№ 0064Skill
Agentic Control Plane plugin for Muse Code
A Muse Code plugin that policy-checks every tool call against an Agentic Control Plane workspace before it runs, returning allow, ask or deny and logging each decision with its reason.
# Agentic Control Plane for Meta Muse Code Policy-check every tool call Muse Code makes — before it runs — against your [Agentic Control Plane](https://agenticcontrolplane.com) workspace: allow / ask / deny per call, output scanning after the call, one receipt line per session, every decision in your activity log with the reason attached. ## Status: beta-tracking-beta, contract verified Muse Code is in beta, and in the 0.2.1 binary hooks ship as **plugin capabilities** behind the `MUSE_EXPERIMENTAL_PLUGINS` flag (the flag gates only the management CLI — installed hooks fire in normal runs). The wire contract is Claude Code's hook schema, verified end-to-end against Muse's own `muse plugins hook test` runner: snake_case payloads in (`hook_event_name`, `tool_name`, `tool_input`, `session_id`, `permission_mode`), camelCase `hookSpecificOutput` decisions back, exit 2 + stderr as the fallback block channel, `systemMessage` for advisory lines. Two things still await a live model run (the offline `echo` provider makes no tool calls): the ask-prompt round trip in an interactive session, and the live `PreToolUse` payload — its session-level siblings are already confirmed byte-compatible. ## Install This package **is** a Muse native plugin bundle (`.muse-plugin/plugin.json` at the package root): ```bash npm install -g @agenticcontrolplane/muse-code MUSE_EXPERIMENTAL_PLUGINS=1 muse plugins install "$(npm root -g)/@agenticcontrolplane/muse-code" --scope user MUSE_EXPERIMENTAL_PLUGINS=1 muse plugins approve acp ``` Sign in once to get a credential: - a key in `~/.acp/credentials` (written by the [installer](https://agenticcontrolplane.com/install-explained) — one command, free for individuals). Muse Code runs hooks with a **cleared environment**, so `ACP_BEARER_TOKEN` does not reach them in live sessions — the file is the real path. Optional operational overrides live in `~/.acp/config.json`: `govern_base`, `console_base`, `agent_tier`, `check_timeout_ms`, `shadow`. ## What it does | Event | Gateway call | Effect | |---|---|---| | `PreToolUse` | `POST /govern/tool-use` | allow / ask / deny before the tool runs | | `PermissionRequest` | `POST /govern/tool-use` | a policy deny settles Muse's own approval; anything else lets the native prompt proceed | | `PostToolUse` | `POST /govern/tool-output` | output scanning; a server block becomes a deny the model sees



ChatForm
Tgmlabs