configure-surface

configure-surface is a skill for Claude Code, Codex from laurigates/claude-plugins. It costs 41 tokens per session (2,630 once invoked), scanned A, original, MIT.

A setup guide for Surface, an experimental check that detects when documented behavior no longer matches the code.

In plain words
What is it for?
Use it to connect prose claims to code symbols and add a pinned verification check to pre-commit hooks or CI.
Why use it?
It helps prevent documentation from becoming inaccurate after code changes by stopping commits or builds when linked logic changes.

Skill for Claude CodeCodex

Part of the configure-plugin plugin — 48 skills shipped together

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/laurigates/claude-plugins/configure-surface
Any agent
npx skills add laurigates/claude-plugins --skill configure-surface
Clone the repo
git clone --depth 1 https://github.com/laurigates/claude-plugins

Made for: Claude Code, Codex.

Or install configure-plugin, the plugin that ships this one along with the rest of its 48 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for configure-surface

README.md
[![agentmods](https://agentmods.dev/badge/skills/laurigates/claude-plugins/configure-surface.svg)](https://agentmods.dev/skills/laurigates/claude-plugins/configure-surface)
Your own site
<a href="https://agentmods.dev/skills/laurigates/claude-plugins/configure-surface"><img src="https://agentmods.dev/badge/skills/laurigates/claude-plugins/configure-surface.svg" alt="Measured on agentmods" height="20"></a>
Per session 41 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,630 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00041 $0.02630
Opus 5 $0.00020 $0.01315
Sonnet 5 $0.00008 $0.00526
Haiku 4.5 $0.00004 $0.00263

Measured yesterday against content hash 7127dd5548d0, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

configure-surface scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

configure-plugin/skills/configure-surface/SKILL.md · 218 lines

How it starts

The opening of the file, as written. The whole thing — 218 lines — stays where its author put it; the contents beside it link to each section on GitHub.

/configure:surface

Scaffold and harden Surface — a deterministic "documentation governed like code" gate. Surface anchors prose claims to code symbols, stores an AST-normalized logic fingerprint per symbol, and blocks CI/commits when the fingerprint drifts until a human re-runs surf verify. It ignores cosmetic edits and catches flipped operators, relaxed comparisons, and dropped await.

⚠️ Experimental — adopt defensively. As of 2026-06 Surface is a young, single-maintainer project (no crates.io publish, bus-factor 1). The engine and release hygiene vetted well, but treat it as a pinned, optional gate — never an unpinned dependency. This skill defaults to SHA-pinned installs and fail-closed checksum verification.

When to Use This Skill

Use this skill when... Use another approach when...
Adding a deterministic doc↔code drift gate to CI/pre-commit Enforcing same-commit doc discipline by convention (blueprint:blueprint-docs-currency)
You want specific prose claims pinned to specific functions Detecting stale generated content (blueprint:blueprint-sync)
You want an offline, no-LLM gate that fails the build on logic drift You want semantic "is the doc still true?" judgment (code-quality:code-review)
Hardening an existing Surface setup (pin by SHA, verify checksums) Generating docs from code (documentation:docs-generate)

Context

  • surf.toml: !find . -maxdepth 2 -name 'surf.toml'
  • Hubs dir: !find . -maxdepth 2 -type d -name 'hubs'
  • Pre-commit config: !find . -maxdepth 1 -name '.pre-commit-config.yaml'
  • Workflows: !find . -path '*/.github/workflows/*' -maxdepth 3 -name '*.yml'
  • Language markers: !find . -maxdepth 1 \( -name 'Cargo.toml' -o -name 'package.json' -o -name 'pyproject.toml' -o -name 'go.mod' \)

Parameters

Parse from $ARGUMENTS:

  • --check-only: Report Surface adoption status and pin hygiene; make no changes (CI mode).
  • --fix: Apply scaffolding and hardening without prompting.
  • --pin <tag>: Release tag to install/pin (default: latest stable; resolve its commit SHA before writing any uses: ref).

Read the full file on GitHub · 218 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 218 lines · 41 tokens per session scan A 7127dd5548d0

Subscribe to this mod's changes

configure-surface is a skill published in the GitHub repository laurigates/claude-plugins (57 stars, last pushed yesterday), licensed MIT. It adds 41 tokens to every session and 2,630 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.

Related

Other skills, from other repositories

ci-log-interpretation

Use this skill when reading or analyzing CI logs from a Shopware GitHub Actions workflow to figure out why a build failed — phrases like "why did CI fail", "what broke the build", "check the pipeline", "interpret these logs", "debug this red build" — or whenever raw run logs, job logs, or check annotations from a…

shopwareLabs/ai-coding-tools · 154 tokens

setup

Verify the actionlint-check hook's runtime prerequisites and configuration for this repository. Use when: 'set up actionlint', 'configure actionlint', 'is actionlint working', workflow lint silently isn't happening, or the hook reported a missing prerequisite. Actions: check (read-only verification, default) | apply…

melodic-software/claude-code-plugins · 73 tokens

code-review

CI code-review lane for a GitHub pull request. High-signal correctness and maintainability findings only, scoped out of security when a security lane exists. Use when: 'CI code review', 'claude-review lane', '/review:code-review', or a reusable workflow invokes the org code-review plugin command.

melodic-software/claude-code-plugins · 63 tokens

github-logs-analyze

Analyze GitHub Actions failure logs.

nanasess/eccube-dev-agents · 6 tokens

cicd

CI/CD pipeline patterns and deployment strategies for automated, reliable software delivery. Use when the user asks to design a build pipeline, choose a deployment model (blue-green, canary, rolling), configure environment promotion, manage build artifacts, implement zero-downtime deployments, set up quality gates, or…

krzysztofsurdy/code-virtuoso · 89 tokens

watch-ci

Monitor GitHub Actions CI runs until completion. Use when: watching CI after push, checking build status, monitoring PR checks, waiting for CI completion, user says 'watch CI', 'check CI', 'CI status', 'monitor build', or /watch-ci. Not for: pushing code (use push-ci), creating PRs (use create-pr). Output: per-run…

sd0xdev/sd0x-harness · 86 tokens