@akasecurity/ai-tc-claude-code
v0.8.2
Published
AI Traffic Control — inspect and govern AI prompts in Claude Code
Keywords
Readme
@akasecurity/ai-tc-claude-code — the aka plugin for Claude Code
The Claude Code plugin for AI Traffic Control (ai-tc). It hooks into a Claude Code session and inspects its traffic — prompts, tool calls, tool results, file reads — scanning each event against your rule packs and applying inline warn / redact / block policies. Every event is recorded to a local SQLite store at ~/.aka/data/aka.db.
Detection runs entirely on your machine. There's no account and no backend — nothing leaves your computer to be scanned.
Install
This package is distributed through the Claude Code plugin marketplace, not npm install. Add the marketplace and install the plugin from inside Claude Code:
/plugin marketplace add akasecurity/marketplace
/plugin install aka@akasecurityOr let the aka CLI do it for you:
npm install -g @akasecurity/cli
aka plugins install claude-codeThen run aka init to scaffold the local store, and aka dashboard to view findings.
What it registers
The plugin installs Claude Code hooks that run locally with no node_modules, and fail open (a hook error never breaks your session):
- SessionStart — snapshot the session context.
- UserPromptSubmit — scan prompts before they reach the model.
- PreToolUse — scan tool inputs (Bash, Edit, Write, MultiEdit, NotebookEdit, WebFetch, Task, and
any
mcp__*tool) before they run. Sensitive content in text a tool merely stores is masked in place; in text a tool acts on — a shell command, a URL, an MCP argument — masking would change what runs, so the call is blocked instead. - PostToolUse — scan tool outputs and file reads (Bash, Read, WebFetch) after they return.
- Stop — reconcile token usage and finalize the session record.
It also adds slash commands for reports and setup (/aka:health, /aka:findings, /aka:dashboard, and more).
Docs
Full documentation and the built-in detection catalog live at akasecurity.github.io/ai-tc-docs.
