Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Authors
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

ProTermsPrivacyRefunds
Back to skills

Rashomon

BSecurity

Start recording what this Claude Code session asks to run. Use when the user says "rashomon", "start rashomon", "claude rashomon", "watch this session", "record my session", asks to turn the recorder on, or wants an easier way to launch recorded sessions. For reports use rashomon-report; to stop use rashomon-stop; for install state use rashomon-status.

8 stars
0 votes
0 copies
0 views
Added 9/28/2026
developmentgoshellbashgit

Works with

claude codecli

Security Analysis

B75/100
criticalSends environment variables or credentials to an external URL

Scanned 9/28/2026

Install to Claude Code

$npx -y skills add altrace-dev-role/rashomon --skill rashomon --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Rashomon?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Rashomon
[![Security: B — Skills Directory](https://www.skillsdirectory.com/api/skills/altrace-dev-role-rashomon/badge)](https://www.skillsdirectory.com/skills/altrace-dev-role-rashomon)

More formats (shields.io, HTML) on the badges page.

Files
SKILL.md
---
name: rashomon
description: 'Start recording what this Claude Code session asks to run. Use when the user says "rashomon", "start rashomon", "claude rashomon", "watch this session", "record my session", asks to turn the recorder on, or wants an easier way to launch recorded sessions. For reports use rashomon-report; to stop use rashomon-stop; for install state use rashomon-status.'
---

Install the rashomon recorder so every tool call from now on is recorded as a
declaration (identifiers; shape, including a command's program name; the
hostnames the call names, meaning URL hosts and ssh/scp/sftp/rsync
destinations; and the working directory and transcript path. No prompts,
responses, file contents or other argument values).

1. Resolve the binary, in this order. Set `$RASHOMON` to the first absolute
   path that works:
   - `~/.local/bin/rashomon` if present and executable
   - `~/go/bin/rashomon` if present and executable (where `go install` puts it)
   - `/opt/homebrew/bin/rashomon` or `/usr/local/bin/rashomon` (brew installs;
     checked explicitly because a GUI-launched app's PATH may not carry them)
   - `command -v rashomon`, kept only when it returns an absolute path
   - None found: if `command -v go` also fails, stop and point the user at the
     README's install options instead of building. With Go present, build from
     this repository when the cwd is the rashomon repo
     (`go build -o ~/.local/bin/rashomon ./cmd/rashomon`; on Windows,
     PowerShell does not expand `~` for go — use
     `go install ./cmd/rashomon`, which lands `rashomon.exe` in
     `"$(go env GOPATH)\bin"`). Outside the repo, ask the user where their
     rashomon checkout is rather than fetching an unpinned module from the
     network.
   Never install from a `go run` path — `watch` refuses temporary build
   directories because the installed hook entry records the absolute path.

2. Run `$RASHOMON watch`. It writes eight hook entries (PreToolUse,
   PostToolUse, PostToolUseFailure, SessionStart, SessionEnd, Stop,
   StopFailure, UserPromptSubmit) into `~/.claude/settings.json` and prints an install id plus
   the exact `detach --install <id>` line that undoes it. Quote that undo
   line back to the user verbatim.

3. Run `$RASHOMON status` and show the result, so the user sees the eight
   entries as present and where the store lives.

4. Tell the user, briefly, and say the SCOPE first — it is the part they are
   actually agreeing to:
   - Recording is USER-WIDE AND OPEN-ENDED, not this session and not this
     project. The entries go in `~/.claude/settings.json`, which Claude Code
     reads for every project on this machine, so every session from now on is
     recorded — including unrelated repositories and client work — until
     `/rashomon-stop` or the `detach --install <id>` line removes them.
     Someone who is under an agreement not to instrument a particular
     codebase needs to know that before saying yes, not after.
   - Recording covers tool calls from this point on. A session the recorder
     joined mid-way reports its coverage as `unverified` (reason
     `probe_absent`) — that is honest accounting, not a failure. Sessions
     started after this install are eligible for verified coverage, because
     the probe is in place from their first moment; the report is the proof.
   - `/rashomon-report` renders what was recorded; `/rashomon-stop` removes
     the hooks and keeps the store; `/rashomon-forget` erases records.
   - After a turn, they may occasionally see a short line starting `※
     rashomon:` in Claude Code's own output. That is the recap: exception-only,
     so it says nothing on a clean turn and prints once when a turn has a
     recorded failure, a declaration without recorded execution, coverage
     that did not verify, or a truncated projection. It always points at
     `/rashomon-report --session <id>` for the detail rather than trying to
     say more itself.

5. Offer the one-word launcher once, if it is not already on their PATH.
   From the rashomon repo, on macOS or Linux:

       mkdir -p ~/.local/bin
       ln -sf "$(git rev-parse --show-toplevel)/scripts/claude-rashomon" ~/.local/bin/claude-rashomon
       case ":$PATH:" in *":$HOME/.local/bin:"*) ;; *) echo 'add ~/.local/bin to your PATH' ;; esac

   macOS does not ship `~/.local/bin` or put it on PATH — the mkdir and the
   PATH check matter there. On Windows, the launcher is
   `scripts\claude-rashomon.ps1` (run it with `powershell -File`, or put
   `scripts\` on PATH); the POSIX launcher and the optional state-line hook
   need Git Bash, which Claude Code uses for hooks on Windows when present.
   From then on `claude-rashomon` in any directory runs `watch` and starts
   `claude` in one step, with the liveness probe in place from the session's
   first moment — no mid-session `probe_absent` downgrade. Extra arguments
   pass through to `claude` unchanged; `--help`, `--version` and management
   subcommands such as `doctor` pass through without running `watch`.

Do not edit `~/.claude/settings.json` by hand and do not install the hook
entries yourself — `watch` is the only writer, and it preserves the value of
every foreign entry byte for byte (indentation may change).

Attribution

altrace-dev-rolealtrace-dev-role
View sourceMore from altrace-dev-role →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

Browser Extension Developer

Use this skill when developing or maintaining browser extension code in the `browser/` directory, including Chrome/Firefox/Edge compatibility, content scripts, background scripts, or i18n updates.

284972 votes

Seo Optimizer

SEO optimization with keyword analysis, readability assessment, technical validation, content quality. Use for search rankings, blog posts, content audits, or encountering keyword density, readability scores, meta tags, schema markup errors.

2222 votes

Google Official Seo Guide

Official Google SEO guide covering search optimization, best practices, Search Console, crawling, indexing, and improving website search visibility based on official Google documentation

1862 votes

Tanstack Start

Build a full-stack TanStack Start app on Cloudflare Workers from scratch — SSR, file-based routing, server functions, D1+Drizzle, better-auth, Tailwind v4+shadcn/ui. Use whenever the user mentions TanStack Start, asks to scaffold a full-stack Cloudflare app with SSR, wants an SSR dashboard, or asks for a React 19 + Cloudflare Workers app with file-based routing and server functions — even if they don't name TanStack Start specifically. No template repo — Claude generates every file fresh per ...

10311 votes

Pentest

PTES-aligned adversarial security audit for backend, frontend, and mobile applications. Produces a CVSS-scored Hacker Report with verified PoCs and phased remediation.

5491 votes
View all in development →