claude-code
Pass
Audited by Gen Agent Trust Hub on Apr 11, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill is a legitimate collection of markdown documentation files designed to help users and AI agents understand and operate the 'Claude Code' tool. All instructions are informational and follow standard developer workflows.
- [COMMAND_EXECUTION]: The documentation contains numerous examples of shell commands for installation (npm, pip), git operations, testing, and debugging. These are presented as educational examples and troubleshooting steps for the user.
- [EXTERNAL_DOWNLOADS]: References official Anthropic resources (GitHub repositories, documentation) and well-known registries for tool installation. It also includes an external documentation service for LLM-optimized context, which is used neutrally for information retrieval.
- [DATA_EXFILTRATION]: Correctly identifies security risks associated with credential management, instructing users to use environment variables and gitignored '.env' files rather than hardcoding secrets in version control.
- [REMOTE_CODE_EXECUTION]: Describes the tool's built-in capability to install plugins from remote sources (GitHub, NPM, URLs) as a feature of the assistant, while providing guidance on auditing these components before installation.
Audit Metadata