New

Reads now get trimmed, not blocked: −24% cost on bulk-file tasks in our benchmark.

New

Reads now get trimmed, not blocked: −24% cost on bulk-file tasks in our benchmark.

Docs

Snout 0.1.10 · a plugin for Claude Code

Snout is a context gate for Claude Code. It classifies every file your agent reads before it enters context, holds back the bulk a task doesn’t need, and reports what that saved. Everything runs on your machine.

Install

Add the marketplace, install the plugin, and restart Claude Code. That’s the whole setup.

claude plugin marketplace add biffbuster/snout-context
claude plugin install snout@snout

Snout starts in observe mode: it records and flags, and blocks nothing.

Modes

Observe. Records every read and what Snout would hold back. Blocks nothing. This is the default.

Advise. Asks you before a low-value read goes ahead.

Enforce. Trims a flagged whole-file read to its first lines and attaches an outline and a search hint, so the agent keeps working in the same turn.

/snout:mode enforce

Commands

/snout:report what this session read, and how much was low-value
/snout:report --by-agent the same per subagent, plus reads one agent repeated
/snout:explain <path> why a file was classified: label, score, band
/snout:scan [dir] per-label distribution for a folder
/snout:allow <path> never flag this file again
/snout:apply suggested changes, previewed, applied on --yes
/snout:statusline a live token counter in your terminal
/snout:doctor is it installed, and is it firing?

What gets classified

Rules look at a file’s name, its path, and its first 2 KB. There’s no model and no network call, and a decision takes under a millisecond.

Lockfiles. package-lock.json, yarn.lock, Cargo.lock, and the rest of the family.

Generated code. Files that say they’re generated, with banners like @generated or DO NOT EDIT, plus generated JSON and YAML by naming convention.

Vendored code. vendor/, node_modules/, deps/, and other installed trees.

Build output. dist/, build/, out/, target/, and coverage/, but only when your .gitignore ignores them. A committed build/ folder is usually hand-written tooling.

Minified files. *.min.js, *.min.css, and source maps.

Secrets. .env files, keys, and credentials. Snout asks before these are read, in every mode.

Scoring and thresholds

Every file gets a score from 0 to 1 for every label. The strongest flag decides the band.

Act, 0.90 and up. Enforce trims the read; advise asks first.

Ask, 0.50 to 0.90. Snout checks with you before the read.

Read, below 0.50. Unsure means read. The agent gets the whole file.

Files under about 2k tokens and directories are never blocked, because a block costs the agent a turn. To preview other thresholds on a folder:

/snout:scan src --deny 0.95 --ask 0.6

Configuration

Settings resolve in order: built-in defaults, then ~/.snout/config.json, then .snout/config.json in your project, then environment variables. /snout:doctor shows where each setting came from.

{
"mode": "enforce",
"alwaysAllow": ["fixtures/**"],
"alwaysDeny": ["legacy/generated/**"]
}

Your data

Everything Snout records lives in .snout/ in your project, as plain JSONL you can read, search, and delete. Add .snout/ to your .gitignore. The free plugin never sends anything off your machine.

Measured results

Our benchmark runs real headless Claude Code sessions on 9 coding tasks, with Snout off and with it enforcing, and each task’s own test decides pass or fail. On Haiku, across 90 runs, cost on tasks that meet bulk files fell 24%, and every task passed in both arms. On tasks that never touch bulk files, Snout did nothing and cost didn’t move. The same tasks on Codex CLI cut effective tokens 23% on bulk-file tasks, with all 30 enforced runs passing.

Snout, a pink anteater in a cowboy hat
Snout, a pink anteater in a cowboy hat