enterprise-security
Pass
Audited by Gen Agent Trust Hub on Mar 21, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: Provides multiple Bash scripts for security monitoring and enforcement, such as the 'audit-trail.sh' script which logs tool usage to /var/log/claude-code/.
- [COMMAND_EXECUTION]: Utilizes the
jqutility to parse and process agent tool inputs and outputs within security enforcement hooks. - [COMMAND_EXECUTION]: Includes scripts for system-level configuration, such as 'setup-audit-log-rotation.sh' which writes logrotate configurations to /etc/logrotate.d/.
- [EXTERNAL_DOWNLOADS]: Contains patterns for retrieving credentials from external services like HashiCorp Vault and AWS Secrets Manager using
curlandawsCLI tools. - [COMMAND_EXECUTION]: Features Git pre-commit hooks designed to scan and prevent the submission of potential secrets in repository history.
Audit Metadata