Skip to content

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Latest commit

 

History

2 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 

Repository files navigation

mlab-claude-mod

Claude Code mod that spots CVE IDs in Claude's replies and, on hover, shows a card enriched with data from vuln.mlab.sh.

I looked at the xz backdoor, see CVE-2024-3094, and Log4Shell CVE-2021-44228.
 ⚠ CVE-2024-3094 10   ⚠ CVE-2021-44228 10 KEV
                       ╰─ hover → card floats above

What it does

  • Detects CVE-YYYY-NNNN (case-insensitive) in every block of Claude's replies.
  • Adds a row of chips under the text, one per CVE, colored by CVSS severity: magenta = CRITICAL, red = HIGH, yellow = MEDIUM, green = LOW, gray = unknown or still loading. The badge shows the CVSS score, plus KEV when the CVE is in the CISA KEV catalog.
  • Hovering a chip floats a card above the text, without shifting anything:
    • severity and CVSS score, KEV with its due date;
    • publication date, EPSS and its percentile, CWE;
    • description (200 characters max), affected products;
    • link to https://vuln.mlab.sh/cve/<id>.
  • Data comes from the public API https://vuln.mlab.sh/api/v1/cve/<id>, no token needed. Each CVE is fetched once per session.
  • The stored message is untouched: only the display changes, and Claude still reads the original text.

Requirements

  • Claude Code with mod support (function hooks / hooks modules), in the terminal or the desktop app's Code tab.
  • Network access to vuln.mlab.sh.

Installation

1. Get the repo

git clone git@github.com:mlab-sh/mlab-claude-mod.git ~/mlab-claude-mod

2a. Terminal: load the mod for one session

claude --plugin-dir ~/mlab-claude-mod

The folder is watched: any code change hot-reloads the mod.

2b. Desktop app, or load it in every session

The desktop app cannot take --plugin-dir. Declare the folder in ~/.claude/settings.json instead (project settings are not read for this):

{
  "env": {
    "CLAUDE_CODE_PLUGIN_DIRS": "~/mlab-claude-mod"
  }
}

To load several folders, separate the paths with : (macOS/Linux) or ; (Windows). Then restart the app or the session.

3. Check it works

Ask Claude to mention a CVE, e.g. "tell me about CVE-2021-44228". A ⚠ CVE-2021-44228 10 KEV chip appears under the reply; hover it.

Known limitations

  • Mouse hover only: needs a terminal that reports the mouse (fullscreen mode) or the desktop app.
  • Card clipped on short replies: a card cannot extend past its message. On a reply shorter than about 7 lines, its top gets cut off.
  • Chips under the text: the text is rendered as one block, so the CVE isn't highlighted inside the sentence; a chip is added below instead.
  • No retry: if the API fails or doesn't know the CVE, the chip shows ? until the session ends.
  • Black background: the card has an opaque black background, which stands out in light theme. Change backgroundColor in hooks/register.tsx to adjust it.

Layout

.claude-plugin/plugin.json   plugin manifest (name, version, types contract)
hooks/hooks.json             declares the hooks module
hooks/register.tsx           all of the mod's code
types/index.d.ts             shape of a CVE card + shared state (cve-hover.cves)

How hooks/register.tsx works:

  1. A ui.render hook on AssistantMessage receives each reply block's text. With no CVE in it, it falls back to the default rendering.
  2. Otherwise it redraws the block: the original text (Markdown), then the chip row.
  3. For each unknown CVE, ensure() calls $.http.fetch and stores the result in the cve-hover.cves state. That write redraws the chips and cards.
  4. Each chip is a Box with a key, which makes it its own hover scope. Its card is a Box with position="absolute" and display="none", switched to display: 'flex' on hover, so it overlays the text without moving it.

Development

Validate the manifest and the module:

claude plugin validate .

The report lists the hooks, the $ calls, the state keys read and written, and anything the engine would refuse.

Run with hot reload:

claude --plugin-dir .

If a hook fails, a dim cve-hover: … line appears in the conversation. claude --debug has the details.

The .claude-plugin/types/ folder is generated by Claude Code for editor typing; git ignores it.

About

No description, website, or topics provided.

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages