GuidesClaude Code

Five free Claude Code add-ons worth installing

Memory that survives a closed session, and context that costs less.

Persistent memory across sessions, smaller context, an official Anthropic plugin that audits your project, and a skill that learns from your corrections. What each one does, the install commands, and what it can see.

Free. No email required, nothing to download.

What you get
  • Four free add-ons, what each one does, and the exact install commands
  • Which to install first, and which to leave until you hit a real problem
  • What each tool can see, including the one that can sync your memory to the cloud
  • The gateway that pools free provider tiers, and the security setup it needs first
  • The safety check to run before you install any of them

Install for a problem you actually have

Every one of these is free and takes minutes to install, which is exactly why people end up with five of them and no idea what any of them can see.

So the rule first, then the tools. Install one at a time, for a problem you have already hit, and read what it can access before you point it at real work. A Claude Code add-on can read your files, your context and your credentials, and can talk to services outside your machine. That is what makes them useful and it is also the whole risk.

The add-ons are free and open source. Claude Code itself, and any third party model provider you wire in, still cost whatever they cost. Two of these route your work somewhere: Headroom through a proxy on your own machine, and Claude-Mem through a model to compress it. Both are covered below.

Claude Code Setup: let Anthropic audit your project

Start here, because it tells you which of the rest you actually need.

Claude Code Setup is published by Anthropic on its own plugin marketplace. It reads your codebase and recommends the automations that fit it: skills, MCP servers, hooks, subagents and slash commands. A React project might come back with a browser testing MCP. A data project will not.

It runs read only and does not modify your files, which makes it the safest thing on this page to try first.

Run it against a real project rather than an empty folder. On an empty folder it has nothing to reason about, which is how people conclude it does nothing.

Claude-Mem: memory that survives a closed session

Close a Claude Code session and the useful context goes with it. Next time you are re-explaining the project, the decisions you already made, and the three approaches that did not work.

Claude-Mem captures what happens during a session, compresses it, and makes the relevant parts available again in later sessions. So Claude keeps hold of your project, your previous decisions, the work already done and the problems you hit.

# the quick way
npx claude-mem install

# or from inside Claude Code
/plugin marketplace add thedotmack/claude-mem
/plugin install claude-mem

Restart Claude Code after installing, or it will not pick up the new configuration.

Before you point it at client work, know where the memory goes:

  • Stored locally by default. A SQLite database for the memories and a Chroma vector database for search, both on your machine.
  • Cloud sync is offered. There is an option to back your memories up to cmem.ai. That is a copy of your working context leaving your machine, so decide deliberately rather than clicking through.
  • Compression uses a model. The installer asks you to sign in to provision a memory key, and you can point it at your own provider key instead. Either way the session content passes through a model to be compressed.
  • Private tags work. Wrap anything you do not want captured in <private> tags and it stays out of storage.

Worth knowing: Claude Code already reads a CLAUDE.md file in your project, and that is the right home for durable facts like commands, architecture and conventions. Claude-Mem is for the session history a file like that will never hold.

Headroom: send less, spend less

More context is not better context. Agents burn tokens on huge tool outputs, logs, files and JSON where most of it changes nothing about the answer.

Headroom compresses what your agent reads before it reaches the model. It ships as a library, a local proxy and an MCP server, and the proxy is the version that drops in front of Claude Code.

# install the CLI
uv tool install --python 3.13 "headroom-ai[all]"

# start the local proxy
headroom proxy --port 8787

# point Claude Code at it
ANTHROPIC_BASE_URL=http://localhost:8787 claude

There are pip, npm and Docker routes too. Check the README for the current invocation, because the project moves quickly.

The numbers it reports, by workload:

  • Around 20 percent fewer tokens for coding agents generally.
  • 60 to 95 percent fewer on JSON, which is where the big wins are.
  • 57 percent on incident debugging, and 42 percent on codebase exploration.
  • 21 to 30 percent on code search and issue triage.

Your mileage depends entirely on what you do all day. Tool heavy and data heavy work saves most, and a conversation about copy saves almost nothing.

Compression runs on your machine. The project is explicit that no prompt or file content is sent anywhere to be compressed, which is the opposite trade-off to Claude-Mem. Think of the pair as remember what matters, and stop sending what does not.

Task Observer: a workflow that learns from your corrections

The most interesting one, and the slowest to pay off.

Most people build an AI workflow and never touch it again, so they keep making the same corrections forever. Task Observer watches multi-step work and records what happened: the corrections you repeat, the gaps where no skill covers a task you keep doing by hand, what worked, and where it was wrong itself.

You review those observations and fold them into better skills. Claude does the task, you correct it, the correction gets observed, the skill improves, and you correct it less next time. It compounds when you are reusing the same skills, and does nothing much if every job is a one off.

npx skills add rebelytics/one-skill-to-rule-them-all --skill task-observer

Installing the files is not the same as switching it on, and this is where most people think it is broken. You also have to add the activation instruction from references/environments.md to your CLAUDE.md, or install the session start hook. To check it is actually running, do a few sessions of real work and look for a skill-observations/observation-log/ folder.

Observations land in skill-observations/observation-log/ and proposed changes in skill-updates/, both in your shared folder. On claude.ai it hands you a structured document at the end of the session instead.

The custom version

Guides like this are the generic version.

Everyone reading this page gets the same system. We build content systems that learn your voice from what you have actually published, know who you are writing for, and make every piece better because of how the last one performed. Then we either hand it to your team or run it for you.

Our systems drive results
267K+
Followers built
8M
Views in 7 months
4
Channels in parallel

OmniRoute: one endpoint, hundreds of providers

The one you have seen in every thumbnail, and the one with conditions attached. Read the whole section before you install it.

OmniRoute is an open source AI gateway. It puts hundreds of providers behind a single endpoint, falls back automatically when one hits a quota, and pools the free tiers of the providers you connect. It is MIT licensed, has over 70,000 stars, and is developed daily. It is a real project, not a wrapper someone threw together.

The genuinely clever part is that a fresh install answers with no key at all, because a keyless provider is pre-wired into its auto routing.

# install and run
npm install -g omniroute
omniroute

# dashboard: http://localhost:20128
# api:       http://localhost:20128/v1

Then connect a provider in Dashboard, Providers, and point Claude Code at the endpoint. The base URL is http://localhost:20128/v1, the key comes from Dashboard, Endpoints, and the model auto lets it choose.

If you would rather run it in Docker, use their own command, because it binds to loopback rather than every interface:

docker run -d --name omniroute --restart unless-stopped --stop-timeout 40 \
  -p 127.0.0.1:20128:20128 -v omniroute-data:/app/data \
  diegosouzapw/omniroute:latest

One practical gotcha before the security one. The Docker image ships a 1024 MB heap, which is fine for the dashboard and light chat but not for coding agents. Claude Code sends long overlapping contexts and the process can die outright. Raise OMNIROUTE_MEMORY_MB and give the container more than 2 GB if you are actually routing Claude Code through it.

Now the part that decides whether you should run this at all.

OmniRoute has an open critical advisory, CVE-2026-88062, scored 9.5. Its custom agent endpoint takes a command from the request and runs it, and the only check is that two attacker-supplied fields agree with each other. Code then runs in the same process that holds every provider API key you connected.

The advisory covers every version up to and including 3.8.50, which is both the newest release and the newest published package, and it lists no patched version. We checked the unreleased 3.8.51 branch on 29 September 2026 and that endpoint is unchanged.

The unauthenticated path is narrower than the headline suggests. It needs one of two things: login switched off, or a brand new instance that has no management password yet. The default is login on, so the exposure is mostly self inflicted. That makes these steps non-optional rather than nice to have.

  1. 01
    Set a management password immediately

    Before anything else, and before you connect a single provider. Until you do, the instance is in the bootstrap window where setup writes are accepted without credentials, which is one of the two ways the flaw is reachable.

  2. 02
    Leave login switched on

    It is on by default. Turning it off for convenience is the other way in, and it is exactly what people do on a local tool. Do not.

  3. 03
    Keep it on loopback

    Bound to 127.0.0.1 and nowhere else. Not on a VPS, not behind a tunnel, not on the office network, not on your phone. If it is reachable, so is the endpoint.

  4. 04
    Treat the box as holding your keys

    Because it does. Connect throwaway provider accounts rather than keys that are attached to billing you care about.

And be clear about what the free token figure means. It adds up the free tiers of many separate providers, it is not extra Anthropic capacity, you create an account and a key with each one, and using their free tiers to drive a coding agent may breach their terms. It is real, it is just not what the thumbnails imply.

Our honest read: worth running on a machine where nothing matters if you want to see what pooled routing feels like. Not worth pointing at client work until a fixed release ships.

The order to add them in

You do not need all four, and adding them all in one afternoon is how you end up unable to tell which one broke something.

  1. 01
    Claude Code Setup

    First, against a real project. Read only, made by Anthropic, and it tells you what the project actually needs.

  2. 02
    Claude-Mem

    Once you are regularly picking work back up across several sessions. That is the point the re-explaining gets annoying enough to fix.

  3. 03
    Task Observer

    Once you have skills and workflows you reuse. Before that there is no pattern for it to observe.

  4. 04
    Headroom

    When context size or token spend has become a real problem, not before. It is the most involved to set up and the easiest to skip.

  5. 05
    OmniRoute

    Last, and only if you specifically want to experiment with routing through other providers. Read its section first, because it is the only one here with an open critical advisory and a setup you have to get right.

Stop at whichever one solved your problem.

Before you install anything

  • One at a time. Install it, use it on something real, understand what it changed. Then consider the next.
  • Check the repository is alive. Stars matter less than the last commit date and whether there are open security advisories. A gateway or proxy that stores credentials and has not been updated in months is a bad bet.
  • Check you are on the real project. Popular tools get cloned. Match the owner name against the project’s own site or docs, not against whichever link was in the video.
  • Not on production credentials first. Try anything new on a project with nothing sensitive in it. Never on a repo holding live keys or client data.
  • Prefer read only. If a tool can work without write access, give it none.

None of this is paranoia about open source. It is that a Claude Code add-on runs with your access, to your files and your keys, and "it was free on GitHub" is not a security model.

Common questions

  • Are these Claude Code add-ons free? Yes. Claude-Mem and Headroom are Apache 2.0, Task Observer is CC BY 4.0, and Claude Code Setup is Anthropic’s own free plugin. Claude Code itself still costs what it costs, and Claude-Mem compresses your sessions through a model, so a provider key you supply can carry its own cost.
  • Which one should I install first? Claude Code Setup, against a real project. It is read only, it is made by Anthropic, and it looks at your actual codebase and tells you which automations are worth having. That answer beats guessing from a list.
  • Does Claude Code not already have memory? It reads a CLAUDE.md file in your project, which is the right place for durable facts like your commands, architecture and conventions. What it does not keep is the history of a session: the decisions you talked through and the approaches you ruled out. That is the gap Claude-Mem fills.
  • What is the difference between Claude-Mem and Headroom? They solve opposite halves of the same problem. Claude-Mem makes sure useful information from past sessions comes back. Headroom makes sure unnecessary information never gets sent. You can run both, and they do not overlap.
  • Will Claude-Mem send my code to the cloud? By default it stores memories locally in SQLite with a Chroma vector database for search. It also offers cloud sync to back them up to cmem.ai, which is opt in, and compression runs through whichever model provider you configure. Use <private> tags for anything that should never be captured.
  • Is OmniRoute safe to use? It has an open critical advisory, CVE-2026-88062, covering every version up to and including 3.8.50, which is the newest release, with no patched version listed. The unauthenticated path needs either login switched off or a brand new instance with no management password set, and login is on by default. So set a password before you do anything else, leave login on, keep it bound to 127.0.0.1, and connect throwaway provider accounts. We would not point it at client work until a fixed release ships.
  • Does OmniRoute really give you 1.6 billion free tokens? Not in the way it sounds. That figure adds up the documented free tiers of many separate providers. It is not extra Anthropic capacity, you have to create an account and an API key with each provider, those keys then sit in the gateway, and using a provider’s free tier to drive a coding agent may breach its terms. The routing and the fallback are real, the headline number is an aggregate.
  • Is it safe to install third party Claude Code extensions? Treat them like code, because they are. They run with your access to your files, your context and your credentials. Install one at a time, read what it can reach, check the repository is actively maintained and free of open advisories, and never try something new on a project holding live keys or client data.

Want this built around your business?

We build content systems for small businesses that are not AI native. Tell us your content problem and we will come back within 48 hours with what yours would include.

← All guides