<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Verify and Share |</title><link>https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/</link><atom:link href="https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/index.xml" rel="self" type="application/rss+xml"/><description>Verify and Share</description><generator>HugoBlox Kit (https://hugoblox.com)</generator><language>en</language><lastBuildDate>Sat, 03 Oct 2026 00:00:00 +0000</lastBuildDate><image><url>https://haobin-tan.netlify.app/media/icon_hu_eee4a95885829ab2.png</url><title>Verify and Share</title><link>https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/</link></image><item><title>Trust It: Verifying Unsupervised Runs</title><link>https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/trust_it_verifying_unsupervised_runs/</link><pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate><guid>https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/trust_it_verifying_unsupervised_runs/</guid><description>
&lt;div class="callout flex px-4 py-3 mb-6 rounded-md border-l-4 bg-blue-100 dark:bg-blue-900 border-blue-500"
data-callout="note"
data-callout-metadata=""&gt;
&lt;span class="callout-icon pr-3 pt-1 text-blue-600 dark:text-blue-300"&gt;
&lt;svg height="24" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"&gt;&lt;path fill="none" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.5" d="m16.862 4.487l1.687-1.688a1.875 1.875 0 1 1 2.652 2.652L6.832 19.82a4.5 4.5 0 0 1-1.897 1.13l-2.685.8l.8-2.685a4.5 4.5 0 0 1 1.13-1.897zm0 0L19.5 7.125"/&gt;&lt;/svg&gt;
&lt;/span&gt;
&lt;div class="callout-content dark:text-neutral-300"&gt;
&lt;div class="callout-title font-semibold mb-1"&gt;Note&lt;/div&gt;
&lt;div class="callout-body"&gt;&lt;h3 id="tldr"&gt;TL;DR&lt;/h3&gt;
&lt;p&gt;Make the check as serious as the run was unsupervised:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;Read the diff yourself.&lt;/li&gt;
&lt;li&gt;Turn the tests into a hook that gates the turn.&lt;/li&gt;
&lt;li&gt;Verify headless runs by their JSON result and exit code.
&lt;ul&gt;
&lt;li&gt;Get a cold second opinion on anything that matters.&lt;/li&gt;
&lt;/ul&gt;
&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="keep-unattended-runs-in-auto-mode"&gt;Keep Unattended Runs in Auto Mode&lt;/h2&gt;
&lt;p&gt;When a run goes unattended at work, keep it in auto mode rather than bypass permissions. In auto mode, the classifier still reviews each action for danger. But it never judges whether the code is actually correct. It only flags dangerous actions.&lt;/p&gt;
&lt;h2 id="start-with-the-diff-not-the-summary"&gt;Start with the Diff, Not the Summary&lt;/h2&gt;
&lt;p&gt;Don&amp;rsquo;t start with Claude&amp;rsquo;s summary of what it did. Start with the diff itself.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Run &lt;code&gt;/code-review&lt;/code&gt; to walk the changes and flag issues.&lt;/li&gt;
&lt;li&gt;Then put your own eyes on &lt;code&gt;git diff&lt;/code&gt;.&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Read what changed. Read the files that were part of the plan first, then look for anything outside it.&lt;/p&gt;
&lt;h2 id="turn-tests-into-a-gate-not-a-promise"&gt;Turn Tests into a Gate, Not a Promise&lt;/h2&gt;
&lt;p&gt;The real gate on an unsupervised run is whether the tests passed. Don&amp;rsquo;t leave that to trust. Wire it as a &lt;strong&gt;hook&lt;/strong&gt; so Claude can&amp;rsquo;t skip it.&lt;/p&gt;
&lt;p&gt;A couple of hooks do the job:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;A &lt;strong&gt;stop hook&lt;/strong&gt; that runs your tests and refuses to end the turn on a failure.&lt;/li&gt;
&lt;li&gt;A &lt;strong&gt;post-tool-use hook&lt;/strong&gt; that lints and type checks after every edit.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The key detail is the exit code. A hook that exits with &lt;code&gt;exit 2&lt;/code&gt; feeds the failure straight back to Claude. Claude reads that failure and fixes it without you asking.&lt;/p&gt;
&lt;h2 id="get-a-cold-second-opinion"&gt;Get a Cold Second Opinion&lt;/h2&gt;
&lt;p&gt;Open a fresh session or sub-agent and have it review the changed code with no memory of how the code was built. Because it has no stake in the approach, it catches the things the original run talked itself past. A second reviewer with fresh eyes finds what the author rationalized away.&lt;/p&gt;</description></item><item><title>Plugins</title><link>https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/plugins/</link><pubDate>Sat, 03 Oct 2026 00:00:00 +0000</pubDate><guid>https://haobin-tan.netlify.app/doc/claude/claude-code-in-action/03-verify-and-share/plugins/</guid><description>
&lt;div class="callout flex px-4 py-3 mb-6 rounded-md border-l-4 bg-blue-100 dark:bg-blue-900 border-blue-500"
data-callout="note"
data-callout-metadata=""&gt;
&lt;span class="callout-icon pr-3 pt-1 text-blue-600 dark:text-blue-300"&gt;
&lt;svg height="24" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"&gt;&lt;path fill="none" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.5" d="m16.862 4.487l1.687-1.688a1.875 1.875 0 1 1 2.652 2.652L6.832 19.82a4.5 4.5 0 0 1-1.897 1.13l-2.685.8l.8-2.685a4.5 4.5 0 0 1 1.13-1.897zm0 0L19.5 7.125"/&gt;&lt;/svg&gt;
&lt;/span&gt;
&lt;div class="callout-content dark:text-neutral-300"&gt;
&lt;div class="callout-title font-semibold mb-1"&gt;Note&lt;/div&gt;
&lt;div class="callout-body"&gt;&lt;h3 id="tldr"&gt;TL;DR&lt;/h3&gt;
&lt;ul&gt;
&lt;li&gt;When you use plugins, read before you install. A plugin runs code with your privileges, so look at its hooks, agents, and MCP servers first.&lt;/li&gt;
&lt;li&gt;When you build one, package your .claude the moment it works. One manifest, one install.&lt;/li&gt;
&lt;/ul&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="what-is-a-plugin"&gt;What Is a Plugin&lt;/h2&gt;
&lt;p&gt;A plugin is one &lt;strong&gt;installable unit&lt;/strong&gt;.&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;It bundles everything you&amp;rsquo;d otherwise share by hand: skills, subagents, hooks, and MCP server configs, plus the longer tail of stuff like language server protocol servers, background monitors, themes, and a slice of &lt;code&gt;settings.json&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;One version, one install.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Inside a session, you can install one directly by name. Example:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/plugin install github@claude-plugins-official
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;h2 id="adding-a-marketplace-for-your-team"&gt;Adding a Marketplace for Your Team&lt;/h2&gt;
&lt;p&gt;For a team, the better move is to add a &lt;strong&gt;private marketplace&lt;/strong&gt; once. A marketplace is a shared source that plugins resolve through:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-bash" data-lang="bash"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;/plugin marketplace add your-org/claude-plugins
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;Once it&amp;rsquo;s added, every install after that resolves through it. You get centralized discovery, version tracking, and updates in one place instead of scattered across everyone&amp;rsquo;s laptop.&lt;/p&gt;
&lt;h2 id="read-before-you-install"&gt;Read before You Install&lt;/h2&gt;
&lt;p&gt;Before you install, check the plugin&amp;rsquo;s details. Claude Code shows you what it will install and estimates the context cost, along with a plain warning that Anthropic doesn&amp;rsquo;t control what&amp;rsquo;s inside third-party plugins.&lt;/p&gt;
&lt;p&gt;Two things worth knowing about where plugins come from:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;The in-app submission form posts to the community marketplace after Anthropic&amp;rsquo;s automated review.&lt;/li&gt;
&lt;li&gt;The official marketplace is curated on its own separate track.&lt;/li&gt;
&lt;/ul&gt;
&lt;div class="callout flex px-4 py-3 mb-6 rounded-md border-l-4 bg-emerald-100 dark:bg-emerald-900 border-emerald-500"
data-callout="tip"
data-callout-metadata=""&gt;
&lt;span class="callout-icon pr-3 pt-1 text-emerald-600 dark:text-emerald-300"&gt;
&lt;svg height="24" xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"&gt;&lt;path fill="none" stroke="currentColor" stroke-linecap="round" stroke-linejoin="round" stroke-width="1.5" d="M12 18v-5.25m0 0a6 6 0 0 0 1.5-.189m-1.5.189a6 6 0 0 1-1.5-.189m3.75 7.478a12.1 12.1 0 0 1-4.5 0m3.75 2.383a14.4 14.4 0 0 1-3 0M14.25 18v-.192c0-.983.658-1.823 1.508-2.316a7.5 7.5 0 1 0-7.517 0c.85.493 1.509 1.333 1.509 2.316V18"/&gt;&lt;/svg&gt;
&lt;/span&gt;
&lt;div class="callout-content dark:text-neutral-300"&gt;
&lt;div class="callout-title font-semibold mb-1"&gt;Tip&lt;/div&gt;
&lt;div class="callout-body"&gt;&lt;p&gt;Install plugins and add marketplaces &lt;strong&gt;only&lt;/strong&gt; from sources you truly trust, and check what a plugin actually does before turning it on.&lt;/p&gt;&lt;/div&gt;
&lt;/div&gt;
&lt;/div&gt;
&lt;h2 id="components-run-alongside-yours"&gt;Components Run Alongside Yours&lt;/h2&gt;
&lt;p&gt;A plugin doesn&amp;rsquo;t overwrite your configuration. Its components run alongside your own.&lt;/p&gt;
&lt;p&gt;Things that are worth noticing&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Hooks stack&lt;/strong&gt;.&lt;/p&gt;
&lt;p&gt;A plugin&amp;rsquo;s PreToolUse hook and your own PreToolUse hook both fire on every tool call. Neither replaces the other. -&amp;gt; This is exactly why you read the details first.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Skills, agents, and commands are namespaced under the plugin name, so they never clash with yours. A plugin can also ship a &lt;code&gt;settings.json&lt;/code&gt; file, but only a narrow one. Claude Code honors just two keys from it: the agent and subagent status line keys.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Agent key&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Setting it promotes one of the plugin&amp;rsquo;s subagents to the main thread, along with its system prompt, tool restrictions, and model. In other words, enabling the plugin can change how Claude Code behaves by default.&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;h2 id="packaging-your-own-plugin"&gt;Packaging Your Own Plugin&lt;/h2&gt;
&lt;p&gt;Once you&amp;rsquo;ve built a &lt;code&gt;.claude&lt;/code&gt; directory that works, don&amp;rsquo;t make your team copy and paste it between machines. &lt;strong&gt;Package it&lt;/strong&gt; instead.&lt;/p&gt;
&lt;p&gt;A plugin uses the same &lt;code&gt;.claude&lt;/code&gt; shape you already use:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;One folder per skill.&lt;/li&gt;
&lt;li&gt;One markdown file per subagent under &lt;code&gt;agents&lt;/code&gt;.&lt;/li&gt;
&lt;li&gt;&lt;code&gt;hooks/hooks.json&lt;/code&gt; and &lt;code&gt;.mcp.json&lt;/code&gt;, at the plugin root.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The directory structure does most of the work. Claude Code discovers components by convention.&lt;/p&gt;
&lt;h2 id="the-manifest"&gt;The Manifest&lt;/h2&gt;
&lt;p&gt;An optional manifest lives at &lt;code&gt;.claude-plugin/plugin.json&lt;/code&gt; and holds the name, version, description, and author. Example:&lt;/p&gt;
&lt;div class="highlight"&gt;&lt;pre tabindex="0" class="chroma"&gt;&lt;code class="language-json" data-lang="json"&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;name&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;svg-splitter-review&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;version&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;0.1.0&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;description&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Reviews the SVG Splitter repo&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;author&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="p"&gt;{&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="nt"&gt;&amp;#34;name&amp;#34;&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt; &lt;span class="s2"&gt;&amp;#34;Lewis Menelaws&amp;#34;&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt; &lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;span class="line"&gt;&lt;span class="cl"&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;p&gt;A couple of details are worth knowing:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Name is the only required field.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;It namespaces your skills as &lt;code&gt;/plugin-name:skill-name&lt;/code&gt;, so a skill in this plugin runs as &lt;code&gt;/svg-splitter-review:&amp;lt;skill-name&amp;gt;&lt;/code&gt;. That keeps your skills from colliding with anyone else&amp;rsquo;s.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;&lt;strong&gt;Version it like any other dependency.&lt;/strong&gt;&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;</description></item></channel></rss>