CoalMine

Nine review skills for coding agents: dead code, hallucinations, dependency security, resilience and contract drift

Plugin

Medium risk

We rate an entry medium when the tool runs code, makes network calls or reads project files. Check what exactly it does before installing.

Why this level

  • The checks read project files and run builds and tests
  • Fixes apply to the working tree, though with a revert if tests fail
All reasons and checks

thecolliery/coalmine

Install

In your terminal, with SkillFoxx CLI

npx skillfoxx add plugins/coalmine

Detects the agents on your machine, checks the risk and pins the version.

Other ways to install

Run one by one in the Claude Code chat

/plugin marketplace add thecolliery/coalmine
/plugin install coalmine@coalmine

Checked against the repository on Sep 25, 2026, commit 4e84429.

Text for your agent

Install the plugin: /plugin marketplace add TheColliery/CoalMine, then /plugin install coalmine@coalmine. Alternatively: npx skills add TheColliery/CoalMine. Run /rot-canary for analysis without edits.

Other ways from the author
/plugin marketplace add TheColliery/CoalMine
/plugin install coalmine@coalmine

In Claude Code the rot-canary hook is wired automatically.

This is third-party code. Review the repository files before installing.

What it does

The plugin adds nine code quality checks to the agent, each as a separate skill. They include rot-canary for dead code, leaks and stale docs, source-grounding against hallucinations, supply-chain-audit for dependency vulnerabilities and licenses, plus checks for resilience, observability, testability, scaling and contract drift. Some checks run on demand via a command, some run in the background, and in Claude Code rot-canary wires into hooks and runs at session end. Every fix goes through a safe loop that reverts if tests fail.

Who it is for. For developers and QA engineers who want to catch common code problems before they reach the repository.

Good fit when

  • You need to scan a project for dead code, leaks and races at session end
  • You need to audit dependencies for vulnerabilities and licenses
  • You want a background guard against agent hallucinations with source verification

Not a fit when

  • You need a full static analyzer or CI pipeline rather than in-agent checks
  • You are conserving tokens and cannot afford extra passes on every task

Example request

Run rot-canary on the changed files and show dead code and leaks, do not fix anything yet

Limitations

The checks run inside the agent and depend on its model; this is not a deterministic linter. Automatic session-end runs are wired out of the box for Claude Code; for other agents the hooks are added manually with snippets from platform-configs. Apache-2.0 licensed.

How to disable. Uninstall the coalmine plugin via /plugin or remove the skill folders and the rot-canary hooks from the agent settings.

Security check

  • The checks read project files and run builds and tests
  • Fixes apply to the working tree, though with a revert if tests fail

README in short

The README describes nine canary skills, named after the mine canary that dies first. A table lists what each check catches and how it runs: background, one-time, on demand or automatically at session end. It notes compatibility with Claude Code, Cursor, Codex, Gemini CLI, Cline and Copilot through the SKILL.md standard. Installation is a Claude Code plugin or via npx skills; fixes apply through a safe loop with rollback.

FAQ

Do the checks fix code or only report?

By default they report first; fixes apply through a safe loop: stash, apply, run build and tests, revert on failure.

Does it work outside Claude Code?

The skills follow the SKILL.md standard and work across agents, but automatic session-end hooks are wired out of the box for Claude Code; others use manual snippets.

Editors’ pick

A skills library that gives coding agents a development process: brainstorming, planning, TDD, subagents and code review

PluginMedium riskNo VPN needed292.5KRepository stars
Editors’ pick

Small composable skills for engineering with agents: plan grilling, TDD, bug diagnosis, code review and architecture

SkillLow risk271.4KRepository stars
Editors’ pick

GitHub toolkit for spec-driven development: the specify CLI adds agent commands and skills to a project, from principles to implementation

CLIMedium riskNo VPN needed139.3KRepository stars

Reference MCP servers

Model Context Protocol servers

Official

Official reference MCP servers: Filesystem, Fetch, Git, Memory, Sequential Thinking, Time and Everything

MCP serverMedium risk90.6KRepository stars
Foxx AICoalMine

I am Foxx AI and I have already vetted this tool. Ask about install, setup or anything else, and I will keep it simple.