Claude Engineering Coach — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Claude Engineering Coach (Plugin) and scored it 15/100 (red). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 4 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 4 flagged
This plugin references the AWS credentials file or the access-key fields stored inside it (const AWS_ACCESS_KEY_ID = /\b(?:AKIA|ASIA|ABIA|A…). Those are long-lived keys with broad cloud access, so any code that reads them can hand your whole AWS account to whatever it contacts next.
creds = open(os.path.expanduser("~/.aws/credentials")).read()
requests.post(url, data={"creds": creds})# let the SDK resolve credentials; never read or transmit the file yourself
import boto3
s3 = boto3.client("s3")This plugin references the AWS credentials file or the access-key fields stored inside it (var AWS_ACCESS_KEY_ID = /\b(?:AKIA|ASIA|ABIA|ACC…). Those are long-lived keys with broad cloud access, so any code that reads them can hand your whole AWS account to whatever it contacts next.
creds = open(os.path.expanduser("~/.aws/credentials")).read()
requests.post(url, data={"creds": creds})# let the SDK resolve credentials; never read or transmit the file yourself
import boto3
s3 = boto3.client("s3")Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A native Claude Code plugin that coaches you on your AI-assisted coding — without leaving the Claude Code terminal. Get usage summaries, anti-pattern coaching, tool comparisons, and flow analysis via MCP tools and /coach:* slash commands. (It can still read Codex / OpenCode / Copilot sessions too, but it runs inside Claude Code.)
Local-only · read-only · zero telemetry.
Reuses the analytics core of Microsoft's AI Engineering Coach — but that is a VS Code / GitHub Copilot extension. This one is built for Claude Code: it ships as a Claude Code plugin, so the coaching lives where you already work. MIT-licensed. Not affiliated with, sponsored by, or endorsed by Microsoft. See NOTICE.It reads your on-disk AI session logs (e.g. ~/.claude/projects/**/*.jsonl) and turns them into actionable coaching:
Claude can also call the underlying tools on its own — just ask "how was my coding this week, and what should I improve?"
Nothing leaves your machine: the server parses your logs in-process, redacts secrets before any output reaches the model, and never writes to your session files.
Requires Node ≥ 18 (the bundled MCP server runs with node). No npm install needed — the server bundle and rule assets are committed.
In an interactive Claude Code session:
/plugin marketplace add nnhhoang/claude-engineering-coach
/plugin install coach@devempower-coach
/reload-pluginsHere marketplace add points at the GitHub repo (owner/repo), so there is no folder path to fill in. The marketplace name devempower-coach is read from .claude-plugin/marketplace.json; you use it in the install coach@devempower-coach step. Choose a scope when prompted (Local is fine for yourself).
git clone https://github.com/nnhhoang/claude-engineering-coach.git
cd claude-engineering-coach
claude --plugin-dir .The . means "this folder" — nothing to fill in. Loads the plugin (commands + MCP server) for that session only.
Note: an earlier draft showed/plugin marketplace add /path/to/claude-engineering-coach. That/path/to/...was just a placeholder for "wherever you cloned it" — the two methods above avoid it entirely (one usesowner/repo, the other uses.).
/mcpYou should see the `coach` server connected with 13 tools. Then run:
/coach:summarycoach_summary, coach_activity, coach_credits, coach_codeProduction, coach_flow, coach_patterns, coach_insights, coach_wellbeing, coach_workflows, coach_harnessComparison, coach_sessions, coach_contextHealth, and coach_reload (re-read logs after new sessions).
When no date range is given, tools default to the last 90 days. Pass fromDate / toDate (ISO YYYY-MM-DD) to widen or narrow.
core/ vendored analytics (parsers, analyzers, 45 rule + 10 metric .md)
└─ formatters.ts pure formatter functions
mcp/
├─ tool-defs.ts 12 tools (+ 90-day default + secret redaction)
├─ analyzer-cache.ts lazy, cached Analyzer over parseAllLogs(findLogsDirs())
├─ server.ts MCP stdio server (list / call / reload)
└─ dist/server.mjs committed esbuild bundle (+ rules/ + metrics/ assets)
commands/ /coach:summary · improve · compare · flow
.claude-plugin/ plugin.json + marketplace.json
.mcp.json registers the bundled "coach" serverThe analytics engine is reused verbatim from upstream (it was already VS Code-free). Only the integration layer (mcp/) and packaging are new.
mcp/** or re-vendoring core/npm install # first time only
npm run build # → mcp/dist/server.mjs (+ copies rule/metric assets)
npm test # core-smoke, tool-defs, analyzer-cache, server.e2eThe build commits its output (mcp/dist/) so the plugin runs on a fresh clone with only node.
This project vendors the analytics core of microsoft/ai-engineering-coach (MIT). Vendored files under core/ keep their original Microsoft copyright headers; see NOTICE and VENDOR.md for the exact upstream commit.
Licensed under the MIT License. Not affiliated with Microsoft.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.