Golden Thread 0.21.0 · a plugin for Claude Code · MIT

Memory, rules and security for Claude Code, shaped to the way you work

One vault every session shares, rules re-asserted for every response, one-tap actions for your role, and your fingerprint on the actions that matter. Click any feature below to watch it run in gt's own help.

Click any tile

Everything in the box

Every feature works two ways: type the command, or just say what you want in plain words and Claude runs it for you. Each tile opens a demo of it; nothing runs on your computer.

Memory every session sharesType/gt:gt-openOr just sayOpen the my-app project and continue where we left off.One Obsidian vault of plain markdown and git. Opening a project loads its brief, research, decisions and design in a fixed order, and indexes its memory notes without reading them all, so the session starts informed and your context stays small.See it run → Capture at the closeType/gt:gt-closeOr just sayI'm done for now, wrap up this session.At the end of a session gt sorts what was learned: dated findings go to research.md, choices and their reasons to decisions.md, open items into a handoff, and anything true across projects to the shared wiki. Every write goes through a queue that refuses to overwrite another live session's work.See it run → 10 Core rules, every responseTypecore-rules/*.mdOr just sayShow me my Core rules and which ones are checked.Your rules are re-asserted with every prompt, so a long session cannot crowd them out. Five are also verified: a commit without passing tests, a secret in the session, a direct vault write, an unnamed vault target or a reply without the real time is blocked before it lands. Each rule is one file you can read, edit or add to.See them → Plan before codeType/gt:gt-planOr just sayPlan the retry-logic change before writing any code.Restates the requirement, reads the project's design, names the risks and unknowns, and writes a numbered plan where every phase has a goal and a done condition. Nothing is built until you approve it, and editing the plan resets the approval.See it run → Build it test-firstType/gt:gt-implementOr just sayImplement the approved plan, one phase at a time.Carries out the approved plan one phase at a time: writes the failing test, makes it pass, runs the checks and names which tests ran. It stops on the first failure and commits only on your yes. It refuses to start without an approved plan.See it run → Commit only when greenType/gt:gt-allin-commitOr just sayCommit this once every check passes.Runs every check (tests, the secrets scan, code and lint rules) and reports how many actually ran, not just what they found. It refuses to commit on the default branch, without a test receipt that covers every staged file, or when a check could not run. It never pushes. The demo shows a commit refused, the tests run, then let through.See it run → Your role, your toolsTypeinstall.sh --personaOr just saySet my persona to executive.Eight roles: developer, product manager, project manager, executive, leadership, operations, DBA and network administrator. Each starts its projects with the files people in that role keep, such as a status board, a one-page brief, an incident log or an IP/VLAN map, and adds 12 one-tap buttons. Drafts are written for your audience; facts never change with your role.See them → Security levelType/gt:gt-settings lockdownOr just saySet my security level to trust local.Choose how much Claude may run without asking: strict, trust local, trust network, insecure or paranoid. gt writes only its own allow rules into Claude Code's settings, backs the file up first and logs every change. Try any action at each level in the help's Security tab.See it → Every protection, its own switchType/gt:gt-settings securityOr just sayTurn on sandbox mode.The level is a starting point, not a package. Sandbox mode, gt unlock, each paranoid part, single-use permits for 15 actions, protected paths, the commit test gate and the push and commit fingerprints can each be turned on or off. With gt unlock on, loosening one needs you present.See it → Your fingerprint for what mattersTypegt_unlock.py enroll touchidOr just sayHelp me set up gt unlock with Touch ID.With gt unlock on, sensitive actions wait for you: a gateway call to GitHub, Jira or Microsoft 365, a stored credential, a publish, reading a folder outside your projects, or turning a protection off. Approve with Touch ID, Windows Hello or an authenticator code. An agent's shell cannot do it for you.See it → LOTR: one gateway, fewer tokensType/gt-lotr:gt-lotrOr just sayShow my open pull requests and my Jira issues.Put one gateway in front of your MCP servers instead of loading every server's tool schemas into every session. A specialised agent makes the calls and returns a compact answer, so large results never fill your context: about half the tokens in typical use, up to 90% with a specialised agent.See it run → Visualize how it worksType/gt-visualize:gt-visualizeOr just sayExplain how this codebase works, in 3D.Turns a codebase into a scroll-driven 3D walkthrough written from the code and your notes, or a code city where every file is a building, sized by lines and coloured by language or churn. Then tour it scene by scene, ask what any part does, or trace a path hop by hop.Explore it → Usage meterType/gt-usage:gt-usageOr just sayAm I near my limit?Shows where you stand against your 5-hour and weekly allowance and what ending or cutting a session would save. Above a threshold, every reply carries a one-line note so you never hit the limit by surprise.See it run → Savings you can seeType/gt-usage:gt-usage-savingsOr just sayIs gt saving me tokens?A running ledger of what gt saved you: LOTR's smaller context, sessions compacted while their cache was still warm, and calibration. Each entry says how it was measured.See it run → Calibrate the modelsType/gt:gt-calibrateOr just sayCheck whether each agent is on the right model.Re-runs recent agent stages on cheaper and stronger models and compares the results, so every agent runs on the smallest model that still gets it right. It shows an estimated cost before it spends anything.See it run → Handoffs nothing falls out ofType/gt:gt-create handoffOr just sayWork through the handoffs that are waiting.When a session ends with work open, the next one gets a handoff with each item listed and labelled by how well it is known. A handoff closes only when every item is resolved: done, turned into a task, or dropped with a reason.See it run → What's next, across everythingType/gt:gt-list tasksOr just sayWhat's overdue, and what should I do first?Every open task in every project, ranked by project priority against the clock. Start my day shows what is waiting on you, what is overdue and what to do first.See it run → Correct a wrong fact everywhereType/gt:gt-forgetOr just sayForget that we chose Postgres; that was wrong.When something turns out to be wrong, gt finds every note that states it and retracts each one, so a mistake does not keep coming back in later sessions.See it run → Every machine in stepType/gt:gt-syncOr just saySync the vault with my other machine.Your vault is a git repository. gt-sync shows how far ahead or behind it is, pulls newer knowledge from your other machines (fast-forward only, never a merge) and pushes this machine's work after its checks pass.See it run → Try it safely firstType/gt-demo:gt-demoOr just sayRun the Golden Thread demo.A self-running tour of PizzaBot 3000 in its own throwaway vault: every act shows a real feature, and you only click Next. Your own notes are never touched.See it run →
Your role's buttons

The gt pane, for each role

Each role gets its own 12 one-tap buttons in a pane beside Claude Code (Claude Code 2.1.287 or newer). These are the real buttons from each role pack. Click one to see exactly what it sends to Claude. You can rename, reorder or add your own.

This button sends

Click a button.

Recorded end to end

Watch a whole workflow

Real conversations recorded against gt's demo vault: what you say, what Claude runs, what gt answers.

Coming in 0.21.0

What's new

Security level at install

The installer asks every choice up front, security first. Five levels, from strict to paranoid, decide how much Claude may run without asking. They reduce prompts; they are not a security boundary.

Paranoid

Strict plus locks on gt's installed code: read-only files, a guard on shell writes, and a signed manifest each hook checks before it runs. Changing it needs you in person.

Single-use permits

Optional tokens for 15 risky actions, including push, publish, file writes and network fetches. Bound to one action and target, they expire in minutes and work once.

File and network brokers

Disk reads, web fetches and file writes each go through one narrow agent. Paths like ~/.ssh, .env and .git are never written, even with approval.

Spend less allowance

One token profile sets seven cost settings. A cache-expiry guard compacts idle sessions while their cache is warm, and a models page shows each agent's cost.

Memory you can correct

/gt:gt-forget retracts every note that states a wrong fact. Handoffs close only when each open item is resolved.

Breaking: /gt:gt-close now closes the session and /gt:gt-complete completes a project, task or handoff. The levels very secure, mostly secure and partly secure are renamed strict, trust local and trust network; an existing setting carries over. Full list in the changelog.

The Core tier

The ten rules

1Write to the vault only through a queue, never straight into a file another session is editing.checked
2Name the vault on every command that changes it.checked
3Never put a secret's value into the session, not even to check or redact it.checked
4Never commit code whose tests you have not seen pass, and say which ran.checked
5Begin every reply with the real wall-clock time from a hook.checked
6The always-loaded memory holds only facts every project needs.reminder
7Don't load the whole memory index up front; look things up.reminder
8Run independent work in parallel, within one budget shared by every session.reminder
9Secrets live only in the secrets store, never in source, a repo, a log or a session.reminder
10Label every figure presented as fact: unverified, self-verified or independently verified.reminder

Every rule is re-asserted for every response; "checked" rules are also verified, and a reply or command that breaks one is blocked. LOTR figures are the author's own measurements; savings depend on your servers and workload.

Install

Try it

git clone https://github.com/shaven/golden-thread
bash golden-thread/golden-thread-plugin/install.sh --vault ~/MyVault
# then restart Claude Code: plugins and hooks load at session start