Skip to content

v0.11.0

Choose a tag to compare

@mikecarroll mikecarroll released this 17 Sep 14:43
· 7 commits to main since this release
c9f7663

coolhand-cli v0.11.0

September 2026 · npm · GitHub

What's new in v0.11.0

This release adds four new commands for browsing LLM request templates, referenced files, and locally-built Claude skills, tightens the MITM proxy's network exposure and secret redaction, and drops the temporary coolhand-node git dependency now that its upstream release has shipped.

New commands

coolhand search-templates — lists and searches the resolved client's LLM request templates. The Unmatched and Ignored API Calls system buckets are hidden unless --include-system is passed.

coolhand search-templates --search "summarize" --workload-id abc123

Supports --search, --workload-id, --status, --include-deprecated, --include-system, --page, --per-page, --client-id, and --json. Requires a private API key (coolhand login --scope private).

coolhand get-template — fetches a single template by hashid, printing every list field plus the full, untruncated user_prompt_pattern and system_prompt_pattern.

coolhand search-referenced-files and coolhand list-referenced-file-sessions — read which files a client's logged requests are associated with. search-referenced-files lists files aggregated and ranked by reference count; list-referenced-file-sessions is the per-file drill-down.

coolhand search-referenced-files --file-path-contains src/config.ts
coolhand list-referenced-file-sessions --file-path src/config.ts

Both require a private API key and support pagination, --client-id, and --json.

coolhand sync-skills — discovers locally-built Claude skills (SKILL.md files) under ~/Documents/Claude, the Cowork local-agent-mode sessions directory, and ~/.claude/skills, content-hashes and dedupes near-identical copies, and uploads one canonical file per skill as a client file.

coolhand sync-skills --dry-run

Supports --root, --source, --skill, --exclude-skill, --force, --dry-run, --client-id, and --json. Requires a private API key, same as upload-client-file.

Changed

coolhand-node bumped to ^0.13.0 (now published to npm), dropping the temporary git-commit pin used while searchReferencedFiles/listReferencedFileSessions were in review.

Security

The MITM proxy (coolhand claude/coolhand monitor) now binds to 127.0.0.1 only, instead of all network interfaces — previously the unauthenticated forward proxy was reachable from any other host on the same network for as long as the wrapped command ran.

coolhand map-claude-projects --output PATH now asks for confirmation before overwriting an existing file, showing its size and modified time. Add --force to skip the prompt.

The MITM proxy now applies the same redactSecrets scrubber to captured request/response bodies that analyze-claude-sessions uses — previously only headers and the URL were sanitized, so a captured body echoing a live secret was uploaded to Coolhand verbatim.

redactSecrets now also catches Authorization: Basic headers and Slack/Discord webhook URLs — send-capable credentials that didn't match the existing assignment-keyword patterns.

Breaking changes

None. All changes are additive or security hardening — no removed/renamed commands, flags, or config fields.