cc-arsenal: Instructions file for Claude Code

CLAUDE.md

cc-arsenal CLAUDE.md is an instructions file for Claude Code from mgiovani/cc-arsenal. It costs 1,200 tokens per session, scanned D, original, MIT.

Claude Code-specific instructions for installing and developing the cc-arsenal plugin collection. Claude Code is an AI coding assistant, and a plugin marketplace is a place where its extensions can be registered and installed.

In plain words
What is it for?
Use them to install cc-arsenal in Claude Code, test local changes, and understand its plugin variants and related Makefile commands.
Why use it?
They explain how to add the marketplace, choose plugin variants, and use a local setup during development.

Instructions file for Claude Code

Written for Claude Code: Claude Code plugin machinery. Also seen: reads .claude/ paths; mentions subagents; mentions Claude Code.

This is mgiovani/cc-arsenal's own configuration. It tells Claude Code how to work on cc-arsenal itself, so it is not a mod to install elsewhere. Copy it as a starting point and replace the rules that are about this project. Everything cc-arsenal configures →

Reuse

Borrowing it

Nothing to install: this file belongs to mgiovani/cc-arsenal. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.

Copy the file
curl -O https://raw.githubusercontent.com/mgiovani/cc-arsenal/main/CLAUDE.md
Clone the repo
git clone --depth 1 https://github.com/mgiovani/cc-arsenal

Made for: Claude Code.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for cc-arsenal CLAUDE.md

README.md
[![agentmods](https://agentmods.dev/badge/instructions/mgiovani/cc-arsenal/claude-md.svg)](https://agentmods.dev/instructions/mgiovani/cc-arsenal/claude-md)
Your own site
<a href="https://agentmods.dev/instructions/mgiovani/cc-arsenal/claude-md"><img src="https://agentmods.dev/badge/instructions/mgiovani/cc-arsenal/claude-md.svg" alt="Measured on agentmods" height="20"></a>
Per session 1,200 This file is loaded in full into every session.
When invoked 1,200 The same file — it is already loaded in full.
Security scan D 2 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.01200 $0.01200
Opus 5 $0.00600 $0.00600
Sonnet 5 $0.00240 $0.00240
Haiku 4.5 $0.00120 $0.00120

Measured 6d ago against content hash 5d575cf2222b, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-06, from the pricing page.

Security

Grade D, and why

cc-arsenal CLAUDE.md scanned grade D with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 6d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

`make configure` never modifies `~/.claude/settings.json`: it only symlinks the files you select.

Recursive force deletehighDestructive command

rm -rf with a variable or a broad path is one typo away from removing the wrong tree.

rm -rf ~/.claude/plugins/cache/cc-arsenal-marketplace/
CLAUDE.md · 113 lines

How it starts

The opening of the file, as written. The whole thing — 113 lines — stays where its author put it; the contents beside it link to each section on GitHub.

@AGENTS.md

This file adds Claude-Code-only guidance on top of the tool-agnostic AGENTS.md above (Claude Code doesn't read AGENTS.md natively, so this import is the bridge). Everything else (repo overview, skill catalog, skill anatomy, evals, Makefile commands, contributing) lives in AGENTS.md; don't duplicate it here.

Register this repository as a Claude Code Plugin marketplace:

/plugin marketplace add mgiovani/cc-arsenal

Then, to install a specific plugin set:

  1. Select Browse and install plugins
  2. Select cc-arsenal-marketplace
  3. Select one of the variants (see the table below)
  4. Select Install now

Alternatively, directly install via:

/plugin install cc-arsenal@cc-arsenal-marketplace

For local development, add a local marketplace instead:

/plugin marketplace add /path/to/cc-arsenal

Benefits over npx skills add: managed installation, automatic updates, easy enable/disable, no system-wide symlinks, plus the extras below (subagent orchestration, hooks, plugin variants) that only work inside Claude Code.

Plugin variants: install the whole toolkit or a focused subset:

Plugin Use Case
cc-arsenal Complete toolkit: every skill
cc-arsenal-dev Development workflows
cc-arsenal-product Product specs: PRD, design spec, and design tokens
cc-arsenal-review Code review and quality audits
cc-arsenal-docs Documentation generation
cc-arsenal-git Git/GitHub workflow automation
cc-arsenal-jira Jira standup, planning, and CLI
cc-arsenal-skills Specialty model-invoked capabilities
cc-arsenal-teams Team orchestration (experimental)

Each variant's exact skill set is defined in .claude-plugin/marketplace.json, the single source of truth, so the list never drifts across docs. The cc-arsenal variant intentionally omits the skills field there: an unset skills means "auto-load every skill in the repo," so it never needs syncing with the others.

Troubleshooting plugin updates:

Local directory marketplaces ("source": "directory") do NOT support auto-update or version detection: Claude Code caches marketplace.json on first install and local file changes don't invalidate that cache. After creating new skills or bumping versions:

rm -rf ~/.claude/plugins/cache/cc-arsenal-marketplace/
# Then in Claude Code: /plugin → Update now

Use a GitHub remote marketplace instead for automatic updates in production.

Read the full file on GitHub · 113 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 6d ago First seen · 113 lines · 1,200 tokens per session scan D 5d575cf2222b

Subscribe to this mod's changes

cc-arsenal CLAUDE.md is an instructions file published in the GitHub repository mgiovani/cc-arsenal (7 stars, last pushed 6d ago), licensed MIT. It adds 1,200 tokens to every session, about $0.0060 per session on Opus 5. A static security scan graded it D with 2 findings (reads agent configuration directories, recursive force delete). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other instructions, from other repositories

next.js AGENTS.md

AGENTS.md instructions for vercel/next.js, covering next.js development guide, codebase structure, monorepo overview, core package: packages/next and other important packages.

vercel/next.js · 7,296 tokens

codex AGENTS.md

AGENTS.md instructions for openai/codex, covering rust/codex-rs, the codex-core crate, code review rules, crate api surface and model visible context.

openai/codex · 5,182 tokens

vscode buildNext.instructions.md

Working notes and architecture documentation for the new esbuild-based build system in build/next. Use when making changes to the new build pipeline (transpile/bundle commands, NLS plugin, source-map handling, resource copying, or self-hosting watch tasks).

microsoft/vscode · 6,785 tokens

vscode oss-third-party-notices.instructions.md

Instructions for microsoft/vscode, covering vs code oss third-party-notices pipeline, architecture, pipeline flow in ci, applying the notice (cutover) and fallback chain (never fail the build).

microsoft/vscode · 5,001 tokens

langchain AGENTS.md

AGENTS.md instructions for langchain-ai/langchain, covering global development guidelines for the langchain monorepo, corridor security analysis, project architecture and context, monorepo structure and development tools & commands.

langchain-ai/langchain · 4,469 tokens

spec-kit AGENTS.md

AGENTS.md instructions for github/spec-kit, covering agents.md, about spec kit and specify, quickstart — add a new integration in 5 steps, integration architecture and integrationmanifest — file tracking.

github/spec-kit · 7,104 tokens