
Research
/Security News
16 Malicious Firefox Extensions Steal Cryptocurrency Wallet Credentials
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.
codebase-context-skill
Advanced tools
Programming-first context engine for Claude Code — TypeScript-powered codebase indexing, dependency graphing, symbol-level search, and zero-token context injection via hooks.
Context engineering middleware for Claude Code. Intelligent codebase indexing, token-efficient file selection, local tracking, testing, auditing, and session persistence — all via local MD files.
This skill plugin sits between your queries and Claude Code. It ensures every interaction has precisely the right context — no wasted tokens exploring files that don't matter, no losing track of what was changed.
Before this skill: Claude Code explores your codebase from scratch on every query, reading files it doesn't need, losing context when the window fills up.
With this skill: Your codebase is indexed once, only relevant files are read per query, and everything is tracked in local MD files that persist across the session.
npx codebase-context-skill init
bunx codebase-context-skill init
npm install -g codebase-context-skill
ccs init
git clone https://github.com/AnitChaudhry/codebase-context-skill.git
# Copy each skill as its own directory (Claude Code requires one level deep)
for d in codebase-context-skill/skills/*/; do
name=$(basename "$d")
cp -r "$d" ".claude/skills/ccs-$name/"
done
# Copy shared resources
cp -r codebase-context-skill/{agents,templates,references} .claude/skills/_ccs/
# Copy MCP config
cp codebase-context-skill/.mcp.json .mcp.json
Important: Skills must be at .claude/skills/<name>/SKILL.md (one level deep). Do NOT copy into .claude/skills/ccs/skills/ — Claude Code won't discover nested skills.
If you already have a .mcp.json, merge the ccs entry manually (see MCP Server Connection below).
Naming: When installed via npx/CLI, commands use hyphens:
/ccs-init,/ccs-build, etc. When installed as a Claude Code plugin (git clone with.claude-plugin/), the plugin namespace adds the prefix automatically:/ccs-init,/ccs-build, etc.
| Command | Description |
|---|---|
/ccs-init | Deep-research the codebase, generate project-map, architecture, file-index, conventions |
/ccs-status | Show what's indexed, staleness, file counts, token savings estimate |
/ccs-refresh | Rebuild index (full, incremental, or session-based) |
/ccs-query [question] | Preview which files would be selected for a given query |
| Command | Description |
|---|---|
/ccs-plan [task] | Plan a task with full dependency-aware context |
/ccs-build [task] | Create/implement with tracked context and commit-style logging |
/ccs-refactor [scope] | Scope a refactor — identify all affected files and dependencies |
/ccs-fix [issue] | Fix bugs with dependency tracking, root-cause analysis, and verification |
/ccs-team [task] | Spawn an agent team for complex multi-part tasks |
| Command | Description |
|---|---|
/ccs-test [scope] | Run tests, track results locally, suggest and auto-fix failures |
/ccs-audit [scope] | Audit code for security, performance, patterns, accessibility, dead code |
/ccs-review [scope] | Code review with full context — style, logic, security, performance |
| Command | Description |
|---|---|
/ccs-research [query] | Search official docs, resolve errors, check deps, find best practices |
| Command | Description |
|---|---|
/ccs-connect | Set up MCP server — creates/updates .mcp.json, configures endpoint, verifies connection |
| Command | Description |
|---|---|
/ccs-branch | Create/switch branches with auto-generated context reference files |
/ccs-pr | Prepare PR with full context — title, summary, blast radius, review areas |
/ccs-merge | Merge with dependency checking — conflict prediction, resolution context |
/ccs-diff | Smart diff with impact analysis — dependency chains, blast radius, categorization |
/ccs-sync | Pull/rebase/push with conflict context and resolution recommendations |
/ccs-stash | Stash with tracked context — remembers what you were working on |
/ccs-log | Smart commit history — groups by branch, cross-references with task.md |
| Command | Description |
|---|---|
/ccs-deploy | Pre-deployment checklist — tests, build, env vars, dependencies, breaking changes |
/ccs-track | View/manage session task log, see all changes made this session |
The plugin ships with a .mcp.json that configures the CCS remote MCP server automatically. When you install (via npx, manual clone, or /ccs-init), this config is created in your project root:
{
"mcpServers": {
"ccs": {
"type": "http",
"url": "https://skills.thinqmesh.com/api/mcp"
}
}
}
What this gives you: 6 MCP tools available to Claude Code — skill info, all 23 command docs, OS-specific install commands, model strategy, and context file details.
If you already have a .mcp.json with other MCP servers, run /ccs-connect — it merges the CCS entry safely without overwriting your existing servers.
To reconfigure or verify, run:
/ccs-connect
Alternative (global config):
claude mcp add --transport http ccs https://skills.thinqmesh.com/api/mcp
Note: All MCP config lives in the plugin's
.mcp.jsonat your project root. To modify the endpoint or switch between remote/local, edit this file directly — do not modify~/.claude/settings.jsonfor project-level config.
/ccs-init)Scans your entire codebase and generates local reference files in .ccs/:
When you ask Claude Code anything, the skill:
Every action is logged in .ccs/task.md with git-commit-style entries:
| Model | Used For | Commands |
|---|---|---|
| Haiku 4.5 | Lightweight lookups, scanning, status checks | status, refresh, query, track, stash, log |
| Sonnet 4.6 | Standard coding execution | build, fix, test, branch, sync |
| Opus 4.6 | Deep reasoning, architecture, complex analysis | init, plan, refactor, audit, review, research, deploy, pr, merge, diff, team |
All context files are stored in .ccs/ (add to .gitignore):
.ccs/
├── project-map.md # File structure + dependency graph
├── architecture.md # Tech stack, patterns, data flow
├── file-index.md # Files ranked by importance
├── conventions.md # Coding style and patterns
├── task.md # Session task log (commit-style)
└── preferences.json # User preferences (refresh mode, etc.)
Set your preference on first init (saved in .ccs/preferences.json):
/ccs-refresh manuallyMIT
Built by Anit Chaudhary — codebase-context-skill v2.0.0
FAQs
Programming-first context engine for Claude Code — TypeScript-powered codebase indexing, dependency graphing, symbol-level search, and zero-token context injection via hooks.
We found that codebase-context-skill demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Research
/Security News
Socket found 16 malicious Firefox extensions designed to steal crypto wallet recovery phrases and private keys using cloned Rabby and OKX interfaces.

Product
Socket now scans VS Code extensions, giving teams early detection of risky behaviors, hidden capabilities, and supply chain threats in developer tools.

Research
/Security News
Socket uncovered two malicious VS Code themes in a GlassWorm-linked cluster with thousands of installs across VS Code Marketplace and Open VSX.