---
title: "shim-cli"
description: "Finds secrets and personal data locally, in your prompts and in the tool results the agent reads, and tells you what it found. In VS Code it reports, and with enforcement on it stops a prompt or denies a tool call before"
canonical: https://agentpluginsdirectory.com/plugins/shim-cli
last-updated: 2026-10-05
---

# shim-cli
Finds secrets and personal data locally, in your prompts and in the tool results the agent reads, and tells you what it found. In VS Code it reports, and with enforcement on it stops a prompt or denies a tool call before it runs; a result that has already reached the model is reported, never masked. No account, no network destination, no telemetry.
- Slug: shim-cli
- Publisher: shim Engineering
- Repository: https://github.com/GetSHIM/shim-cli
- Manifest: plugins/shim-cli/plugin.json
- Version: 1.1.1
- License: Apache-2.0
- Category (editorial): other
- Skills: 0
- MCP servers: 0
- Stars: 7
- Repository created: 2026-08-24
- Repository last pushed: 2026-10-04
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/shim-cli
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## What shim-cli does, in the publisher's words

This plugin registers shim's local hooks. Claude Code gets the prompt, verified PreToolUse and PostToolUse, PostToolUseFailure (report only), Stop, and SessionEnd events. Codex gets the prompt event only. VS Code gets the prompt, PreToolUse, PostToolUse and Stop. There shim never masks; under enforce it stops a prompt, or refuses a call before it runs, and after a tool it only reports: measured against VS Code 1.137.0, a block after a tool is read straight through by the model.

Three manifests sit side by side, one per format:.claude-plugin/plugin.json,.codex-plugin/plugin.json, and plugin.json, the Agent Plugins v1 manifest VS Code, GitHub Copilot CLI and the Copilot app read. Their hook files are hooks/claude.json, hooks/codex.json and com.github.copilot/hooks/hooks.json, each named by its manifest. Current Codex does not load a plugin's hook, so Codex users install it with shim install codex instead; see docs/compatibility.md.

From the project README, punctuation lightly normalized. Full text: https://raw.githubusercontent.com/GetSHIM/shim-cli/HEAD/plugins/shim-cli/README.md
