claude-tap
A local proxy and trace viewer for coding agents: shows system prompts, tool calls and token usage for Claude Code, Codex and other CLIs
Medium risk
We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.
Why this level
- Intercepts the coding agent's network traffic through a local proxy
- Some modes require trusting a local CA certificate
Install
In your terminal, with SkillFoxx CLI
npx skillfoxx add cli/claude-tapDetects the agents on your machine, checks the risk and pins the version.
Other ways to install
Install the tool
pipx install claude-tapWithout pipx, pip install claude-tap works too.
Install claude-tap: uv tool install claude-tap (or pip install claude-tap). Then launch the agent through the wrapper, for example claude-tap instead of claude, or claude-tap --tap-client codex instead of codex.
Other ways from the author
uv tool install claude-tapRecommended install method.
This is third-party code. Review the repository files before installing.
What it does
claude-tap wraps around a coding agent and intercepts its network traffic locally, without sending anything off the machine. The viewer shows the system prompt, message history, tool schemas and calls, streamed responses, and token usage per request. It can diff two adjacent requests line by line to show exactly what changed in the context between agent turns. Each session is saved as a self-contained HTML file that can be shared without running claude-tap again.
Who it is for. For developers debugging coding-agent behavior who want to see the actual model request instead of guessing at it.
Good fit when
- You need to understand why an agent behaved unexpectedly by checking its real context
- You need to compare what changed in the prompt between two consecutive requests
- You need to measure token usage for a specific session
- You route through a custom gateway like DeepSeek or AWS Bedrock and want to verify what actually goes out
Not a fit when
- You only need a usage summary, not full request tracing
- You work with a client claude-tap does not support intercepting (check the supported list)
Example request
Run Claude Code through claude-tap and show what changed in the system prompt between the last two requestsLimitations
Requires Python 3.11 and the client you want to trace already installed. Some clients (Gemini CLI, OpenCode, Pi, Hermes Agent) use forward-proxy mode, which intercepts all of the process's traffic, not just model requests. On macOS, some clients require trusting a local CA certificate in the user login keychain.
How to disable. Just run the agent directly instead of through claude-tap; remove the package with uv tool uninstall claude-tap or pip uninstall claude-tap.
Security check
- Intercepts the coding agent's network traffic through a local proxy
- Some modes require trusting a local CA certificate
README in short
The README describes claude-tap as a local proxy and trace viewer for coding agents, distributed via PyPI. It supports over a dozen clients through reverse- and forward-proxy modes, while Cursor is handled by watching transcripts without traffic interception. The viewer ships as a single self-contained HTML file with a structural diff, search, token usage breakdown, dark mode and several interface languages. Separate guides cover routing Claude Code through the DeepSeek API and AWS Bedrock. MIT licensed.
FAQ
Does data leave my machine?
No, the viewer runs locally, traces are stored on disk, and common auth headers are redacted before they are recorded.
Which agents does it work with?
Claude Code, Codex CLI and App, Gemini CLI, Grok Build CLI, Kimi CLI, OpenCode, Pi, Hermes Agent, Cursor CLI, Qoder CLI, Antigravity CLI, CodeBuddy CLI and a few others — the full list is in the README.
Related
A CLI for testing and red teaming LLM applications: compares models, runs automated CI checks and finds vulnerabilities
Playwright CLI
playwright-cli
Microsoft's official Playwright CLI with an agent skill: drive a browser through short commands without heavy MCP schemas
The official MCP server debugger: web UI, automation CLI and terminal UI in one package
SonarSource's official MCP server: quality and security issues, quality gates and code analysis from SonarQube Server and Cloud