claude-code-sdk

Pass

Audited by Gen Agent Trust Hub on Sep 19, 2026

Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill's Dockerfile implementation example includes a command to download and execute a Node.js installation script from NodeSource (https://deb.nodesource.com/setup_20.x | bash). This is a standard and widely used procedure for setting up Node.js environments in Linux containers.
  • [EXTERNAL_DOWNLOADS]: The skill instructions fetch official packages and setup scripts from well-known services, including NodeSource for Node.js runtimes and the official Anthropic Claude Code SDK from standard package registries.
  • [CREDENTIALS_UNSAFE]: The provided code examples include functions that check for the existence of authentication tokens in the ~/.claude/ directory and ANTHROPIC_API_KEY environment variables. These are standard procedures for the Claude Code SDK to determine authentication status and do not involve insecure hardcoding or exfiltration of secrets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 19, 2026, 07:58 AM
Security Audit — agent-trust-hub — claude-code-sdk