Skills DirectorySkills Directory
SkillsLearnSecurityCategoriesDocsCommunityBlog
Sign InSubmit Skill
Skills Directory

Security-tested agent skills for Claude, coding agents, and AI workflows.

Directory

  • Browse Skills
  • All Skills A–Z
  • Claude Skills
  • Claude Code Skills
  • Agent Skills
  • Categories
  • Submit a Skill

Learn

  • Learn Hub
  • Install Claude Skills
  • Write SKILL.md
  • Skills vs MCP
  • Directories Compared

Security

  • Security
  • Methodology
  • Secure Claude Skills
  • Security Badges

Company

  • About
  • Community
  • Blog
  • API Docs
  • Advertise

2026 Skills Directory. All rights reserved.

Back to skills

Claude Code Haha Local

FSecurity

> Skill by [ara.so](https://ara.so) — Daily 2026 Skills collection. A patched, locally runnable version of the Claude Code source that leaked from Anthropic's npm registry on 2026-03-31. Fixes multiple blocking issues in the original leak so the full Ink TUI works. Supports any Anthropic-compatible API (MiniMax, OpenRouter, etc.). ---

81 stars
0 votes
0 copies
0 views
Added 9/19/2026
toolstypescriptshellbashreactgitapisecurity

Works with

claude codeterminalcliapimcp

Security Analysis

F17/100
criticalPipes output to a shell interpreter
mediumUses curl or wget to download content
criticalExfiltrates credentials via HTTP — exact pattern from Snyk ToxicSkills study
criticalDownloads and executes remote scripts — classic supply chain attack

Scanned 9/19/2026

Install to Claude Code

$npx -y skills add reason-machines/trending-skills --skill claude-code-haha-local --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Claude Code Haha Local?

Add the live security badge to your README — it updates automatically with every re-scan.

Security grade badge for Claude Code Haha Local
[![Security: F — Skills Directory](https://www.skillsdirectory.com/api/skills/reason-machines-claude-code-haha-local/badge)](https://www.skillsdirectory.com/skills/reason-machines-claude-code-haha-local)

More formats (shields.io, HTML) on the badges page.

Download Zip
Files
SKILL.md
```markdown
---
name: claude-code-haha-local
description: Run the leaked Claude Code source locally with any Anthropic-compatible API endpoint
triggers:
  - set up claude code haha locally
  - run claude code from source
  - configure custom API endpoint for claude code
  - use minimax or openrouter with claude code
  - fix claude code not starting
  - connect claude code to compatible API
  - run leaked claude code source
  - self-host claude code with custom model
---

# Claude Code Haha — Local Runnable Claude Code from Leaked Source

> Skill by [ara.so](https://ara.so) — Daily 2026 Skills collection.

A patched, locally runnable version of the Claude Code source that leaked from Anthropic's npm registry on 2026-03-31. Fixes multiple blocking issues in the original leak so the full Ink TUI works. Supports any Anthropic-compatible API (MiniMax, OpenRouter, etc.).

---

## What It Does

- Full Ink TUI interactive interface (identical to official Claude Code)
- `--print` headless mode for scripts/CI
- MCP server, plugin, and Skills support
- Custom API endpoint and model configuration
- Fallback Recovery CLI mode if TUI fails

---

## Installation

### 1. Install Bun (required runtime)

```bash
# macOS / Linux
curl -fsSL https://bun.sh/install | bash

# If unzip is missing on minimal Linux
apt update && apt install -y unzip

# macOS via Homebrew
brew install bun

# Windows (PowerShell)
powershell -c "irm bun.sh/install.ps1 | iex"
```

Verify:

```bash
bun --version
```

### 2. Clone and install dependencies

```bash
git clone https://github.com/NanmiCoder/claude-code-haha.git
cd claude-code-haha
bun install
```

### 3. Configure environment

```bash
cp .env.example .env
```

Edit `.env`:

```env
# Authentication — pick ONE
ANTHROPIC_API_KEY=         # sent as x-api-key header
ANTHROPIC_AUTH_TOKEN=      # sent as Authorization: Bearer header

# Custom endpoint (omit for official Anthropic)
ANTHROPIC_BASE_URL=https://api.minimaxi.com/anthropic

# Model names — map all tiers to your provider's model
ANTHROPIC_MODEL=MiniMax-M2.7-highspeed
ANTHROPIC_DEFAULT_SONNET_MODEL=MiniMax-M2.7-highspeed
ANTHROPIC_DEFAULT_HAIKU_MODEL=MiniMax-M2.7-highspeed
ANTHROPIC_DEFAULT_OPUS_MODEL=MiniMax-M2.7-highspeed

# Timeout in ms (default 600000 = 10 min)
API_TIMEOUT_MS=3000000

# Disable telemetry and non-essential network requests
DISABLE_TELEMETRY=1
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1
```

---

## Key Commands

```bash
# Full interactive TUI
./bin/claude-haha

# Headless single-shot (print mode)
./bin/claude-haha -p "explain this codebase"

# Pipe input into headless mode
echo "what does main.tsx do?" | ./bin/claude-haha -p

# Force fallback Recovery CLI (plain readline)
CLAUDE_CODE_FORCE_RECOVERY_CLI=1 ./bin/claude-haha

# Help / all options
./bin/claude-haha --help
```

---

## Supported Environment Variables

| Variable | Required | Purpose |
|---|---|---|
| `ANTHROPIC_API_KEY` | One of two | Sent as `x-api-key` |
| `ANTHROPIC_AUTH_TOKEN` | One of two | Sent as `Authorization: Bearer` |
| `ANTHROPIC_BASE_URL` | No | Override API endpoint |
| `ANTHROPIC_MODEL` | No | Primary model name |
| `ANTHROPIC_DEFAULT_SONNET_MODEL` | No | Sonnet-tier model |
| `ANTHROPIC_DEFAULT_HAIKU_MODEL` | No | Haiku-tier model |
| `ANTHROPIC_DEFAULT_OPUS_MODEL` | No | Opus-tier model |
| `API_TIMEOUT_MS` | No | Request timeout (ms) |
| `DISABLE_TELEMETRY` | No | Set `1` to disable |
| `CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC` | No | Set `1` to suppress extras |
| `CLAUDE_CODE_FORCE_RECOVERY_CLI` | No | Set `1` for plain CLI fallback |

---

## Provider Configuration Examples

### Official Anthropic API

```env
ANTHROPIC_API_KEY=$ANTHROPIC_API_KEY
ANTHROPIC_MODEL=claude-sonnet-4-5
ANTHROPIC_DEFAULT_SONNET_MODEL=claude-sonnet-4-5
ANTHROPIC_DEFAULT_HAIKU_MODEL=claude-haiku-4-5
ANTHROPIC_DEFAULT_OPUS_MODEL=claude-opus-4-5
```

### MiniMax

```env
ANTHROPIC_AUTH_TOKEN=$MINIMAX_API_KEY
ANTHROPIC_BASE_URL=https://api.minimaxi.com/anthropic
ANTHROPIC_MODEL=MiniMax-M2.7-highspeed
ANTHROPIC_DEFAULT_SONNET_MODEL=MiniMax-M2.7-highspeed
ANTHROPIC_DEFAULT_HAIKU_MODEL=MiniMax-M2.7-highspeed
ANTHROPIC_DEFAULT_OPUS_MODEL=MiniMax-M2.7-highspeed
```

### OpenRouter

```env
ANTHROPIC_AUTH_TOKEN=$OPENROUTER_API_KEY
ANTHROPIC_BASE_URL=https://openrouter.ai/api/v1
ANTHROPIC_MODEL=anthropic/claude-sonnet-4-5
ANTHROPIC_DEFAULT_SONNET_MODEL=anthropic/claude-sonnet-4-5
ANTHROPIC_DEFAULT_HAIKU_MODEL=anthropic/claude-haiku-4-5
ANTHROPIC_DEFAULT_OPUS_MODEL=anthropic/claude-opus-4-5
```

---

## Project Structure

```
bin/claude-haha          # Entry script
preload.ts               # Bun preload — sets MACRO globals
.env.example             # Env var template
src/
├── entrypoints/cli.tsx  # CLI main entry
├── main.tsx             # TUI logic (Commander.js + React/Ink)
├── localRecoveryCli.ts  # Fallback Recovery CLI
├── setup.ts             # Startup initialization
├── screens/REPL.tsx     # Interactive REPL screen
├── ink/                 # Ink terminal render engine
├── components/          # UI components
├── tools/               # Agent tools (Bash, Edit, Grep…)
├── commands/            # Slash commands (/commit, /review…)
├── skills/              # Skill system
├── services/            # Services (API, MCP, OAuth…)
├── hooks/               # React hooks
└── utils/               # Utilities
```

---

## Common Patterns

### Run a one-shot code review in CI

```bash
#!/bin/bash
export ANTHROPIC_API_KEY="$ANTHROPIC_API_KEY"
export ANTHROPIC_MODEL="claude-sonnet-4-5"
export DISABLE_TELEMETRY=1
export CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1

git diff HEAD~1 | ./bin/claude-haha -p "Review this diff for bugs and security issues"
```

### Pipe a file for analysis

```bash
cat src/main.tsx | ./bin/claude-haha -p "Summarize what this file does"
```

### Use a longer timeout for large codebases

```bash
API_TIMEOUT_MS=600000 ./bin/claude-haha -p "Explain the architecture of this project"
```

### Force Recovery CLI for low-resource environments

```bash
CLAUDE_CODE_FORCE_RECOVERY_CLI=1 ./bin/claude-haha
```

---

## Troubleshooting

### TUI does not start / shows nothing

The original leak routed no-argument launches to recovery CLI. This repo fixes it, but if you see a blank screen:

```bash
# Check Bun version (needs recent)
bun --version

# Try recovery mode to confirm the API connection works
CLAUDE_CODE_FORCE_RECOVERY_CLI=1 ./bin/claude-haha
```

### Enter key does nothing in TUI

Caused by missing `modifiers-napi` native package. The repo patches this with a try-catch in the `handleEnter` path. If you still hit it:

```bash
bun install          # re-run in case native bindings failed
```

### Startup hangs immediately

Missing stub files (`verify` skill `.md`, `ultraplan/prompt.txt`, `filePersistence/types.ts`). These are included in this repo. If missing after a fresh clone:

```bash
git status           # check for untracked/missing files
git checkout .       # restore any accidentally deleted stubs
```

### `--print` mode hangs

Usually means `filePersistence/types.ts` or `ultraplan/prompt.txt` stub is absent. Verify:

```bash
ls src/filePersistence/types.ts
ls src/ultraplan/prompt.txt
```

If missing, create empty stubs:

```bash
touch src/filePersistence/types.ts
touch src/ultraplan/prompt.txt
```

### API authentication errors

- `ANTHROPIC_API_KEY` → sent as `x-api-key` header (standard Anthropic format)
- `ANTHROPIC_AUTH_TOKEN` → sent as `Authorization: Bearer <token>` (some compatible APIs require this)
- Set only one; if both are set, check which your provider expects

### Provider rejects model name

All four model env vars must be set to names your provider recognizes:

```env
ANTHROPIC_MODEL=your-provider-model-name
ANTHROPIC_DEFAULT_SONNET_MODEL=your-provider-model-name
ANTHROPIC_DEFAULT_HAIKU_MODEL=your-provider-model-name
ANTHROPIC_DEFAULT_OPUS_MODEL=your-provider-model-name
```

### Telemetry / unexpected outbound requests

```env
DISABLE_TELEMETRY=1
CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1
```

---

## Key Fixes vs. Original Leaked Source

| Symptom | Root Cause | Fix Applied |
|---|---|---|
| TUI never starts | Entry script routed no-args to recovery CLI | Restored `cli.tsx` full entry path |
| Startup hangs forever | `verify` skill imports missing `.md` files; Bun text loader hangs | Created stub `.md` files |
| `--print` hangs | `filePersistence/types.ts` missing | Created type stub |
| `--print` hangs | `ultraplan/prompt.txt` missing | Created resource stub |
| Enter key does nothing | `modifiers-napi` native pkg absent; `isModifierPressed()` throws, breaking `handleEnter` | Added try-catch around modifier check |
| Setup skipped entirely | `preload.ts` auto-set `LOCAL_RECOVERY=1` bypassing all init | Removed that default |

---

## Tech Stack

| Layer | Technology |
|---|---|
| Runtime | Bun |
| Language | TypeScript |
| Terminal UI | React + Ink |
| CLI parsing | Commander.js |
| API client | Anthropic SDK |
| Protocols | MCP, LSP |

---

## Disclaimer

This project is based on Claude Code source code that leaked from Anthropic's npm registry. All original source code copyright belongs to [Anthropic](https://www.anthropic.com). For educational and research use only.
```

Attribution

reason-machinesreason-machines
View sourceMore from reason-machines →
SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments (0)

No comments yet. Be the first to comment!

SSkills DirectorySkills Directory

Ship a skill? Prove it's safe.

Free 120-pattern security scan, letter grade, and an embeddable README badge.

Submit a skill

Related Skills

ucoz-landing-skill

Playbook for creating and editing uCoz landing pages via MCP tools (`templates_tool`, `ftp_tool`, `modules_tool`). Use for tasks such as: "build a landing page", "update the homepage as a landing page", "create a promo page on the homepage", "add a lead form / menu / SEO to the homepage". Homepage: `page_list`, `page_get`; first publish — `page_update` with full `page_tmpl`; HTML edits after generation — `patch_template` (module_id=2, template_id=1), not `update_template`. Activate the mail f...

107 votes

Paperclip

Interact with the Paperclip control plane API to manage tasks, coordinate with other agents, and follow company governance. Use when you need to check assignments, update task status, delegate work, post comments, set up or manage routines (recurring scheduled tasks), or call any Paperclip API endpoint. Do NOT use for the actual domain work itself (writing code, research, etc.) — only for Paperclip coordination.

798221 votes

Daw Music

Digital Audio Workstation usage, music composition, interactive music systems, and game audio implementation for immersive soundscapes.

761 votes

Instantly Rdsthomas Mission Control

Instantly.ai cold email outreach API - manage campaigns, leads, accounts, and analytics. Use for cold email automation, lead management, campaign creation/monitoring, and email account warmup.

761 votes

Caveman Compress

Compress natural language memory files (CLAUDE.md, todos, preferences) into caveman format to save input tokens. Preserves all technical substance, code, URLs, and structure. Compressed version overwrites the original file. Human-readable backup saved as FILE.original.md. Trigger: /caveman-compress FILEPATH or "compress memory file"

1023330 votes
View all in tools →