claude-code-sdk
Pass
Audited by Gen Agent Trust Hub on Sep 19, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's Dockerfile implementation example includes a command to download and execute a Node.js installation script from NodeSource (
https://deb.nodesource.com/setup_20.x | bash). This is a standard and widely used procedure for setting up Node.js environments in Linux containers. - [EXTERNAL_DOWNLOADS]: The skill instructions fetch official packages and setup scripts from well-known services, including NodeSource for Node.js runtimes and the official Anthropic Claude Code SDK from standard package registries.
- [CREDENTIALS_UNSAFE]: The provided code examples include functions that check for the existence of authentication tokens in the
~/.claude/directory andANTHROPIC_API_KEYenvironment variables. These are standard procedures for the Claude Code SDK to determine authentication status and do not involve insecure hardcoding or exfiltration of secrets.
Audit Metadata