Plugin
cc-suite
cc-suite turns three CLI tools (Claude Code, OpenAI Codex CLI, Google Gemini CLI) into one shared brain. Project context is written once in AGENTS.md; CLAUDE.md and GEMINI.md just `@AGENTS.md` to import it. Skills live in `.claude/skills/` and `.agents/skills/` symlinks to it, so the same skill works in all three CLIs. Hooks defined for Claude Code are mirrored into Codex's hook system. MCP servers in .mcp.json are visible to all three. The Claude↔Codex delegation lane is bidirectional: from Claude, /cc-suite:audit, :implement, :verify, :review, :bug-analyze, and :review-plan all hand work to Codex and return structured results. Supersedes the separate cc-bridge and codex-toolkit plugins.
- Analysed
- Last observed
What the code does
- Runs shell commands Code that starts system commands on the machine it runs on.
- Starts other processes Code that launches separate programs.
- Downloads and runs code Code that fetches a script and pipes it into a shell.
- Evaluates code at runtime Code that builds and runs code while it executes.
- Runs hooks automatically Hooks that execute without being called explicitly.
- Runs an AI coding agent unsupervised Code that starts an AI coding agent with its approval prompts switched off.
- Reads AI and developer logins Code that refers to AI tool credentials or publishing tokens, such as .npmrc.
Having a capability is not wrongdoing; many tools need these to do their job. It tells you what to check before you install.
This is public metadata, not a safety certification or complete assessment. Static analysis cannot establish what a tool does at runtime.
Risk
Sign in to see this tool's overall risk level and what drives it. Free.
Coverage
Detailed report
8 findings from automated static analysis of the latest version, with severities and explanations.
Using this tool across your team? We can assess your whole inventory.
Request an inventory assessment