God mode for Claude Code.
This is NOT a third-party Claude Code client. ClawGod is a runtime patch applied on top of the official Claude Code. It works with any version — as Claude Code updates, ClawGod automatically re-extracts and re-patches against the new version on the next launch.
Install these before running the ClawGod installer:
| Tool | Why | Install |
|---|---|---|
| Claude Code (native binary) | ClawGod patches the official Bun standalone binary you already have | claude.ai/install.sh (macOS/Linux) or claude.ai/install.ps1 (Windows) |
| ripgrep | Required by Claude Code's Grep tool | brew install ripgrep / apt install ripgrep / winget install BurntSushi.ripgrep.MSVC |
| Node.js >= 18 | Used by the patcher | nodejs.org |
| Bun | Runtime for the patched cli.js; auto-installed if missing | bun.sh, npm install -g bun, scoop install bun, or choco install bun |
macOS / Linux:
curl -fsSL https://github.com/0Chencc/clawgod/releases/latest/download/install.sh | bashWindows (PowerShell):
irm https://github.com/0Chencc/clawgod/releases/latest/download/install.ps1 | iexGreen logo = patched. Orange logo = original.
| Patch | What you get |
|---|---|
| Internal User Mode | 24+ hidden commands (/share, /teleport, /issue, /bughunter...), debug logging, API request dumps |
| GrowthBook Overrides | Override any feature flag via config file |
| Agent Teams | Multi-agent swarm collaboration, no flags needed |
| Computer Use | Screen control without Max/Pro subscription (macOS) |
| Auto-mode | Unlocks auto-mode for third-party API users (no firstParty gate) |
| Classifier tuning | Tunable auto-mode classifier: timeout / model / retries (CLAWGOD_CLASSIFIER_TIMEOUT_MS, CLAWGOD_CLASSIFIER_MODEL, CLAWGOD_CLASSIFIER_RETRIES) |
| Ultraplan | Multi-agent planning via Claude Code Remote |
| Ultrareview | Automated bug hunting via Claude Code Remote |
| Patch | What's removed |
|---|---|
| CYBER_RISK_INSTRUCTION | Security testing refusal (pentesting, C2, exploits) |
| URL Restriction | "NEVER generate or guess URLs" instruction |
| Cautious Actions | Forced confirmation before destructive operations |
| Login Notice | "Not logged in" startup reminder |
| Patch | What's neutralized |
|---|---|
| Date String (qla) | System prompt encodes user location via Unicode apostrophe variants (U+0027 / U+2019 / U+02BC / U+02B9) and date separator (- vs / for CN timezone). Patched to always use ASCII ' and unmodified date format |
| Geo-Detection Probe (rdp) | Client-side three-axis detection: timezone (Asia/Shanghai / Asia/Urumqi), proxy hostname against XOR-obfuscated 100+ domain blocklist, CN-LLM vendor keywords in base URL. Patched to always return null |
| Apostrophe Selector (odp) | Selects one of four Unicode apostrophes based on detection results. Patched to always return ASCII ' (defense-in-depth) |
| Patch | Effect |
|---|---|
| Green Theme | Brand color → green. Patched at a glance |
| Message Filters | Shows content hidden from non-Anthropic users |
| Feature | What it does |
|---|---|
| Glob/Grep Restore | Bun compile inlines EMBEDDED_SEARCH_TOOLS=true, hiding built-in Glob/Grep tools. Patch un-inlines the env check and adds bfs/ugrep binary availability detection — tools are restored when running under Bun runtime |
| Renderer Shim (2.1.271+) | Claude Code 2.1.271 builds its TUI renderer on Bun.ant.CellSegmenter, a private API that only Anthropic's bundled Bun exposes. ClawGod loads a JS implementation before the patched bundle, so the TUI paints under stock Bun instead of stalling before the first frame |
| 1h Prompt Cache | Forces 1h TTL allowlist on (was effectively 5m → much higher cache_creation token usage) |
| Third-Party Cache Fix | Auto-disables x-anthropic-billing-header when baseURL is non-Anthropic. The header's per-request cch field breaks prompt-cache hit rate on DeepSeek / OneAPI / Bedrock / vLLM and any other Anthropic-compatible proxy. You no longer need to set CLAUDE_CODE_ATTRIBUTION_HEADER=0 yourself. |
| Auto Re-patch | Detects when the user's native Claude binary has been upgraded; transparently re-extracts and re-patches on next launch |
| Update Notification | Checks GitHub releases once per 24h (async, non-blocking). Shows a one-line notice if a newer ClawGod version is available |
| Lean Settings | Three-level token optimization for ~/.claude/settings.json. on (default): removes unused tool definitions + disables Workflows/Artifact; Remote Control remains available. max: additionally disables Remote Control and removes Plan mode, Agent Teams, bundled skills. off: all tools restored |
Lean Settings are non-destructive and persist across updates. Toggle anytime:
claude --lean-on(default) /claude --lean-max(aggressive) /claude --lean-off(restore all). To opt out of a single setting, set it yourself (e.g."disableArtifact": false).
Remote Control (/remote-control, /rc) is allowed in on/off and disabled by default only in max. Updating in on mode or running claude --lean-on clears the older Lean Remote Control disable setting. Only max defaults CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1; explicit environment restrictions are preserved. Remote Control still requires upstream account, authentication, endpoint, and organization eligibility.
claude # Patched Claude Code (replaces the official launcher)
clawgod # Same as `claude`, explicit & guaranteed entry point
claude.orig # Original unpatched version (auto-backed-up)clawgod is unambiguous: on Windows where claude.exe may shadow claude.cmd, clawgod.cmd always works. Even after official self-update overwrites claude, clawgod keeps running the patched build.
~/.clawgod/provider.json is auto-created on first run. Setting apiKey lets you skip OAuth entirely and point ClawGod at any Anthropic-compatible endpoint.
{
"apiKey": "sk-ant-...",
"baseURL": "https://api.anthropic.com",
"model": "",
"smallModel": "",
"effort": "",
"timeoutMs": 3000000
}apiKeyset → ClawGod injects it asANTHROPIC_API_KEYand isolates from~/.claude/settings.json. The default protocol requires an Anthropic Messages-compatible endpoint. For Chat Completions gateways, use the configuration below. A non-AnthropicbaseURLpopulates onlyANTHROPIC_AUTH_TOKENfor gateway auth.apiKeyempty → OAuth path. Runclaude auth loginonce;~/.claudekeeps hosting your subagents, skills, and MCP settings.effort→ Sets reasoning effort; an existingCLAUDE_CODE_EFFORT_LEVELtakes precedence. Withprotocol: "openai-chat",type: "grok"or"openai-compat", the proxy sendsreasoning_efforteven when Claude omits effort for a custom model alias.low,medium,high, andxhighpass through;maxmaps toxhigh;autoomits the parameter to use the upstream default. Choose a level supported by your upstream model. Empty/unset configuration leaves request-level effort in control and adds no effort parameter when the request has none.
For an endpoint that exposes /v1/chat/completions, configure:
{
"protocol": "openai-chat",
"apiKey": "sk-...",
"baseURL": "https://example.com/v1",
"model": "your-upstream-model",
"smallModel": "your-upstream-model"
}baseURL is the API base (including /v1 when required), not the full /chat/completions URL. Set the model names to IDs accepted by your provider. ClawGod starts a loopback proxy inside the launcher process; no external gateway or separate service is required. timeoutMs also covers the upstream request and stream; an existing API_TIMEOUT_MS takes precedence.
- Omitting
protocolkeeps the existing behavior.type: "openai-compat"andtype: "grok"remain supported; an explicitprotocoltakes precedence.protocol: "anthropic"uses Messages directly. Grok defaults tohttps://api.x.ai/v1and retains its settings/environment API key fallback. Other Chat providers require an explicit API base and key. - Supports text, system prompts, tool calls/results, forced tool selection and parallel-tool controls, streaming, usage, and base64/URL images. Parallel tool arguments are assembled and validated before their content blocks are emitted; text still streams immediately. Missing upstream usage remains zero rather than a fabricated exact count.
- Base64 PDFs are sent as Chat Completions
fileparts and require file support in the upstream model/API. Text documents are sent as text. PDF URLs, document citations, non-text tool results, server tools, and structured output formats are rejected with a clear error. Historical Anthropic thinking/signature blocks are omitted. Model-specific reasoning features are not losslessly translated. /v1/messages/count_tokensestimates locally without a billed generation request. Thex-clawgod-token-count: estimateresponse header marks the result. It uses UTF-8 text bytes / 3 plus message overhead, 1600 tokens per image, and decoded PDF bytes / 3. This is a rough budget, not the model's tokenizer; PDF byte size does not reflect page count and the estimate cannot guarantee context-window fit.- Chat
stopmaps toend_turn(ortool_usewhen the response contains tool calls): the protocol does not distinguish natural completion from a matched stop sequence.length,tool_calls, andcontent_filtermap tomax_tokens,tool_use, andrefusal. Upstream HTTP errors retain their status andRetry-After; malformed or truncated streams produce an error. /v1/responsesand automatic protocol detection are not supported. Useopenai-chatonly for Chat Completions endpoints.
~/.clawgod/patches.json (auto-created empty) switches features off persistently — your choices survive updates and reinstalls. Absent key = on.
{ "theme": false, "geo-neutralize": false }| Feature id | Controls |
|---|---|
agent-teams |
Agent Teams always enabled |
computer-use |
Computer Use unlock |
ultraplan |
Ultraplan slash command |
ultrareview |
Ultrareview slash command |
voice-mode |
Voice Mode |
auto-mode |
Auto-mode model selection on third-party APIs |
classifier-tuning |
Auto-mode classifier overrides: CLAWGOD_CLASSIFIER_TIMEOUT_MS (min deadline; unset = 60-120s by context, v2.1.251+), CLAWGOD_CLASSIFIER_MODEL, CLAWGOD_CLASSIFIER_RETRIES (unset = 4) |
theme |
Green brand/logo color scheme |
geo-neutralize |
Geo/proxy steganography neutralization in system prompt |
cyber-risk |
Removes CYBER_RISK_INSTRUCTION from system prompt |
url-restriction |
Removes URL generation restriction from system prompt |
cautious-actions |
Removes "Executing actions with care" section from system prompt |
not-logged-in |
Removes "Not logged in" notice |
message-filter |
Bypasses non-ant message/attachment filters |
bun-ant-shim |
Bun.ant.CellSegmenter renderer shim for Claude Code 2.1.271+ (see Reliability) |
For a single launch, set an env var instead — feature id upper-cased, dashes to underscores:
CLAWGOD_FEATURE_THEME=false claude # green theme off, this run only
CLAWGOD_FEATURE_GEO_NEUTRALIZE=true claude # temporarily re-enable one disabled in patches.jsonSince @anthropic-ai/claude-code v2.1.113, the npm package no longer ships cli.js — it's a thin loader that dispatches to platform-specific Bun standalone binaries. ClawGod adapts:
- Locates the user's installed native Bun binary in
~/.local/share/claude/versions/ - Extracts the embedded
cli.jssource from the__BUNsegment (Mach-O / ELF / PE) - Extracts the embedded
.nodenative modules (audio-capture, image-processor, computer-use-*, url-handler) into~/.clawgod/vendor/ - Rewrites
/$bunfs/...virtual paths to point at the extracted modules - Applies 29 regex-based patches (version-agnostic — same patches work across many releases)
- The
claude/clawgodlaunchers run the patched cli.js under the Bun runtime - Loads
bun-ant-shim.cjsbefore the patched cli.js, supplying theBun.ant.CellSegmenterrenderer API that Claude Code 2.1.271+ expects
A .source-version stamp in ~/.clawgod/ records which native version was patched. On every launch the wrapper compares it against the latest binary in versions/; if the user upgraded Claude Code via the official installer, ClawGod auto-re-patches on the next run.
Just run claude update as usual. ClawGod patches the command to route through its own installer, which pulls the current Anthropic release from npm (@anthropic-ai/claude-code-<plat>@latest), re-extracts cli.js, re-applies patches, and rewrites the launcher. So the upstream update command keeps working the way you expect — you get the latest Claude, with patches still applied, in one step.
Extra options:
claude update --version 2.1.180 # Pin to a specific Claude Code version
claude update --no-upgrade # Re-patch the installed Claude version--version is useful when a new release has issues and you want to stay on a known-good version. --no-upgrade re-applies the latest patches to a complete clean-source backup of the installed version. Older installations without that backup download the same Claude version once to recover it; subsequent re-patches reuse the local backup.
If you'd rather invoke the installer directly (same effect, both paths fetch the same upstream release and re-patch):
macOS / Linux:
curl -fsSL https://github.com/0Chencc/clawgod/releases/latest/download/install.sh | bashWindows:
irm https://github.com/0Chencc/clawgod/releases/latest/download/install.ps1 | iexIf you'd rather drop ClawGod and use Anthropic's original claude update (which manages its own paths and would overwrite our launcher), uninstall first:
bash ~/.clawgod/install.sh --uninstallmacOS / Linux:
curl -fsSL https://github.com/0Chencc/clawgod/releases/latest/download/install.sh | bash -s -- --uninstall
hash -r # refresh shell cacheWindows:
irm https://github.com/0Chencc/clawgod/releases/latest/download/install.ps1 -OutFile install.ps1; .\install.ps1 -UninstallUninstall restores claude.orig → claude and removes the clawgod alias.
After install or uninstall, restart your terminal or run
hash -rif the command doesn't take effect immediately.
GPL-3.0 — Not affiliated with Anthropic. Use at your own risk.
