Skip to content

anti-hall

anti-hall

Make Claude Code and Codex check before they claim.

Install See the guards

Powered by a Rust engine at its core. How it works

What it is

anti-hall is a plugin for Claude Code, with a separate port for Codex. At its core is a Rust engine that answers every hook (the checks the assistant's harness runs before and after each step) through one thin trigger, running the plugin's own rules (How it works). On top of it sit hooks and a set of skills you can call by name. Together they stop the assistant from:

  • stating things it has not checked: a library function that does not exist, "it works" without running anything, "done" with tasks still open;
  • taking risky git actions: force-pushes, and AI credit lines in commit messages and GitHub PR, issue or release text;
  • flooding your main conversation: heavy commands and file edits go to helper agents, and runaway agent spawning is capped.

Node.js 22+ is a temporary compatibility fallback during the migration and is removed in v1.0. There are no npm dependencies. It runs on macOS and Linux (including WSL on Windows). Everything it keeps stays on your machine, apart from one update check, which you can turn off (details).

  • Verify first

    No claim without a check: speculation, "done" and made-up APIs are sent back.

  • Safe git

    No force-pushes, no AI credit lines in commits or GitHub text.

  • Task tracking

    A task list the assistant must keep honest before it stops.

Install in one minute

You need Node.js 22 or newer on your PATH (node --version) for now (no longer needed from v1.0). The engine binary is fetched for you (needs curl or wget, and tar).

/plugin marketplace add talas9/anti-hall
/plugin install anti-hall@anti-hall
git clone https://github.com/talas9/anti-hall.git
node anti-hall/plugins/anti-hall/codex/install-codex.js --global

Then add .anti-hall/ to your project's .gitignore, because anti-hall keeps per-project session notes there. To check it works, ask the assistant "is anti-hall working". Full steps: Install.

What you'll notice in your first session

Most of anti-hall is quiet. You will see it when the assistant tries one of the things it is there to stop. Each message says what was stopped, why, and what to do instead. The assistant reads it and changes course; you rarely need to do anything.

The assistant tries to force-push. The command never runs:

⛔ anti-hall · git-guard: force push is blocked.
Why: Rewriting published history is a deliberate human action.
Do instead: do it manually with explicit owner confirmation, never from an automated push.

The assistant guesses instead of checking. A reply that ends on "probably" with nothing to back it up is sent back once:

⛔ anti-hall · speculation-guard: your reply states something speculative ('probably')
without verifying it or flagging it as unverified.
Why: Unverified claims read as facts.
Do instead: verify it with a tool, or say what is unverified ('I don't know, here is what
I would check'), then continue.

The main session runs a long command itself. Builds, test suites and deploys go to a helper agent, which returns a short summary instead of pages of output:

⛔ anti-hall · command-guard: heavy command (verb: npm) blocked in the main thread.
Why: Raw output floods the main thread.

Other things you will see:

  • Work is tracked as a task list, and the assistant is asked not to stop while tasks are still open (Task tracking).
  • When the context window reaches 85%, the assistant writes a handover file and suggests /compact or /clear (Handovers and context).
  • An optional two-line statusline shows your project, git state, model, context use and agent activity (Statusline).

Not happy with a check? Every guard has a setting, and you can tell the assistant to skip one for a short while. See Turning a check off.

Network and privacy

There is no telemetry or analytics. One request is on by default: an update check to GitHub (a tag-list request with no project data), which you can turn off with the versionAlerts.antiHall setting. The optional classifier features (Jev, the semantic judge, mesh triage) are off by default and only send the text they judge to the provider you configure. Everything else stays in ~/.anti-hall/ and <repo>/.anti-hall/. The full table is in PRIVACY.md.

Not happy with a check?

Every guard has a setting, and you can tell the assistant to skip one for a short while. See Turning a check off.

Where next

  • Getting started

    Install, update and uninstall on Claude Code and Codex.

  • Guards and checks

    What each guard stops and how to turn it off.

  • How it works

    The Rust engine at the core: one resident process answers every hook.

  • Settings

    Every setting with its default, generated from the code.

  • Troubleshooting

    The doctor, common messages, and what they mean.

  • Contributing

    Branch flow, tests, and where the contributor docs live.