The ZIFFER plugin for Claude Code
A plugin for the Claude Code AI assistant that helps a developer set ZIFFER up, installed once.
A plugin for the Claude Code AI assistant that helps a developer set ZIFFER up, installed once. It scans the code, puts ZIFFER in it, builds the policy from the scan, sets up the policy pipeline, and checks the result against a sandbox. It is a setup helper: ZIFFER decides what an AI agent may run, and nothing it guarantees depends on the plugin or on the AI assistant behaving well.
1. The idea in one paragraph
The plugin carries two things. The first is the ZIFFER tools, the same local server as sdk.md section 10, started for you. The second is six skills: written procedures the AI assistant follows, step by step, with those tools. Each skill says which tool to call at each step, what to show you, and where to stop and wait for you. Nothing is written into your project, sent to ZIFFER or started on your machine without you seeing it first.
2. What you need
- Claude Code, and Node.js 22 or later (the ZIFFER tools run with
npx). - For the first four skills: nothing else. No account and no key.
- For the fifth, a sandbox API key from ZIFFER (sandbox.md section 4).
- For the policy steps: the policy repository template from your onboarding pack, and, to grade
your rules on your own machine, the
ziffercommand line tool (install.md section 1).
The ZIFFER tools this plugin starts are version 0.3.0 of @ziffer-io/mcp. The skills need
its code scan.
3. Install it
It installs from ZIFFER's public repository, https://github.com/ziffer-hq/ziffer-sdk. Add the repository as a plugin marketplace, then install the plugin from it:
claude plugin marketplace add ziffer-hq/ziffer-sdkclaude plugin install ziffer@zifferThe ZIFFER tools read ZIFFER_API_URL, ZIFFER_API_KEY, ZIFFER_TRUST_ANCHOR and
ZIFFER_SUITE_FLOOR from the environment Claude Code starts in (sdk.md section 3). Set
them in your shell, never in a file in your repository. Only the fifth skill needs them.
4. The skills
Type the skill's name, or ask in your own words ("scan this project with ZIFFER") and Claude picks
it. /ziffer:start offers them in order and picks up where your project already is: a project that
already calls ZIFFER starts at the policy.
| Skill | What it does | What it never does |
|---|---|---|
/ziffer:scan | Scans your code for the tools it gives an AI model. Shows the counts, the tools that cannot be undone, and the one place to put ZIFFER. Explains any one tool on request. | Start the servers of your installed AI tools before you have seen the list and agreed. Grade a tool itself: every verdict is the ZIFFER engine's. |
/ziffer:integrate | Shows the exact change at the place the scan found: one call at the top of your dispatcher, the module the scan wrote beside it, and the tools file. Writes it once you approve, then checks it. | Invent a dispatcher when the scan found none. Add a prompt filter, an output classifier or a "be careful" instruction and call it a fix. |
/ziffer:policy | Copies the policy repository template, brings in the scan's draft rules, and asks you about every tool that cannot be undone and every tool the scan could not classify. Checks the result without a key. | Decide a classification for you. Fill in who approves, who is told, or your signing key. |
/ziffer:pipeline | Adds the template's workflows unchanged, and lists every variable and secret they read with where each value comes from. Reads a failed run's log back to you. | Set a value, read a secret, or publish. |
/ziffer:verify | Checks your key, then sends one call that should run and one that should be held to your sandbox, once you say so, and explains the receipt or the refusal. | Approve anything. Send anything to a tenant that is not a sandbox. |
How the first policy reaches ZIFFER. Your first signed policy is handed to ZIFFER as part of
your enrolment. From then on, every merge to your policy repository's main branch is signed with
your own key and published by your own pipeline (policy-ci.md section 5). The
plugin prepares changes; a person merges them.
5. The five hard stops
Every skill carries these, word for word, as instructions to the AI assistant:
- It never creates, reads, prints or stores a policy signing key or any other private key. It gives you the command to run on your own machine, and stops.
- It never names who approves, and never creates an invitation. A person decides who approves, and your administrator creates invitations (approvers.md section 2).
- It never publishes a policy and never merges a pull request. It prepares the change; a person merges it.
- It never classifies a tool on its own authority. It proposes, with the scan's reason shown, and you confirm or correct it.
- It never presents itself as a control. It is a setup helper.
It also never writes a credential into a file in your repository, and never sends anything to ZIFFER except through the ZIFFER tools you can see in the session.
These are instructions, not guarantees. An AI assistant can be talked out of an instruction. That is why nothing ZIFFER enforces depends on them: the signing key is yours alone, approvers are enrolled by a person, and your policy is published only by your own pipeline.
6. Remove it
claude plugin uninstall ziffer@zifferclaude plugin marketplace remove ziffer7. What this does not cover
- Other AI assistants. The skills are written for Claude Code. Any assistant that starts an MCP server can use the ZIFFER tools directly (sdk.md section 10), without the skills.
- Your repository's settings. The
ziffer-productionenvironment and the protection rule onmainare set by a person, in your repository's settings; no tool here can see them. - Production.
/ziffer:verifysends proposals to a sandbox only. - Windows. The skills give shell commands for macOS and Linux. On Windows, run them in WSL or Git Bash.