setup

A guided setup wizard for configuring AgentKeeper, a Claude Code security add-on.

In plain words
What is it for?
Use it when getting started with AgentKeeper, checking its current connection mode, or changing its blocking settings.
Why use it?
It helps determine how AgentKeeper is connected and guides you through enabling, disabling, or configuring its protection mode.

Skill for Claude CodeCodex

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add skills/rad-security/claude-code-plugin/setup
Any agent
npx skills add rad-security/claude-code-plugin --skill setup
Clone the repo
git clone --depth 1 https://github.com/rad-security/claude-code-plugin

Made for: Claude Code, Codex.

Per session 44 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,031 The whole file, excluding the scripts and references it only reads on demand.
Security scan B 2 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00044 $0.02031
Opus 5 $0.00022 $0.01015
Sonnet 5 $0.00009 $0.00406
Haiku 4.5 $0.00004 $0.00203

Measured yesterday against content hash c2bb9d1065a3, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade B, and why

setup scanned grade B with 2 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Reads agent configuration directoriesmediumAgent snooping

.claude/, .codex/, .gemini/ hold keys, settings and other credentials a mod has no legitimate need for.

grep -q 'agentkeeper\.dev' "$HOME/.claude/settings.json" 2>/dev/null && echo "USER_HOOKS" || echo "NO_USER_HOOKS"

Makes network callslowCapability

Not a fault in itself. Listed so you know the mod talks to something, and to what.

curl -s --max-time 5 "https://www.agentkeeper.dev/api/v1/claude-code/health" \
plugins/agentkeeper/skills/setup/SKILL.md · 212 lines

How it starts

The opening of the file, as written. The whole thing — 212 lines — stays where its author put it; the contents beside it link to each section on GitHub.

AgentKeeper Setup

You are running the AgentKeeper setup wizard. Determine the user's current mode and guide them accordingly.

Step 0: Parse Arguments

Check the user's slash command invocation for flags:

  • If the invocation includes --local (either /agentkeeper:setup --local or --local anywhere in the args): the user has explicitly opted into local-only mode. Set OPTED_LOCAL=true and remember this for Step 2.
  • Otherwise: OPTED_LOCAL=false.

Step 1: Determine Current Mode

Check these in order:

Check for push-hooks (security team deployment)

Read .claude/settings.json in the current project directory. Look for any hooks with URLs containing www.agentkeeper.dev. If found, the user is in push-hooks mode — their security team has already deployed AgentKeeper.

Check for user-level HTTP hooks (connected via plugin)

Run:

grep -q 'agentkeeper\.dev' "$HOME/.claude/settings.json" 2>/dev/null && echo "USER_HOOKS" || echo "NO_USER_HOOKS"

If USER_HOOKS, the user is in user-level hooks mode. This is the best state.

Check for API key (connected mode)

Check if the API key file exists and is non-empty. Use Bash:

AGENTKEEPER_DIR="$HOME/.agentkeeper-plugin"
[ -n "$CLAUDE_PLUGIN_DATA" ] && AGENTKEEPER_DIR="$CLAUDE_PLUGIN_DATA"
cat "$AGENTKEEPER_DIR/api_key" 2>/dev/null

If it contains a key, the user is in connected mode.

Otherwise: disconnected OR local mode

If none of the above matched, branch on the OPTED_LOCAL flag from Step 0:

  • OPTED_LOCAL=true → the user is in local-only mode (explicit opt-in). Proceed to the Local Mode display in Step 2.
  • OPTED_LOCAL=false → the user is in disconnected mode — hooks are not active and there is no account linked. Do NOT treat this as a success state. Proceed to the Disconnected Mode display in Step 2 and stop before Step 3.

Step 2: Show Status Based on Mode

If push-hooks mode:

Display:

AgentKeeper Setup

Mode: Push-Hooks (managed by your security team)
Hooks: Active — configured in .claude/settings.json
Source: Your security team deployed these hooks to this repository.

You're already covered. AgentKeeper hooks are evaluating tool calls
via your organization's API. No additional setup needed.

Run /agentkeeper:status to see your shield status.
Run /agentkeeper:audit to check your Claude Code configuration.

Read the full file on GitHub · 212 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 212 lines · 44 tokens per session scan B c2bb9d1065a3

Subscribe to this mod's changes

setup is a skill published in the GitHub repository rad-security/claude-code-plugin (2 stars, last pushed 25d ago), licensed MIT. It adds 44 tokens to every session and 2,031 once invoked, about $0.0002 per session on Opus 5. A static security scan graded it B with 2 findings (reads agent configuration directories, makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.

Related

Other skills, from other repositories

systematic-debugging

Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.

obra/superpowers · 21 tokens

next-cache-components-adoption

Turn on Cache Components in a Next.js app and resolve the blocking routes it surfaces. Use when the user wants to enable, adopt, or migrate to Cache Components, flip the cacheComponents flag, work through a flood of blocking-prerender / instant validation errors, run the cache-components-instant-false codemod, or…

vercel/next.js · 95 tokens

babysit-pr

Babysit a GitHub pull request after creation by continuously polling review comments, CI checks/workflow runs, and mergeability state until the PR is merged/closed or user help is required. Diagnose failures, retry likely flaky failures up to 3 times, auto-fix/push branch-related issues when appropriate, and keep…

openai/codex · 114 tokens

imagegen

Generate or edit raster images when the task benefits from AI-created bitmap visuals such as photos, illustrations, textures, sprites, mockups, or transparent-background cutouts. Use when Codex should create a brand-new image, transform an existing image, or derive visual variants from references, and the output…

openai/codex · 113 tokens

cpu-profile-analysis

Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…

microsoft/vscode · 71 tokens

next-cache-components-optimizer

Drive a Next.js route to instant navigation by setting up an agentic loop, under Cache Components / PPR, on initial load (hard navigation) and client-side navigation (soft navigation). Encode the goal as a failing @next/playwright instant() e2e and work it to green, one verified route at a time; the shipped test then…

vercel/next.js · 170 tokens