chainoftrust.dev · install-time trust report REV d7dbd9a · PINNED · RECOMPUTABLE
WarningsInspected 2026-09-05 · recomputable

anthropics/claude-code

github.com/anthropics/claude-code at d7dbd9a09f59775726ed14bbea8fc9dfdff62f7b · examined 2026-09-05 15:47 UTCServed from cache

BREAKS HERE INSTALL PATH AGENT CONFIG REGISTRY BLAST RADIUS TRUST ROOT UNAUDITABLE

The chain of trust: breaks at agent config · amber holds a warning · dashed was not established

Some of what installing this would do is worth reading before you agree to it.

The written summary was skipped for this report. The findings below are the analysis; the summary is only prose over them.
Annotations: 14 findings, 12 distinct concerns
1
WARNING · agent-config / Claude Code hook manifest

The repository ships 5 Claude Code hook manifests. A harness that indexes a cloned working tree can pick these up without any install step being run.

plugins/explanatory-output-style/hooks/hooks.json, plugins/hookify/hooks/hooks.json, plugins/learning-output-style/hooks/hooks.json, and 2 more

2
WARNING · agent-config / Claude Code plugin manifest

The repository ships 1 Claude Code plugin manifest. A harness that indexes a cloned working tree can pick these up without any install step being run.

.claude-plugin/marketplace.json

3
WARNING · agent-config / agent skill definition

The repository ships 10 agent skill definitions. A harness that indexes a cloned working tree can pick these up without any install step being run.

plugins/claude-opus-4-5-migration/skills/claude-opus-4-5-migration/SKILL.md, plugins/frontend-design/skills/frontend-design/SKILL.md, plugins/hookify/skills/writing-rules/SKILL.md, and 7 more

4
WARNING · agent-config / hooks

The hook manifest registers 1 lifecycle hook: SessionStart. Hooks run when their event fires, without the user invoking anything by name.

plugins/explanatory-output-style/hooks/hooks.json, plugins/learning-output-style/hooks/hooks.json

5
WARNING · agent-config / hooks

The hook manifest registers 4 lifecycle hooks: PostToolUse, PreToolUse, Stop, UserPromptSubmit. Hooks run when their event fires, without the user invoking anything by name.

plugins/hookify/hooks/hooks.json

6
WARNING · prose / the documentation advertises piping a downloaded script straight into a shell

The documentation advertises piping a downloaded script straight into a shell. The sentence it says that in is quoted verbatim, from README.md.

README.md

7
NOTE · agent-config / agent command or subagent definition

The repository ships 3 agent command or subagent definitions. A harness that indexes a cloned working tree can pick these up without any install step being run.

.claude/commands/commit-push-pr.md, .claude/commands/dedupe.md, .claude/commands/triage-issue.md

8
NOTE · unauditable-surface / census

83% of the repository by size (1 of 229 files) is binary or generated and cannot be reviewed by reading.

file listing at the analysed commit

9
NOTE · agent-config / hook-commands

The hook manifest runs 1 command. The first is quoted verbatim.

${CLAUDE_PLUGIN_ROOT}/hooks-handlers/session-start.sh

plugins/explanatory-output-style/hooks/hooks.json, plugins/learning-output-style/hooks/hooks.json

10
NOTE · agent-config / hook-commands

The hook manifest runs 4 commands. The first is quoted verbatim.

python3 ${CLAUDE_PLUGIN_ROOT}/hooks/pretooluse.py

plugins/hookify/hooks/hooks.json

11
NOTE · prose / the project documents data it sends somewhere

The project documents data it sends somewhere. The sentence it says that in is quoted verbatim, from README.md.

README.md

12
CLEAN · install-path / verification

The latest release publishes integrity files (SHASUMS256.txt.sig). No install script is committed to the repository, so how they are consumed depends on the instructions you follow.

release v2.1.261

13
CLEAN · trust-root / activity

The last push was 1 day ago (2026-09-04).

GitHub repository pushed_at field

14
CLEAN · trust-root / concentration

Among the 53 most active contributors, the busiest (actions-user) accounts for about 57% of commits.

GitHub contributors API, first page

Unsurveyed: declared out of scope
Hatched = not measured

Declared limits are as load-bearing as findings: this is the difference between a report and a scanner that implies completeness.

What the project says about itself
⚠ Untrusted input: nonce-fenced, rendered inert
**MacOS/Linux (Recommended):** ```bash curl -fsSL https://claude.ai/install.sh | bash ```README.md · the documentation advertises piping a downloaded script straight into a shell
When you use Claude Code, we collect feedback, which includes usage data (such as code acceptance or rejections), associated conversation data, and user feedback submitted via the `/bug` command.README.md · the project documents data it sends somewhere

Quoted verbatim from the repository at this commit, reproduced so you can weigh them. This text was treated as data, never as instructions.

Target
anthropics/claude-code
Revision
d7dbd9a
Files listed / read
229 / 5 · 0 executed
Method
read one at a time over HTTPS. Nothing cloned, extracted, installed or executed
Generated
2026-09-05 15:47:02 UTC · served from cache
Verdict
arithmetic over distinct concerns, recomputable by anyone
Formats