ZIFFER home

The ZIFFER plugin for Claude Code

A plugin for the Claude Code AI assistant that helps a developer set ZIFFER up, installed once.

A plugin for the Claude Code AI assistant that helps a developer set ZIFFER up, installed once. It scans the code, puts ZIFFER in it, builds the policy from the scan, sets up the policy pipeline, and checks the result against a sandbox. It is a setup helper: ZIFFER decides what an AI agent may run, and nothing it guarantees depends on the plugin or on the AI assistant behaving well.


1. The idea in one paragraph

The plugin carries two things. The first is the ZIFFER tools, the same local server as sdk.md section 10, started for you. The second is six skills: written procedures the AI assistant follows, step by step, with those tools. Each skill says which tool to call at each step, what to show you, and where to stop and wait for you. Nothing is written into your project, sent to ZIFFER or started on your machine without you seeing it first.

2. What you need

  • Claude Code, and Node.js 22 or later (the ZIFFER tools run with npx).
  • For the first four skills: nothing else. No account and no key.
  • For the fifth, a sandbox API key from ZIFFER (sandbox.md section 4).
  • For the policy steps: the policy repository template from your onboarding pack, and, to grade your rules on your own machine, the ziffer command line tool (install.md section 1).

The ZIFFER tools this plugin starts are version 0.3.0 of @ziffer-io/mcp. The skills need its code scan.

3. Install it

It installs from ZIFFER's public repository, https://github.com/ziffer-hq/ziffer-sdk. Add the repository as a plugin marketplace, then install the plugin from it:

claude plugin marketplace add ziffer-hq/ziffer-sdk
claude plugin install ziffer@ziffer

The ZIFFER tools read ZIFFER_API_URL, ZIFFER_API_KEY, ZIFFER_TRUST_ANCHOR and ZIFFER_SUITE_FLOOR from the environment Claude Code starts in (sdk.md section 3). Set them in your shell, never in a file in your repository. Only the fifth skill needs them.

4. The skills

Type the skill's name, or ask in your own words ("scan this project with ZIFFER") and Claude picks it. /ziffer:start offers them in order and picks up where your project already is: a project that already calls ZIFFER starts at the policy.

SkillWhat it doesWhat it never does
/ziffer:scanScans your code for the tools it gives an AI model. Shows the counts, the tools that cannot be undone, and the one place to put ZIFFER. Explains any one tool on request.Start the servers of your installed AI tools before you have seen the list and agreed. Grade a tool itself: every verdict is the ZIFFER engine's.
/ziffer:integrateShows the exact change at the place the scan found: one call at the top of your dispatcher, the module the scan wrote beside it, and the tools file. Writes it once you approve, then checks it.Invent a dispatcher when the scan found none. Add a prompt filter, an output classifier or a "be careful" instruction and call it a fix.
/ziffer:policyCopies the policy repository template, brings in the scan's draft rules, and asks you about every tool that cannot be undone and every tool the scan could not classify. Checks the result without a key.Decide a classification for you. Fill in who approves, who is told, or your signing key.
/ziffer:pipelineAdds the template's workflows unchanged, and lists every variable and secret they read with where each value comes from. Reads a failed run's log back to you.Set a value, read a secret, or publish.
/ziffer:verifyChecks your key, then sends one call that should run and one that should be held to your sandbox, once you say so, and explains the receipt or the refusal.Approve anything. Send anything to a tenant that is not a sandbox.

How the first policy reaches ZIFFER. Your first signed policy is handed to ZIFFER as part of your enrolment. From then on, every merge to your policy repository's main branch is signed with your own key and published by your own pipeline (policy-ci.md section 5). The plugin prepares changes; a person merges them.

5. The five hard stops

Every skill carries these, word for word, as instructions to the AI assistant:

  1. It never creates, reads, prints or stores a policy signing key or any other private key. It gives you the command to run on your own machine, and stops.
  2. It never names who approves, and never creates an invitation. A person decides who approves, and your administrator creates invitations (approvers.md section 2).
  3. It never publishes a policy and never merges a pull request. It prepares the change; a person merges it.
  4. It never classifies a tool on its own authority. It proposes, with the scan's reason shown, and you confirm or correct it.
  5. It never presents itself as a control. It is a setup helper.

It also never writes a credential into a file in your repository, and never sends anything to ZIFFER except through the ZIFFER tools you can see in the session.

These are instructions, not guarantees. An AI assistant can be talked out of an instruction. That is why nothing ZIFFER enforces depends on them: the signing key is yours alone, approvers are enrolled by a person, and your policy is published only by your own pipeline.

6. Remove it

claude plugin uninstall ziffer@ziffer
claude plugin marketplace remove ziffer

7. What this does not cover

  • Other AI assistants. The skills are written for Claude Code. Any assistant that starts an MCP server can use the ZIFFER tools directly (sdk.md section 10), without the skills.
  • Your repository's settings. The ziffer-production environment and the protection rule on main are set by a person, in your repository's settings; no tool here can see them.
  • Production. /ziffer:verify sends proposals to a sandbox only.
  • Windows. The skills give shell commands for macOS and Linux. On Windows, run them in WSL or Git Bash.

On this page