Plugins · CPO
CLI reference
Every ccpp cpo command: inspect the rules in force, validate files, dry-run hooks, manage profiles.
All commands print Markdown, or JSON with --json.
Inspect
| Command | |
|---|---|
ccpp cpo view [dir] | The rules in force in a project directory (default .): name and description of every active policy. Written for Claude: refusals point to it. |
ccpp cpo list | Built-in, user and project policies, with status active, disabled, overridden or invalid. |
ccpp cpo show <id> | Metadata, message and issues of every file defining <id>. |
ccpp cpo catalog | Events in lifecycle order, check kinds, builtins, effects, CEL variables and functions, placeholders. |
ccpp cpo schema | JSON Schema of the frontmatter, including registered builtins. |
Validate and test
| Command | |
|---|---|
ccpp cpo lint [files…] | Validates files (all discovered ones by default); exit 1 on errors. |
ccpp cpo trace [file] | Dry-runs a hook input (a file, or stdin): CPO events, evaluations, decision and answer. |
trace reads state but never writes it, never writes logs and sends no webhook. It runs snapshot (git objects
only) and reports what restore would do. A hook input is the JSON Claude Code sends to hooks:
{
"session_id": "test",
"cwd": "/home/me/project",
"hook_event_name": "PreToolUse",
"tool_name": "Bash",
"tool_input": { "command": "npm install left-pad" },
"tool_use_id": "toolu_1"
}ccpp cpo trace hook-input.jsonHooks
| Command | |
|---|---|
ccpp cpo hook | The hook entry point: hook input on stdin, Claude Code answer on stdout and exit code. |
ccpp cpo hooks [--all] | Prints the settings.json hooks block routing every gateable event to ccpp cpo hook. |
The Claude Code plugin registers these hooks for you. ccpp cpo hooks is for setups
that configure hooks by hand.
Profiles
ccpp cpo profile list | view | set | add | create | update | scope | rename | remove | unset, described on
the Profiles page. Publishers use profile index and profile keygen
(Profile sources).
Language servers
ccpp cpo lsp status | stop (Language servers).
Environment variables
| Variable | Default | |
|---|---|---|
CPO_LOG_DIR | <tmp>/ccpp-cpo/log | Where log writes one JSONL file per session. |
CPO_STATE_DIR | <tmp>/ccpp-cpo/state | Session, turn and tool use state, and the work ledger. |
CPO_PROFILES | bundled profiles | The profile source, a directory or an http(s):// URL. |
CPO_PROFILES_SIGNING_KEY | none | Default private key for profile index --sign. |
CPO_LSP_BUDGET_MS, CPO_LSP_IDLE_MS | 4000, 30 minutes | Language server check budget, daemon idle time. |