DEVELOPER DOCS

MCP & Plugin

Part 2 — The Claude Code Plugin

On this page

What it provides

CommandPurposeNetwork
/opexia:instrumentDetect the stack, instrument it, verify a span landsYes — verification only
/opexia:securePrompt-injection audit + mitigations under reviewZero egress
/opexia:logCommitted, agent-queryable relational dev-logZero egress
/opexia:compressSet up, calibrate, and verify pxcoreNone

Plus the bundled pxcore MCP server (vendored — no pip install required) and a Stop hook that enriches pending dev-log entries.

Current version: 0.6.0.


Installation

code
/plugin marketplace add <marketplace-url>
/plugin install opexia

Verify:

code
/help

/opexia:instrument, /opexia:secure, /opexia:log, and /opexia:compress should be listed.


/opexia:instrument

Instruments the project for Evigauge observability. It detects the tech stack (Python, Next.js, Node, React, React Native), chooses the correct integration route, writes the code and env, and verifies a span lands with zero dead-letters.

code
/opexia:instrument
/opexia:instrument use direct http
/opexia:instrument attribute per end user

Argument: an optional free-form instruction.

What it does

  1. Detects the stack — reads manifests and entrypoints.

  2. Picks a route:

    StackRoute
    Pythonopexia-trace SDK (init() + @observe)
    Next.jsinstrumentation.ts + OTLP/JSON exporter
    Node / TSGeneric OTel bootstrap + attribute helpers
    React / React NativeDirect HTTP span emission
  3. Writes the code — bootstrap, attribute helpers, and .env entries.

  4. Verifies — emits a real span and confirms it arrived with zero dead-letters. This is the step that matters: an instrumented app that silently dead-letters every span looks identical to a working one until you check.

Also use it for debugging

Run it on an already-instrumented project to diagnose empty dashboard panels or dead-lettered spans. It knows the failure modes — protobuf 415, nested objects in opexia.decision / opexia.sources, undocumented opexia.* keys, missing capture_text.

See SDK: verifying a span landed for the manual equivalent.


/opexia:secure

Audits every system instruction in the project for prompt-injection susceptibility, then applies mitigations only after you explicitly say yes.

code
/opexia:secure
/opexia:secure audit only
/opexia:secure prompts/**

Argument: optionally a path or glob to focus on, or audit only to skip applying fixes.

How it works

  1. Runs opexia audit locally — zero network, zero LLM.
  2. Reads the local report.
  3. Presents each finding with its injection type and mitigation.
  4. Writes fixes only on your explicit go-ahead.

What it audits

Every system instruction it can find: CLAUDE.md, system prompts, agent instructions, skill definitions, and in-code prompt templates.

Checks are applicability-gated — a check that cannot apply to your setup is skipped rather than reported as a false positive. A hardcoded secret is always a FAIL.

Findings are mapped to OWASP, NIST, MITRE, and NSA references, so a finding is defensible in a security review rather than a bare assertion.

Zero egress is a hard guarantee. No network call, no LLM call, no process spawned. Findings are a disclosure about your system's weaknesses — they must never leave the machine. When this runs inside opexia shipcheck as Gate 3, only the verdict and finding categories reach the shared PR comment; the evidence stays local.


/opexia:log

Maintains a local, relational, agent-queryable dev-log — a committed knowledge graph of how the codebase was built.

code
/opexia:log init
/opexia:log                              # enrich pending commit entries (default)
/opexia:log query "why did auth break"
/opexia:log rebuild
ArgumentEffect
initSet up the dev-log and install the post-commit hook
(none)Enrich pending commit entries — the default
query "<question>"Traverse the graph to answer a question
rebuildRebuild graph.jsonl from the entry files

The model

Every git commit becomes a node. Tasks, decisions, bugs, and components are also nodes. Typed edges connect them, so the history is traversable rather than a flat log.

This answers questions a commit log cannot: "what happened in auth and why did it break", "which commit introduced this, and what decision drove it". The commit message records what changed; the graph records why.

How it stays current

  • A post-commit hook writes a stub entry for each commit — it never blocks or slows a commit.
  • A Stop hook nudges Claude to enrich pending entries with the reasoning behind the change when it finishes a task. The hook is loop-guarded, and is a no-op unless the repo has run /opexia:log init.
  • graph.jsonl is the agent-queryable artifact.

Commit the dev-log. Its value is being there for the next person — and for the next agent session.

Local and zero-egress. Nothing about your codebase's history leaves the machine.


/opexia:compress

Sets up and manages pxcore token compression in Claude Code.

code
/opexia:compress
/opexia:compress calibrate
/opexia:compress status
/opexia:compress proxy
ArgumentEffect
(none)Set up compression
calibrateRun the calibration battery for the active model
statusReport whether compression is active, and why or why not
proxySet up pxcore-proxy instead of the MCP route

Calibration

Compression stays off for a model until calibration proves it safe. The battery measures imaged-reading fidelity separately for gist and lookup content, then gates each class independently.

Pre-baked profiles ship inside the wheel (for example pxcore/calibration/profiles/claude-fable-5.json). Run calibrate for a model that has no profile yet.

status is the right command when compression is not saving what you expected — it names the reason: uncalibrated model, content classified exact, or the net-loss guard keeping text.


The Stop hook

The plugin registers one hook:

JSON
{
  "hooks": {
    "Stop": [
      { "hooks": [
        { "type": "command",
          "command": "bash \"${CLAUDE_PLUGIN_ROOT}/hooks/devlog-stop.sh\"" }
      ]}
    ]
  }
}

It nudges Claude to enrich pending dev-log commit entries when a task finishes. It is a no-op unless the repo has run /opexia:log init, so installing the plugin does not change behaviour in repos that do not use the dev-log.