened permissions

mod-audit v0.2 adds baseline-and-diff auditing for Claude Code mods, flagging new hooks, credential reads and widened permissions in updates after adversa.ai measured trojanized updates breaking test harnesses.

mod-audit v0.2 audits Claude Code mod updates for swapped hooks and widened permissions

The update becomes the audit target

The developer behind mod-audit, an offline supply-chain auditor for Claude Code mods, shipped version 0.2 on October 11 with a narrowed mission: catching what changes when an already-installed mod updates. According to the dev.to announcement, the redesign follows results from adversa.ai in which trojanized updates to Claude Code mods broke test harnesses with success rates as high as 92.5%, and whose takeaway was that reviewing updates, rather than scanning at install time, is the security control that currently counts.

The argument is straightforward. A scan at install time validates the release you chose; the malicious payload can land days later inside a routine update, after trust and permissions have already been granted.

Baseline and diff

Two commands carry the release. mod-audit baseline hashes the files of installed mods and records their hook commands and declared permissions into a snapshot, meant to be taken from a clean install. mod-audit diff then runs after an update, re-audits only what changed, and prints a grouped report that closes with a one-line verdict, such as a high-risk rating plus a count of high-severity findings in the delta. The announcement's sample output shows a changed plugin manifest whose lifecycle hook now pipes a remotely downloaded script straight into a shell — precisely the class of change an install-time scan never sees.

Four signals watched in the delta

The diff report groups findings into four categories:

  • New network exfiltration: the ENV-EXFIL rule, which looks for API keys placed near network sinks, is re-run against changed files.
  • Credential-path reads: new TS-CRED-PATH and HOOK-CRED-READ rules flag reads of SSH keys, AWS credential files, .pem keys, .env files and credentials. — paths the author argues a mod should never need to touch.
  • New or swapped hooks: the hook command inventory is compared against the baseline, and any addition or swap is rated high severity. The post describes this as a pin-swap pattern in the style of Plugin4Shell.
  • Permission widening: DIFF-PERM-WIDENED raises severity when an update flips a shell setting from false to true or adds a network grant.

Offline by design

The announcement contrasts mod-audit with ClawSecure Watchtower, a cloud service that continuously monitors mods but requires their source to leave the machine while users wait on a third-party verdict. mod-audit is a local, offline CLI: the author says a verdict comes back in milliseconds, and the tool is intended to run in CI or on a nightly schedule that re-checks installed mods. It uses only the Python standard library, requires Python 3.9 or newer, is MIT licensed with zero dependencies, installs from PyPI via pip, and hosts its source on GitHub.

Stated limitations

The author is candid about what the tool is not. It is a set of offline heuristics, not a sandbox, so a diff can only be as good as the baseline it starts from — snapshots should be taken from a clean install and stored somewhere the updater itself cannot write. TypeScript scanning is regex-based, a deliberate trade that keeps dependencies at zero and scans quick, which means heavily obfuscated code still requires manual review. mod-audit also does not replace metadata or policy reviewers; it targets the executed TypeScript layer those tools skip.

Why it matters

The adversa.ai numbers describe an active supply-chain risk, not a theoretical one: updates that tamper with test harnesses succeed most of the time, meaning the usual safety net — the tests themselves — is exactly what gets compromised. Mod ecosystems compound this by handing extensions hook execution, shell access and network permissions that persist silently across updates. Baseline-plus-diff auditing is a cheap, automatable response: pin a known-good state, then review only what changes, either in CI or on a nightly schedule. mod-audit v0.2 will not catch everything — a poisoned baseline and obfuscated code remain open gaps the author acknowledges — but it turns the update channel itself into a monitored surface, and it makes a swapped hook or a quietly widened permission something a developer sees the next morning rather than never.

  • #supply-chain
  • #claude-code
  • #security
  • #python
  • #open-source

Related posts