Free Claude Code plugins for your standup, brag doc and lost sessions
Two free plugins for Claude Code and Codex, from Shabash, a Mac app for teams that use coding agents. One writes your standup and brag doc and finds old sessions from the history on your computer. The other checks the skills and plugins you've installed for hidden instructions. Nothing goes to Shabash.
Shabash
Six commands that read the history Claude Code already keeps on your computer: the prompts you typed and each session's title. export reads the one session you pick in full. They read Codex's history too.
/shabash:standupYour standup from your sessions and commits since your last workday, ready to paste into Slack.
"write my standup"/shabash:bragA list of what you shipped in the last 30 days, or a quarter, for a performance review.
"brag doc for last quarter"/shabash:searchAn old session found from words you typed in it, with the command to resume it.
"find the session where I fixed login"/shabash:exportOne session turned into a clean write-up of what was decided and what changed.
"export yesterday's session"/shabash:threadsWhat you worked on this week, where each piece stopped, and how to pick it back up.
"what was I working on?"/shabash:keepHow many old sessions Claude Code has deleted, and, only if you say yes, a longer limit.
"why did my sessions disappear?"Install
claude plugin marketplace add shabash-dev/shabash-plugins
claude plugin install shabash@shabashIn Codex: codex plugin marketplace add shabash-dev/shabash-plugins, then codex plugin add shabash@shabash. Needs Python 3. Read the code on GitHub.
What it found on my Mac
The first time I ran /shabash:keep. A transcript is a session's full conversation, and cleanupPeriodDays is the Claude Code setting for how many days they're kept:
cleanupPeriodDays: not set, so Claude Code uses its 30-day default transcripts on this computer: 326, 1935 MB sessions in your prompt history whose transcript is gone: 840 of 1050
Shabash Skill Scanner
A skill you install is someone else's instructions that Claude follows with your files and keys in reach. This reads what Claude Code or Codex loads and points at the lines worth reading yourself.
- Shell commands written as
!`command`in a skill, which run the moment it's used - Hidden HTML comments with an instruction or link
- Invisible characters that hide text on screen
curlorwgetposting data, or a download piped intosh- Reads of
.env,~/.sshor.aws/credentials - "Don't tell the user" and similar instructions
npxpackages and MCP servers with no fixed version, so a new release runs without you seeing it- Hooks, which run by themselves, that do any of these (add
--allto list every hook)
Then Claude opens each flagged file, treats what's in it as data, and tells you which flags are fine. It only reads, and a careful attacker can still write something it misses.
Install
claude plugin marketplace add shabash-dev/skill-check
claude plugin install shabash-skill-check@shabash-skill-checkThen type /shabash-skill-check:scan. Needs Python 3. Read the code on GitHub.
What it found on my Mac
Checked 137 files; 8 have something worth reading yourself.
npx tsx with no fixed version, so a new release of that package would have run without me seeing it. Where a bad skill can hide things.Files and commands the plugins read
Your prompt history, the titles of your sessions, read-only git commands in your project folders, and for the scanner, your installed skills, plugins and the MCP servers in your settings. What they find is printed into your Claude Code or Codex session, which sends it to Anthropic or OpenAI like anything else you do there. Nothing goes to Shabash, though each reply ends with one line linking to it. Each README lists every file and command, and the privacy notice covers them.
Free to use, and source-available, not open source: you can read the code but not copy or reuse it (terms).
Questions
How do I write a standup from Claude Code?
Install the Shabash plugin and type /shabash:standup. It reads your sessions and your own commits since the start of your last workday and writes Yesterday, Today and Blockers, ready to paste into Slack.
Why did my Claude Code sessions disappear?
Claude Code deletes a session's transcript once it's older than cleanupPeriodDays, 30 days unless you've changed it. /shabash:keep tells you how many you've lost and, if you say yes, raises the limit. It can't bring back ones already gone. More on the cleanup.
How do I search my old Claude Code sessions?
Type /shabash:search and a few words you remember typing. It looks through the last year of your prompts and gives the command to resume each match. Searching history by hand.
Are Claude Code skills and plugins safe to install?
Only as safe as whoever wrote them: a skill can hide an instruction where GitHub doesn't show it. The Skill Scanner points at those lines in what you've already installed. The full post.
Do the plugins work with Codex?
Yes. Both install in Codex with codex plugin marketplace add. In Codex, the Shabash commands read Codex's history in ~/.codex, and the scanner also checks Codex's skills, plugins and hooks. keep is for Claude Code only.
Does anything get sent to Shabash?
No. The scripts make no network calls of their own. What they print goes into your Claude Code or Codex session, the same as anything else you do there.