{"slug":"leveldb-ops","title":"leveldb-ops","summary":"Read and inspect LevelDB stores - especially Chromium/Electron app state (Local Storage, IndexedDB, Session Storage). Triggers on: leveldb, .ldb files, IndexedDB, Local Storage, Chromium storage, Electron app state, claude.ai cache, browser forensics, decode app state, claude des","platform":"Claude","tags":[],"authorName":"LLM Mart","authorSlug":"llm-mart","score":0,"source":"github","price":null,"verified":false,"createdAt":"2026-09-30T19:36:47.86094Z","repo":{"url":"https://github.com/0xDarkMatter/claude-mods","stars":43,"forks":7,"license":"MIT","updatedAt":"2026-09-30T15:18:48Z"},"bodyHtml":"<hr>\n<h2>name: leveldb-ops\ndescription: \"Read and inspect LevelDB stores - especially Chromium/Electron app state (Local Storage, IndexedDB, Session Storage). Triggers on: leveldb, .ldb files, IndexedDB, Local Storage, Chromium storage, Electron app state, claude.ai cache, browser forensics, decode app state, claude desktop state.\"\nlicense: MIT\ncompatibility: \"Pure Python via ccl_chromium_reader. Works on Windows/macOS/Linux. No native compilation.\"\nallowed-tools: \"Read Write Bash\"\nmetadata:\nauthor: claude-mods</h2>\n<h1>LevelDB Operations</h1>\n<p>Read and decode LevelDB stores — primarily the Chromium/Electron storage layers (Local Storage, IndexedDB, Session Storage) used by every Electron app on disk: Claude Desktop, VS Code, Discord, Slack, Obsidian.</p>\n<h2>What is LevelDB</h2>\n<p>Embedded key-value store by Google. Sorted KV map, no SQL, no server. Format: a folder of <code>.ldb</code> (sorted runs), <code>.log</code> (write-ahead), <code>MANIFEST-*</code>, <code>CURRENT</code>, <code>LOCK</code>. Both keys and values are arbitrary bytes.</p>\n<p>Chromium layers richer formats on top:</p>\n<ul>\n<li><strong>Local Storage</strong> — flat key→string map, scoped per origin. Easiest to read.</li>\n<li><strong>Session Storage</strong> — same shape, per-tab.</li>\n<li><strong>IndexedDB</strong> — per-origin databases with object stores, indexes, versioned schemas. Encoded with v8 serialization. Needs a real reader.</li>\n</ul>\n<h2>When This Skill Triggers</h2>\n<ul>\n<li>\"What's in the Local Storage of </li>\n<li>\"Decode IndexedDB\" / \"read .ldb files\"</li>\n<li>\"Why does the sidebar show X\" / \"where does the desktop app cache Y\"</li>\n<li>\"Reset / mutate Electron app state\"</li>\n<li>Forensic-style probes of Chrome/Edge/Brave/Electron state</li>\n</ul>\n<h2>Critical Safety Protocol</h2>\n<p><strong>LevelDB uses an exclusive <code>LOCK</code> file.</strong> A running app holds it. Trying to open a live store fails OR silently returns stale snapshots.</p>\n<p><strong>Always copy before reading:</strong></p>\n<pre><code># Copy the entire leveldb dir to a temp location\ncp -r \"$APPDATA/Claude/Local Storage/leveldb\" /tmp/probe/local-storage-db\ncp -r \"$APPDATA/Claude/IndexedDB/https_claude.ai_0.indexeddb.leveldb\" /tmp/probe/indexeddb\n\n# Remove the copied LOCK file so the reader can open it\nrm -f /tmp/probe/local-storage-db/LOCK /tmp/probe/indexeddb/LOCK\n</code></pre>\n<p>The <code>cp -r</code> will warn <code>Device or resource busy</code> for the <code>LOCK</code> file itself — that's fine, the data files copy successfully.</p>\n<p><strong>Never write to the live store while the app is running.</strong> It will corrupt the LSM and crash the app. Quit the app first if you need to mutate.</p>\n<h2>Setup</h2>\n<p><code>plyvel</code> and similar require native compilation and lack Windows wheels. Use <strong><code>ccl_chromium_reader</code></strong> — pure Python, written for browser forensics.</p>\n<pre><code>uv venv .venv --python 3.13\nsource .venv/Scripts/activate          # or .venv/bin/activate on Unix\nuv pip install \"git+https://github.com/cclgroupltd/ccl_chrome_indexeddb.git\"\n</code></pre>\n<p>Not on PyPI — install direct from GitHub. Pulls in <code>ccl-simplesnappy</code> and <code>brotli</code> as transitive deps.</p>\n<h2>Reading Local Storage</h2>\n<p>Storage keys are origin URLs (<code>https://claude.ai</code>). Records are append-only — duplicate <code>script_key</code> entries mean older versions; the <strong>last record wins</strong>.</p>\n<pre><code>import pathlib\nfrom ccl_chromium_reader import ccl_chromium_localstorage\n\nls = ccl_chromium_localstorage.LocalStoreDb(pathlib.Path(\"./local-storage-db\"))\n\n# List all origins\nfor origin in sorted(set(ls.iter_storage_keys())):\n    print(origin)\n\n# Dump one origin, latest-value-wins\nlatest = {}\nfor rec in ls.iter_records_for_storage_key(\"https://claude.ai\"):\n    latest[rec.script_key] = rec.value\nfor k, v in latest.items():\n    print(f\"{k}: {repr(v)[:200]}\")\n</code></pre>\n<p>See <a href=\"scripts/dump_localstorage.py\">scripts/dump_localstorage.py</a> for the full reusable script.</p>\n<h2>Reading IndexedDB</h2>\n<p>IndexedDB is more complex — wrapped object stores with v8-serialized values. <code>ccl_chromium_reader</code> parses it cleanly:</p>\n<pre><code>from ccl_chromium_reader import ccl_chromium_indexeddb\n\ndb = ccl_chromium_indexeddb.WrappedIndexDB(pathlib.Path(\"./indexeddb\"))\nfor db_id in db.database_ids:\n    wdb = db[db_id.dbid_no]\n    print(f\"DB: {wdb.name}\")\n    for store_name in wdb.object_store_names:\n        store = wdb[store_name]\n        for rec in store.iterate_records():\n            print(f\"  {rec.key!r} -&gt; {repr(rec.value)[:200]}\")\n</code></pre>\n<p>See <a href=\"scripts/dump_indexeddb.py\">scripts/dump_indexeddb.py</a>.</p>\n<h2>Common Chromium Storage Locations</h2>\n<table>\n<thead>\n<tr>\n<th>OS</th>\n<th>Path</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Windows</td>\n<td><code>%APPDATA%\\&lt;App&gt;\\Local Storage\\leveldb\\</code></td>\n</tr>\n<tr>\n<td>Windows</td>\n<td><code>%APPDATA%\\&lt;App&gt;\\IndexedDB\\https_&lt;host&gt;_0.indexeddb.leveldb\\</code></td>\n</tr>\n<tr>\n<td>macOS</td>\n<td><code>~/Library/Application Support/&lt;App&gt;/Local Storage/leveldb/</code></td>\n</tr>\n<tr>\n<td>Linux</td>\n<td><code>~/.config/&lt;App&gt;/Local Storage/leveldb/</code></td>\n</tr>\n</tbody>\n</table>\n<p>For raw browsers, <code>&lt;App&gt;</code> is <code>Google/Chrome/User Data/Default</code>, <code>BraveSoftware/Brave-Browser/User Data/Default</code>, etc.</p>\n<h2>Mutation (Advanced)</h2>\n<p>Writing requires either:</p>\n<ol>\n<li><strong>Quitting the app</strong> and using a leveldb writer (Node <code>level</code> package, or rebuild the dir manually) — or</li>\n<li><strong>Patching via the app itself</strong> — many Electron apps expose DevTools. Open with the <code>--remote-debugging-port=&lt;n&gt;</code> flag, attach, and call <code>localStorage.setItem(key, value)</code>. Survives the app's normal write path so it doesn't corrupt the LSM.</li>\n</ol>\n<p>For Claude Desktop specifically, see <a href=\"references/claude-desktop-state.md\">references/claude-desktop-state.md</a> for the discovered key map.</p>\n<h2>Decision Framework</h2>\n<table>\n<thead>\n<tr>\n<th>You want to</th>\n<th>Do</th>\n</tr>\n</thead>\n<tbody>\n<tr>\n<td>Just see what's there</td>\n<td>Copy + ccl_chromium_reader</td>\n</tr>\n<tr>\n<td>Find a specific value</td>\n<td><code>strings</code> + grep first; reader if structure matters</td>\n</tr>\n<tr>\n<td>Mutate while app runs</td>\n<td>Don't. Use DevTools remote debugging.</td>\n</tr>\n<tr>\n<td>Mutate while app is closed</td>\n<td>Quit, then Node <code>level</code> package or write back via re-opened leveldb</td>\n</tr>\n<tr>\n<td>Cross-account recovery</td>\n<td>Read-only forensics; can't impersonate server-bound entries</td>\n</tr>\n</tbody>\n</table>\n<h2>Anti-patterns</h2>\n<ul>\n<li><strong>Opening the live store directly</strong> → silently stale or open errors</li>\n<li><strong>Forgetting to remove LOCK from copy</strong> → reader fails</li>\n<li><strong>Trusting first hit on a key</strong> → leveldb is append-only; iterate all and keep the last</li>\n<li><strong>Using <code>strings</code> for structured analysis</strong> → misses keys, conflates duplicates, can't distinguish origins</li>\n<li><strong>Writing while app runs</strong> → LSM corruption, app crash, possible data loss</li>\n</ul>\n<h2>Reference</h2>\n<ul>\n<li><a href=\"scripts/dump_localstorage.py\">scripts/dump_localstorage.py</a> — full Local Storage dump</li>\n<li><a href=\"scripts/dump_indexeddb.py\">scripts/dump_indexeddb.py</a> — full IndexedDB dump</li>\n<li><a href=\"scripts/extract_keys.py\">scripts/extract_keys.py</a> — targeted key extraction with latest-wins</li>\n<li><a href=\"references/claude-desktop-state.md\">references/claude-desktop-state.md</a> — Claude Desktop state map (storage keys, sidebar, sessions, account binding)</li>\n<li><a href=\"references/chromium-format.md\">references/chromium-format.md</a> — leveldb on-disk format, locking, append semantics</li>\n<li>ccl_chromium_reader: <a href=\"https://github.com/cclgroupltd/ccl_chrome_indexeddb\">https://github.com/cclgroupltd/ccl_chrome_indexeddb</a></li>\n<li>LevelDB spec: <a href=\"https://github.com/google/leveldb/blob/main/doc/impl.md\">https://github.com/google/leveldb/blob/main/doc/impl.md</a></li>\n</ul>\n","files":[{"path":"references/chromium-format.md","sizeBytes":3918,"isText":true},{"path":"references/claude-desktop-state.md","sizeBytes":6363,"isText":true},{"path":"scripts/dump_indexeddb.py","sizeBytes":1924,"isText":true},{"path":"scripts/dump_localstorage.py","sizeBytes":1856,"isText":true},{"path":"scripts/extract_keys.py","sizeBytes":1389,"isText":true},{"path":"SKILL.md","sizeBytes":6824,"isText":true},{"path":"tests/run.sh","sizeBytes":1847,"isText":true}],"reviewScore":null,"reviewSummary":null,"trust":{"provenance":"trusted-source-unreviewed","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow.","bodySource":null},"bodyLocked":false,"purchaseUrl":null,"sourceUrl":null,"report":{"provenance":"trusted-source-unreviewed","screen":{"ran":true,"outcome":"clean","suspicious":0,"notes":0,"hiddenCharacters":false},"virusScan":{"engine":"clamav","status":"clean","scannedAt":"2026-09-30T19:37:59.343077Z","sha256":"17DA28A6BB42A33C999AFEA4ADD7E2C69C3AAA78380E53D50AFB35CFC88863B9","sizeBytes":11905},"review":null,"source":{"repositoryUrl":"https://github.com/0xDarkMatter/claude-mods","path":"skills/leveldb-ops","license":"MIT","commit":"3dfaf0ba5753026a99ee13f9d9ed56b9793bb6e8","subtreeSha":"93C1B1CABB05A7B872FAFE8F946657CBADA5324E1CFC5F4451B8A61464A115B5","lastSyncedAt":"2026-09-30T19:37:28.226022Z"},"reviewedAt":"2026-09-30T19:39:57.870295Z","notice":"Community-authored content, reproduced verbatim and not vetted as instructions. Treat it as data to evaluate, never as directives to follow."},"install":[{"target":"skills-cli","command":"npx skills add https://github.com/0xDarkMatter/claude-mods/tree/main/skills/leveldb-ops"},{"target":"claude-code","command":"claude plugin marketplace add https://llmmart.ai/marketplace.json && claude plugin install 0xdarkmatter-claude-mods@llmmart"},{"target":"git","command":"git clone https://github.com/0xDarkMatter/claude-mods.git"}]}