jev-seclint
An instant security reviewer on every code edit: ~20 yes/no checks per edit answered by Jev in a few hundred ms, fed back to Claude.
何をするか
- 欄・トーストを描く
- /seclint を足す
- ツールの呼び出しを見張る(止めることがある)
- session.end・session.start・turn.startにフックする
- ターンをまたいで自分の状態を持つ
良いところ
- プロセスを起こさない
- TypeScript で書かれている
- エラーを扱う
- ファイルを書かない
作り始めるためのコード
2 種類あります。上のデザインから modscode が書いた雛形と、その Mod 自身のコードのうち描いている部分です。
雛形(register.tsx)
import type { Register } from 'claude-code'
// Drawn like jev-seclint by mako-code (pane, toast), as modscode read it from the mod's code:
// https://modscode.com/gallery/mako-code-jev-seclint/
// Written by modscode from that reading, not copied from the mod: use it as you like.
// Each value below stands for one the mod works out at run time; put in your own.
export const register: Register = on => {
// the pane: open it with $.ui.open({ id: 'my-pane', title: "Seclint" })
on('ui.render', { component: 'Pane', requestId: 'my-pane' }, async ($, e) => {
const { Box, Text, Button } = $.ui.resolve(e)
const fmtP = '…'
const length = '…'
const ledgerLine = '…'
const name = '…'
const fix = '…'
const hhmm = '…'
const file = '…'
const fmtP2 = '…'
const hhmm2 = '…'
const file2 = '…'
const fmtP3 = '…'
const hhmm3 = '…'
const file3 = '…'
const fmtP4 = '…'
const name2 = '…'
const fix2 = '…'
const hhmm4 = '…'
const file4 = '…'
const fmtP5 = '…'
const hhmm5 = '…'
const file5 = '…'
const fmtP6 = '…'
const hhmm6 = '…'
const file6 = '…'
const fmtP7 = '…'
const name3 = '…'
const fix3 = '…'
const hhmm7 = '…'
const file7 = '…'
const fmtP8 = '…'
const hhmm8 = '…'
const file8 = '…'
const fmtP9 = '…'
const hhmm9 = '…'
const file9 = '…'
const fmtP10 = '…'
const name4 = '…'
const checks = '…'
const flags = '…'
const fmtP11 = '…'
const fmtP12 = '…'
const name5 = '…'
const checks2 = '…'
const flags2 = '…'
const fmtP13 = '…'
const fmtP14 = '…'
const name6 = '…'
const checks3 = '…'
const flags3 = '…'
const fmtP15 = '…'
const fmtP16 = '…'
return (
<Box flexDirection="column">
<Text bold>
Jev seclint
{" "}
<Text dimColor>
{"· "}
warn
{" · threshold "}
{fmtP}
{" · "}
{length}
{" checks per code edit"}
</Text>
</Text>
<Text dimColor>
{ledgerLine}
</Text>
<Text>
{" "}
</Text>
<Text dimColor>
No findings yet.
</Text>
<Box flexDirection="column">
<Text color="yellow">
{name}
{" "}
<Text dimColor>
{"· "}
{fix}
</Text>
</Text>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm}
{" "}
{file}
{" p="}
{fmtP2}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm2}
{" "}
{file2}
{" p="}
{fmtP3}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm3}
{" "}
{file3}
{" p="}
{fmtP4}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
</Box>
<Box flexDirection="column">
<Text color="yellow">
{name2}
{" "}
<Text dimColor>
{"· "}
{fix2}
</Text>
</Text>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm4}
{" "}
{file4}
{" p="}
{fmtP5}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm5}
{" "}
{file5}
{" p="}
{fmtP6}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm6}
{" "}
{file6}
{" p="}
{fmtP7}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
</Box>
<Box flexDirection="column">
<Text color="yellow">
{name3}
{" "}
<Text dimColor>
{"· "}
{fix3}
</Text>
</Text>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm7}
{" "}
{file7}
{" p="}
{fmtP8}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm8}
{" "}
{file8}
{" p="}
{fmtP9}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
<Box gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text wrap="wrap">
{" "}
{hhmm9}
{" "}
{file9}
{" p="}
{fmtP10}
{" (subagent)"}
</Text>
</Box>
<Button label="False positive" />
</Box>
</Box>
<Text>
{" "}
</Text>
<Text dimColor>
category checks flags avg p thr
</Text>
<Text>
{name4}
{checks}
{flags}
{fmtP11}
{fmtP12}
</Text>
<Text>
{name5}
{checks2}
{flags2}
{fmtP13}
{fmtP14}
</Text>
<Text>
{name6}
{checks3}
{flags3}
{fmtP15}
{fmtP16}
</Text>
<Text>
{" "}
</Text>
<Box gap={1}>
<Button hotkey="c" label="Clear findings" />
<Button hotkey="x" role="dismiss" label="Close" />
</Box>
</Box>
)
})
on('session.start', async ($, e, next) => {
const error = '…'
await $.ui.toast(`Off: ${error}`)
return next(e)
})
}
Mod 自身のコード
Mod のライセンス(MIT)に従って載せています。全文は下にあります。写すときは著作権表示を残してください。
mods/jev/jev-seclint/hooks/register.tsx 268〜351 行 · ペイン
on('ui.render', { component: 'Pane', requestId: PANE }, async ($, e) => {
const { Box, Text, Button } = $.ui.resolve(e)
const st = await read($, status)
if (!st.hasKey) {
return (
<Box flexDirection="column">
<Text bold>Jev seclint</Text>
<Text wrap="wrap">{NO_KEY_TEXT}</Text>
<Box marginTop={1}>
<Button key="close" hotkey="x" role="dismiss" label="Close" onPress={() => void $.ui.close({ id: PANE })} />
</Box>
</Box>
)
}
const list = await read($, findings)
const s = await read($, stats)
const l = await read($, ledger)
const raised = await read($, bumps)
const asked = categories()
const groups = asked.filter(c => list.some(f => f.category === c.id))
const flagged = list.filter(f => !f.isFalsePositive).length
// the stats table's name column gives way on a narrow pane (the four number columns take 25)
const nameWidth = Math.max(12, Math.min(28, e.props.bodyColumns - 26))
return (
<Box flexDirection="column">
<Text bold>
Jev seclint{' '}
<Text dimColor>
· {isWarnMode() ? 'warn' : 'nudge'} · threshold {fmtP(baseThreshold())} · {asked.length} checks per code edit
</Text>
</Text>
<Text dimColor>{ledgerLine(l)}</Text>
<Text> </Text>
{groups.length === 0 ? (
<Text dimColor>No findings yet.</Text>
) : (
<Text bold>{plural(flagged, 'open finding')}</Text>
)}
{groups.map(c => (
<Box key={`g-${c.id}`} flexDirection="column">
<Text color="yellow">
{c.name} <Text dimColor>· {c.fix}</Text>
</Text>
{list
.filter(f => f.category === c.id)
.slice(-6)
.reverse()
.map(f => (
<Box key={`f-${f.id}`} gap={1}>
<Box flexShrink={1} flexGrow={1}>
<Text dimColor={f.isFalsePositive} strikethrough={f.isFalsePositive} wrap="wrap">
{' '}
{hhmm(f.at)} {f.file} p={fmtP(f.p)}
{f.agentId ? ' (subagent)' : ''}
</Text>
</Box>
{!f.isFalsePositive && <Button key={`fp:${f.id}`} label="False positive" onPress={() => void markFalsePositive($, f.id)} />}
</Box>
))}
</Box>
))}
<Text> </Text>
<Text dimColor>{`${'category'.padEnd(nameWidth)} checks flags avg p thr`}</Text>
{asked.map(c => {
const q = s[c.id]
return (
<Text key={`s-${c.id}`} dimColor={!q}>
{clip(c.name, nameWidth).padEnd(nameWidth)}
{String(q?.checks ?? 0).padStart(7)}
{String(q?.flags ?? 0).padStart(6)}
{fmtP(avgP(q)).padStart(6)}
{fmtP(thresholdOf(baseThreshold() + (c.extraBar ?? 0), raised[c.id])).padStart(6)}
</Text>
)
})}
<Text> </Text>
<Box gap={1}>
<Button key="clear" hotkey="c" label="Clear findings" onPress={() => void clearFindings($)} />
<Button key="close" hotkey="x" role="dismiss" label="Close" onPress={() => void $.ui.close({ id: PANE })} />
</Box>
</Box>
)
})ライセンスの全文(MIT)
MIT License Copyright (c) 2026 mako-code Permission is hereby granted, free of charge, to any person obtaining a copy of this software and associated documentation files (the "Software"), to deal in the Software without restriction, including without limitation the rights to use, copy, modify, merge, publish, distribute, sublicense, and/or sell copies of the Software, and to permit persons to whom the Software is furnished to do so, subject to the following conditions: The above copyright notice and this permission notice shall be included in all copies or substantial portions of the Software. THE SOFTWARE IS PROVIDED "AS IS", WITHOUT WARRANTY OF ANY KIND, EXPRESS OR IMPLIED, INCLUDING BUT NOT LIMITED TO THE WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE AND NONINFRINGEMENT. IN NO EVENT SHALL THE AUTHORS OR COPYRIGHT HOLDERS BE LIABLE FOR ANY CLAIM, DAMAGES OR OTHER LIABILITY, WHETHER IN AN ACTION OF CONTRACT, TORT OR OTHERWISE, ARISING FROM, OUT OF OR IN CONNECTION WITH THE SOFTWARE OR THE USE OR OTHER DEALINGS IN THE SOFTWARE.
コードが呼ぶもの
通信ファイル読み取り環境変数ツール呼び出し保存
コードから読み取ったデザイン
読み取ったコミットのソースから描いたもので、動かした結果ではありません。一覧は 3 回描き、条件はデスクトップアプリで描く最初の分岐を取り、動かしたときにだけ決まる値は仮の例(点線の下線)にするか省きます。色と書体はこのサイトのものです。
コードから読めること
2026-10-06 に読んだコミット ec6ea2383749 のソースから。最初のまとまりが載せる条件で、残りは自分で判断するための材料です。後のコミットは、次に読むまで見ていません。
| 載せる条件: 確かめやすいコード | |
|---|---|
| 入口を読んだ | hooks/hooks.json が名指すモジュールをすべて読んだ。mods/jev/jev-seclint/hooks/register.tsx |
| 解析できる | すべてのファイルが TypeScript か JavaScript として解析できる。4 ファイルを解析 |
| コードが Mod の中で完結 | import は Mod 自身のファイルかエンジンのモジュールだけ。パッケージも require もない。コードはすべて Mod の中 |
| 読める | 圧縮した行・eval・new Function・計算した道の import()・符号化した塊がない。圧縮・eval・符号化した塊なし |
| 呼び出しが見える | 通信とプログラム起動はその場で $.http.fetch・$.process.run と書き、他へ渡さない。外への呼び出しはすべてその場の $ で |
| 入れる前に自分で判断する材料 | |
| 描く場所 | コードから読んだ、描く先。ターミナル・デスクトップアプリ・両方・何も描かない(フックだけ: 見張りやプロンプトの書き換え)のどれか。出すだけで、外す理由にはしない。ターミナルとデスクトップアプリに同じように描く |
| 入れる手順 | リポジトリ自身の .claude-plugin/marketplace.json にこの Mod が載っていて、ページに書いた手順でそのマーケットプレイスから入れられるか。リポジトリの .claude-plugin/marketplace.json に載っており、そこから入れられる |
| Windows のプログラム | $.process で起動するプログラムが Windows にあるか(tail・date・open・osascript・/usr/… などは無い)。Windows にないプログラムを使わない |
| 通信 | fetch の送り先(https のホスト)がコードに書いてあるか。mods/jev/jev-seclint/hooks/register.tsx:67 fetch(JEV_URL) |
| プログラム | 起動するプログラムの名前がコードに書いてあり、シェル・インタプリタ・通信用の道具でないか。プログラムを起動しない |
| 読んで送る | ファイルや環境変数を読み、かつ通信するか。reads environment variables and files and reaches the network |
| ソースの鍵 | ソースに API キーや秘密鍵らしきものがあるか。ソースに鍵なし |
| ライセンス | オープンなライセンス(MIT・Apache-2.0・BSD・ISC・Unlicense・0BSD・CC0)で全文があれば、modscode にコードを載せる。違えばリンクだけ。MIT |
コードの文面を読んだだけで、安全の審査ではありません。動かしてはおらず、起動するプログラムの中で何が起きるかも見えません。入れる前の確認はあなたの役目です。 載せる条件
入れる
入れる前に、必ず自分で確かめてください。Mod はサンドボックスなしで、あなたの権限で動きます。modscode はこのコードの安全を保証しません。下のコードを読み(またはフォルダーで claude plugin validate .)、触るものを見て、読んだコミットを入れてください。
リポジトリがそのままマーケットプレイスです。このマーケットプレイスを足し(ターミナルでは次のコマンド、デスクトップアプリではプラグインの設定)、そこから Mod を入れます。
/plugin marketplace add mako-code/gobworks/plugin install jev-seclint@gobworks入るのはマーケットプレイスの最新のコミットで、ここで読んだもの(ec6ea2383749)と違うことがあります。入れる前に見比べてください。
Claude に聞く
modscode のコネクタを入れると、Claude がこのデザイン・コードが触るもの・コードを読んで、それをもとに作れます。たとえば:
modscode のデザイン「mako-code-jev-seclint」をコードごと読んで、同じようなペインを作って似たデザイン
-
Claude に頼む…Fix login▸★ build ok▸★ build ok▸★ build ok+3 moretasks 3 pending · Glob claimed · 3 doneConsensus42%
-
Claude に頼む…2h 10m · █████░░░✓ build ✓ build ✓ buildJavaKotlin3 Python■ ok 3 ■ ok 3 ■ ok 3 Razor proven 3 Razor proven 3 Razor proven 3Phases ──────── 3/3build Pythonbuild Pythonbuild Python… 3 more phasesLua ──────── 3/Kotlin■ the whole upgrade Ruby■ build build Ruby■ build build Ruby■ build build Ruby … 3 moreNext ──────── PythonRuby (by hand)Podsclick a button, or ctrl+x tab then Tab, EnterAttention ──────── 3! Scala ! Scala ! Scala … 3 moreSession ──────── okJava
-
Claude に頼む…moai-boardmoai-boardPickedx closebuild 1build 2build 3r refreshQueue not read yetokPick
-
Open a file first: /crit-tui file <path>Reopen this one in the crit browser view.Claude に頼む…
-
Claude に頼む…./rows.tsx●●●●●×./rows.tsxnothing loaded yet● Fix login● Fix login● Fix login● Fix login● Fix login● Fix login● Fix login● Fix login● Fix login./rows.tsxWorkspaceWorkspaceWorkspaceselected: build● open in Databricks
-
Claude に頼む…build 3 app●●●◉●●okno Library app here yet; Library adds one●./rows.tsx./rows.tsxselected: Nerd