seanthegeek

Coding Agent Collector — AI skill for Claude Code

AI community

Dependency-free forensic collector for AI coding agent artifacts (Claude Code, Gemini CLI, Antigravity, Codex, Cursor.

How to install Coding Agent Collector

This entry records only its repository, not the path inside it, so there is no exact command to give. Open seanthegeek/coding-agent-collector and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Coding Agent Collector does

Dependency-free forensic collector for AI coding agent artifacts (Claude Code, Gemini CLI, Antigravity, Codex, Cursor, ...) for live hosts and disk images

Alternatives in AI

  • Codeburn — Free, local tool to track AI coding token usage and cost across 37 tools and agents (Claude Code, Cursor, Code 9.7k ★
  • Nano Banana 2 Skill — AI image generation CLI powered by Gemini 3 Pro 228 ★
  • Squeez — Hook-based token compressor for 5 AI CLI hosts (Claude Code, Copilot CLI, OpenCode, Gemini CLI, Codex CLI) 188 ★

README

coding-agent-collector

Forensic collector for the on-disk artifacts of AI coding agents and assistants. It walks every user's home directory, copies the artifacts into a staging area, hashes them, and produces one `tar.gz` with a JSONL manifest.

Covered tools, with how each one's catalog entries were validated:

Tool Validation
Claude Code, Antigravity CLI, Codex CLI, Copilot CLI, Ollama Real install plus source
Gemini CLI, Qwen Code, Aider, Continue, Goose, Zed, OpenCode, Crush, Cline, Roo Code, Kilo Code Source code of the project
Amp, Factory Droid, Augment Shipped npm bundle strings plus official docs
Kiro Amazon Q CLI source, Kiro CLI binary strings, official docs
Cursor, Windsurf, Claude Desktop, ChatGPT Desktop Official docs, vendor forums, published DFIR write-ups

VS Code, VSCodium and their forks are collected through their `User` directories, which hold the state of Copilot Chat, Cline, Roo Code, Kilo Code, Continue and Augment extensions. Shell histories and shared cross-agent directories such as `~/.agents` and `~/.env` are collected too.

There are two collectors with the same catalog, manifest schema and archive layout:

  • collect-agent-artifacts.sh is a single POSIX sh script with no dependencies beyond the base system. It runs under bash 3.2 (macOS /bin/sh), dash, ash and busybox, FreeBSD and OpenBSD sh, and zsh in sh emulation.
  • Collect-AgentArtifacts.ps1 is a single Windows PowerShell 5.1 script with no modules, for live Windows hosts. It also runs under PowerShell 7 on any OS.

Either script can collect a mounted disk image of any of the three platforms, because every catalog entry is tried against every home directory.

Quick start

# Live host, all users (run as root to read other users' homes)
sudo ./collect-agent-artifacts.sh -o /var/tmp/ir

# Mounted disk image (Linux, macOS or Windows volume)
sudo ./collect-agent-artifacts.sh -r /mnt/evidence -o /cases/host01