modscode JA

modscode / Gallery / tap

tap

Tap: a live recorder on the hook chain, with a secret guard

Code you can checkTerminal + desktopPaneBandBoxButtonMarkdownSvgText

What it does

  • Draws a pane, a band above the prompt
  • Adds /tap
  • Watches tool calls
  • Hooks prompt.submit, session.append, session.start, turn.complete

Good points

  • No network calls
  • Starts no processes
  • Small: 263 lines
  • Written in TypeScript

Code to start from

Two kinds: a starter modscode writes from the design above, and the lines of the mod's own code that draw it.

Starter (register.tsx)

register.tsx
import type { Register } from 'claude-code'

// Drawn like tap by gfsaaser24 (pane, band), as modscode read it from the mod's code:
// https://modscode.com/gallery/gfsaaser24-tap/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
  // the pane: open it with $.ui.open({ id: 'my-pane', title: "Tap" })
  on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
    const { Box, Markdown, Text, Svg, Button } = $.ui.resolve(e)
    const turns = '…'
    const toolCalls = '…'
    const errors = '…'
    const rows = '…'
    const contextBar = '…'
    const ctxPct = '…'
    const ms = '…'
    const costUsd = '…'
    const outTok = '…'
    const cacheRead = '…'
    const durationChart = '…'
    const at = '…'
    const tool = '…'
    const ms2 = '…'
    const at2 = '…'
    const tool2 = '…'
    const ms3 = '…'
    const at3 = '…'
    const tool3 = '…'
    const ms4 = '…'
    const map = '…'
    const secretsSeen = '…'
    const redacted = '…'
    return (
      <Box flexDirection="column" gap={1}>
        <Markdown text="**Tap** shows the *translation layer*. It sits on the hook chain and sees each thing that crosses the wall: every tool …" />
        <Box flexDirection="row" columnGap={2} flexWrap="wrap">
          <Text>
            <Text bold>
              {turns}
            </Text>
            {" "}
            <Text dimColor>
              turns
            </Text>
          </Text>
          <Text>
            <Text bold>
              {toolCalls}
            </Text>
            {" "}
            <Text dimColor>
              tool calls
            </Text>
          </Text>
          <Text>
            <Text bold color="error">
              {errors}
            </Text>
            {" "}
            <Text dimColor>
              errors
            </Text>
          </Text>
          <Text>
            <Text bold>
              {rows}
            </Text>
            {" "}
            <Text dimColor>
              transcript rows
            </Text>
          </Text>
        </Box>
        <Svg source={`${contextBar}`} alt={`Context window ${ctxPct} percent full`} width={340} height={30} />
        <Box borderStyle="round" borderColor="suggestion" paddingX={1} flexDirection="column">
          <Text>
            <Text bold>
              Last turn
            </Text>
            {" "}
            {ms}
            {" s"}
            <Text dimColor>
              {" / session cost $"}
              {costUsd}
            </Text>
          </Text>
          <Text dimColor>
            {outTok}
            {" tokens out / "}
            {cacheRead}
            {" read from cache"}
          </Text>
        </Box>
        <Svg source={`${durationChart}`} alt="Bar chart of tool call time" width={340} height={78} />
        <Box flexDirection="column">
          <Text bold>
            Tool calls
          </Text>
          <Text dimColor>
            None yet.
          </Text>
          <Text wrap="truncate-end">
            <Text dimColor>
              {at}
            </Text>
            {" "}
            <Text>
              ●
            </Text>
            {" "}
            {tool}
            {" "}
            <Text dimColor>
              {ms2}
              {" ms"}
            </Text>
          </Text>
          <Text wrap="truncate-end">
            <Text dimColor>
              {at2}
            </Text>
            {" "}
            <Text>
              ●
            </Text>
            {" "}
            {tool2}
            {" "}
            <Text dimColor>
              {ms3}
              {" ms"}
            </Text>
          </Text>
          <Text wrap="truncate-end">
            <Text dimColor>
              {at3}
            </Text>
            {" "}
            <Text>
              ●
            </Text>
            {" "}
            {tool3}
            {" "}
            <Text dimColor>
              {ms4}
              {" ms"}
            </Text>
          </Text>
        </Box>
        <Box flexDirection="column">
          <Text bold>
            Transcript rows, by door
          </Text>
          <Text dimColor wrap="wrap">
            {map}
          </Text>
        </Box>
        <Box borderStyle="round" borderColor="success" paddingX={1} flexDirection="column">
          <Text>
            <Text bold>
              Secret guard
            </Text>
            {" is "}
            <Text color="success">
              on
            </Text>
          </Text>
          <Text dimColor>
            {secretsSeen}
            {" keys seen in tool results / "}
            {redacted}
            {" hidden from the model"}
          </Text>
          <Button variant="secondary" label="Turn guard off" />
        </Box>
        <Text dimColor>
          How: hooks on tool.call, turn.complete and session.append. Each one calls next(e).
        </Text>
      </Box>
    )
  })

  // the band above the prompt; what else goes there is drawn under it
  on('ui.render', { component: 'AbovePrompt' }, async ($, e, next) => {
    const { Box, Text, Button } = $.ui.resolve(e)
    const parts = '…'
    return (
      <Box flexDirection="column">
        <Box columnGap={1}>
          <Text dimColor>
            {parts}
          </Text>
          <Button label="Tap" />
        </Box>
        {await next(e)}
      </Box>
    )
  })
}

The mod's own code

Its licence text was not found at the commit read, so only the places in the source are linked.

What its code calls

tool calls

The design, read from code

Drawn from the mod's source at the commit read, not from a run: a list is drawn three times, a condition takes its first branch that draws in the desktop app, and a value only the run time knows is shown as a made-up sample (dotted underline) or left out. Colours and type are this site's.

What its code shows

Read from the source at commit a59bbddc296e on 2026-10-06. The first group decides whether a mod is listed; the rest is for you to weigh. A later commit is not read until the next crawl.

Decides the listing: code you can check
Entry readEvery module hooks/hooks.json names was read.tap/hooks/register.tsx
ParsesEvery file parses as TypeScript or JavaScript.1 files parsed
All its code is in the modEvery import is a file of the mod or the engine's own module; no packages, no require.all its code is in the mod
ReadableNo minified lines, no eval or new Function, no import of a computed path, no encoded blobs.no minified code, no eval, no encoded blobs
Calls in the openNetwork and programs are reached as $.http.fetch and $.process.run in place, never passed around.every call outside goes through $ in the open
For you to weigh before installing
Where it drawsThe terminal, the desktop app, both, or nothing (hooks only: a guard or a prompt rewriter), as its code says. Shown, never a reason to leave a mod out.draws in the terminal and the desktop app, the same in both
Install lineWhether its repository's own .claude-plugin/marketplace.json lists it, so it installs from that marketplace with the lines on its page.its repository's .claude-plugin/marketplace.json does not list it: no install line to give
Programs on WindowsWhether every program it starts through $.process exists on Windows (tail, date, open, osascript, /usr/… do not).runs no program a Windows PC lacks
NetworkWhether every fetch names its https host in the code.no network
ProgramsWhether every program it starts is named in the code and is not a shell, an interpreter or a network tool.starts no programs
Reads and sendsWhether it both reads files or environment variables and reaches the network.reaches no network
Keys in the sourceWhether the source holds what looks like an API key or a private key.no keys in the source
LicenceAn open licence (MIT, Apache-2.0, BSD, ISC, Unlicense, 0BSD, CC0) with its text lets modscode show its code; otherwise the code is linked.no licence

This is a reading of the code text, not a security review: it does not run the mod, and it cannot see what a program the mod starts does. The check before installing is yours. How mods are chosen

Install it

Check it yourself before you install it. Mods run unsandboxed, with your permissions, and modscode does not vouch for what this code does. Read the code below (or run claude plugin validate . in its folder), weigh what it reaches, and install the commit you read.

Its repository's .claude-plugin/marketplace.json does not list it, so there is no install line to give. Read it as code, or follow its author's README.

Ask Claude about it

With the modscode connector added, Claude can read this design, what its code reaches and its code, and build on them. Ask it like this:

Read the modscode design "gfsaaser24-tap" with its code and make me a pane like it

Search them from Claude: the MCP connector

Similar designs