Ranking|Claude Code Mods

ModsCode / Claude Code Mods / Ranking / http-lab

http-lab

An HTTP tool for API work: status, timing, trimmed headers and a body shaped to fit; localhost runs freely, other hosts ask once a session; an /http pane of the session's requests with replay and copy-as-curl.

Code you can checkTerminal + desktopPaneToastBoxButtonText
network, draws

What it does

  • Draws a pane, toasts
  • Adds /http
  • Watches tool calls and can refuse them
  • Hooks classic.PreToolUse, classic.UserPromptSubmit, session.start
  • Calls the network

Good points

  • Written in TypeScript
  • Handles errors

Code to start from

A starter ModsCode writes from the drawing it read, and the mod's own lines that draw, where there are any.

Starter (register.tsx)

register.tsx
import type { Register } from 'claude-code'

// Drawn like http-lab by mako-code (pane, toast), as ModsCode read it from the mod's code:
// https://modscode.com/claude-mods/mods/mako-code-http-lab/
// Written by ModsCode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
  // the pane: open it with $.ui.open({ id: 'my-pane', title: "HTTP" })
  on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
    const { Box, Text, Button } = $.ui.resolve(e)
    const status = '…'
    const method = '…'
    const url = '…'
    const error = '…'
    const dns = '…'
    const connect = '…'
    const tls = '…'
    const ttfb = '…'
    const total = '…'
    const k = '…'
    const v = '…'
    const reqBody = '…'
    const line = '…'
    const allowed = '…'
    const declined = '…'
    return (
      <Box flexDirection="column">
        <Box flexDirection="row" gap={1}>
          <Text>
            ►
          </Text>
          <Button plain label={`${status} ${method} ${url}…   (you)`} />
        </Box>
        <Box flexDirection="row" gap={1}>
          <Text>
            ►
          </Text>
          <Button plain label={`${status} ${method} ${url}…   (you)`} />
        </Box>
        <Box flexDirection="row" gap={1}>
          <Text>
            ►
          </Text>
          <Button plain label={`${status} ${method} ${url}…   (you)`} />
        </Box>
        <Box flexDirection="column" marginTop={1}>
          <Text bold wrap="wrap">
            {method}
            {" "}
            {url}
          </Text>
          <Text wrap="wrap">
            {`× ${error}`}
          </Text>
          <Text dimColor>
            {"dns "}
            {dns}
            {" ms · connect "}
            {connect}
            {" ms"}
            {` · tls ${tls} ms`}
            {" · first byte "}
            {ttfb}
            {" ms · total "}
            {total}
            {" ms"}
          </Text>
          <Text dimColor>
            request headers
          </Text>
          <Text wrap="truncate-end">
            {`  ${k}: ${v}`}
          </Text>
          <Text wrap="truncate-end">
            {`  ${k}: ${v}`}
          </Text>
          <Text wrap="truncate-end">
            {`  ${k}: ${v}`}
          </Text>
          <Text wrap="truncate-end" dimColor>
            {`  body: ${reqBody}`}
          </Text>
          <Text dimColor>
            response headers
          </Text>
          <Text wrap="truncate-end">
            {`  ${k}: ${v}`}
          </Text>
          <Text wrap="truncate-end">
            {`  ${k}: ${v}`}
          </Text>
          <Text wrap="truncate-end">
            {`  ${k}: ${v}`}
          </Text>
          <Text dimColor>
            body
          </Text>
          <Text wrap="truncate-end">
            {`  ${line}`}
          </Text>
          <Text wrap="truncate-end">
            {`  ${line}`}
          </Text>
          <Text wrap="truncate-end">
            {`  ${line}`}
          </Text>
          <Box marginTop={1} gap={1}>
            <Button hotkey="r" label="Replay" />
            <Button hotkey="c" label="Copy as curl" />
            <Button hotkey="l" label="Clear" />
            <Button hotkey="x" role="dismiss" label="Close" />
          </Box>
        </Box>
        <Text dimColor wrap="wrap">
          {`allowed: ${allowed}`}
          {" · "}
          {`declined: ${declined}`}
        </Text>
      </Box>
    )
  })

  on('session.start', async ($, e, next) => {
    const error = '…'
    const masked = '…'
    await $.ui.toast(`Replay failed: ${error}`)
    await $.ui.toast(`Copied as curl${masked}.`)
    return next(e)
  })
}

The mod's own code

Shown under the mod's licence (MIT); its text is below. Keep the notice if you copy these lines.

mods/abilities/http-lab/hooks/register.tsx lines 373–480 · Pane
  on('ui.render', { component: 'Pane', requestId: PANE }, async ($, e) => {
    const { Box, Text, Button } = $.ui.resolve(e)
    const list = await read($, requests)
    const sel = await read($, selected)
    const hostMap = await read($, hosts)
    const width = Math.max(30, e.props.bodyColumns - 2)
    if (list.length === 0) {
      return (
        <Box flexDirection="column">
          <Text dimColor>No requests yet. Claude sends them with the request tool: localhost runs freely, any other host is asked about once a session.</Text>
          <Box marginTop={1}>
            <Button key="close" hotkey="x" role="dismiss" label="Close" onPress={() => void $.ui.close({ id: PANE })} />
          </Box>
        </Box>
      )
    }
    const current = list.find(x => x.id === sel) ?? list.at(-1)
    const urlRoom = Math.max(16, width - 30)
    const declined = Object.keys(hostMap).filter(k => hostMap[k] === 'deny')
    const allowed = Object.keys(hostMap).filter(k => hostMap[k] === 'allow')
    return (
      <Box flexDirection="column">
        {[...list]
          .reverse()
          .slice(0, 30)
          .map(x => {
            const status = x.error !== null ? 'ERR' : String(x.status ?? '')
            const url = x.url.replace(/^https?:\/\//, '')
            return (
              <Box key={`row:${x.id}`} flexDirection="row" gap={1}>
                <Text color={statusColor(x)}>{current?.id === x.id ? '►' : '●'}</Text>
                <Button
                  key={`req:${x.id}`}
                  plain
                  dimColor={current?.id !== x.id}
                  label={`${status.padEnd(3)} ${x.method.padEnd(6)} ${url.length > urlRoom ? `${url.slice(0, urlRoom - 1)}…` : url}  ${x.ms === null ? '' : `${x.ms} ms`}${x.origin === 'person' ? ' (you)' : ''}`}
                  onPress={() => void update($, selected, () => x.id)}
                />
              </Box>
            )
          })}
        {current !== undefined && (
          <Box flexDirection="column" marginTop={1}>
            <Text bold wrap="wrap">
              {current.method} {current.url}
            </Text>
            <Text color={statusColor(current)} wrap="wrap">
              {current.error !== null
                ? `× ${current.error}`
                : `→ ${current.status} ${current.reason} · ${current.ms} ms · ${fmtSize(current.size ?? 0)} · ${hhmmss(current.at)}`}
            </Text>
            {current.timing !== null && (
              <Text dimColor>
                dns {current.timing.dns} ms · connect {current.timing.connect} ms{current.timing.tls > 0 ? ` · tls ${current.timing.tls} ms` : ''} · first byte {current.timing.ttfb} ms · total {current.timing.total} ms
              </Text>
            )}
            {current.reqHeaders.length > 0 && <Text dimColor>request headers</Text>}
            {current.reqHeaders.map(([k, v], i) => (
              <Text key={`rqh:${i}`} wrap="truncate-end">
                {`  ${k}: ${v}`}
              </Text>
            ))}
            {current.reqBody !== null && (
              <Text wrap="truncate-end" dimColor>
                {`  body: ${current.reqBody.slice(0, 300)}`}
              </Text>
            )}
            {current.resHeaders.length > 0 && <Text dimColor>response headers</Text>}
            {current.resHeaders.map(([k, v], i) => (
              <Text key={`rsh:${i}`} wrap="truncate-end">
                {`  ${k}: ${v}`}
              </Text>
            ))}
            {current.preview !== '' && <Text dimColor>body</Text>}
            {current.preview
              .split('\n')
              .slice(0, 24)
              .map((line, i) => (
                <Text key={`b:${i}`} wrap="truncate-end">
                  {`  ${line}`}
                </Text>
              ))}
            <Box marginTop={1} gap={1}>
              <Button key="replay" hotkey="r" label="Replay" onPress={() => void replay($, current.id)} />
              <Button key="curl" hotkey="c" label="Copy as curl" onPress={press => void copyCurl($, current.id, press.surface)} />
              <Button
                key="clear"
                hotkey="l"
                label="Clear"
                onPress={() => {
                  secrets.clear()
                  void update($, requests, () => [])
                }}
              />
              <Button key="close" hotkey="x" role="dismiss" label="Close" onPress={() => void $.ui.close({ id: PANE })} />
            </Box>
          </Box>
        )}
        {(allowed.length > 0 || declined.length > 0) && (
          <Text dimColor wrap="wrap">
            {allowed.length > 0 ? `allowed: ${allowed.join(', ')}` : ''}
            {allowed.length > 0 && declined.length > 0 ? ' · ' : ''}
            {declined.length > 0 ? `declined: ${declined.join(', ')}` : ''}
          </Text>
        )}
      </Box>
    )
  })
Licence text (MIT)
MIT License

Copyright (c) 2026 mako-code

Permission is hereby granted, free of charge, to any person obtaining a copy
of this software and associated documentation files (the "Software"), to deal
in the Software without restriction, including without limitation the rights
to use, copy, modify, merge, publish, distribute, sublicense, and/or sell
copies of the Software, and to permit persons to whom the Software is
furnished to do so, subject to the following conditions:

The above copyright notice and this permission notice shall be included in all
copies or substantial portions of the Software.

THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR
IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY,
FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE
AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER
LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM,
OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE
SOFTWARE.

How to build this: Pane (panel), Deny a tool call

What its code calls

networkruns programswrites filesenv varstool calls

What its code shows

Read from the source at commit ec6ea2383749 on 2026-10-11. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.

Decides the listing: code you can check
Entry readEvery module hooks/hooks.json names was read.mods/abilities/http-lab/hooks/register.tsx
ParsesEvery file parses as TypeScript or JavaScript.2 files parsed
All its code is in the modEvery import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod
ReadableNo minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs
Calls in the openNetwork and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open
For you to weigh before installing
Where it drawsThe terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both
Install lineWhether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.listed in its repository's .claude-plugin/marketplace.json: installs from there
Programs on WindowsWhether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).runs no program a Windows PC lacks
NetworkWhether every fetch names its https host in the code.no network
ProgramsWhether every program it starts is named in the code and is not a shell, an interpreter or a network tool.mods/abilities/http-lab/hooks/register.tsx:59 curl (reaches the network); mods/abilities/http-lab/hooks/register.tsx:104 a program named at run time; mods/abilities/http-lab/hooks/register.tsx:261 powershell (a shell or interpreter); mods/abilities/http-lab/hooks/register.tsx:268 a program named at run time
Reads and sendsWhether it both reads something of yours (files, environment variables, the transcript, settings) and reaches outside (the network, an MCP server, another session, telemetry).reads environment variables and files and reaches the network
Keys in the sourceWhether the source holds what looks like an API key or a private key.no keys in the source
LicenceAn open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets ModsCode show its code; otherwise the code is linked.MIT

This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen

Install it

Check it yourself before you install it. Mods run unsandboxed, with your permissions, and ModsCode does not vouch for what this code does. Read its code (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.

From its marketplace

Its repository is its marketplace. Add that marketplace (in the terminal with these commands, or in the desktop app's plugin settings) and install the mod from it:

/plugin marketplace add mako-code/gobworks
/plugin install http-lab@gobworks
/reload-plugins

This installs the marketplace's latest commit, which may not be the one read here (ec6ea2383749). Compare them before you install. /reload-plugins loads it into a session that is already open.

Try the commit ModsCode read

No marketplace needed. In a terminal, clone the repository, check out the commit read, validate the mod, and load it for one session:

git clone https://github.com/mako-code/gobworks
git -C gobworks checkout ec6ea23837494b5b13124caa186450be8b42bf2d
claude plugin validate gobworks/mods/abilities/http-lab
claude --plugin-dir gobworks/mods/abilities/http-lab

The validate line lists the events the mod hooks and what it asks Claude Code to do, without running it. The last line loads the mod for this session only and writes nothing to your settings. If the author has rewritten history, the commit may no longer exist.

Ask Claude about it

With the ModsCode connector added, Claude can read this mod's code and what it reaches, and build on them. Ask it like this:

Read the ModsCode mod "mako-code-http-lab" with its code and make me one like it

Search them from Claude: the MCP connector

Similar mods

More from this repository

See all 117 mods in this repository

Badge for your README

If this is your mod, paste this into your README. It links to this page.

README.md
[![ModsCode](https://modscode.com/badge/mako-code-http-lab.svg)](https://modscode.com/claude-mods/mods/mako-code-http-lab/)