claude-code-ops

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/validate-hooks-json.py executes git rev-parse --show-toplevel via subprocess.run to locate the repository root. This execution uses a static argument list and does not invoke a shell, following secure practices for subprocess management.
  • [COMMAND_EXECUTION]: The tests/run.sh script executes the Python validation script as part of an offline test suite to ensure configuration lints are performing correctly.
  • [EXTERNAL_DOWNLOADS]: The documentation contains numerous references and links to official resources at https://code.claude.com, https://www.anthropic.com, and https://agentskills.io. These are trusted and well-known services provided for informational purposes only.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 06:30 PM
Security Audit — agent-trust-hub — claude-code-ops