yeet-src

Claudefeed — Security skill for Claude Code

Security community

Live audit log of every command, file, and network connection a Claude Code (or any matched) session makes, from the kernel.

How to install Claudefeed

This entry records only its repository, not the path inside it, so there is no exact command to give. Open yeet-src/claudefeed and copy the folder into ~/.claude/skills/, or the file into ~/.claude/agents/.

What Claudefeed does

Live audit log of every command, file, and network connection a Claude Code (or any matched) session makes, from the kernel.

Alternatives in Security

  • Audit Live Site — audit-live-site 1k ★
  • Agentseal — Security toolkit for AI agents 344 ★
  • Postgres — Execute safe read-only SQL queries against PostgreSQL databases with multi-connection support and defense-in-d 159 ★

README

`claudefeed`

**`tail -f` for a coding agent.** What it ran, what it opened, what it dialed. From the kernel, not from its own log.

Linux: kernel with BTF, tracepoints and kprobes Built with yeet, a JS runtime for eBPF Observes and records; does not block GPL-2.0 Discord

claudefeed streaming exec, open, conn and listen events from a live Claude Code session

**`claudefeed` is an eBPF agent audit feed for Linux: it streams every command, file open and TCP connection a coding-agent session makes, scoped to that session's process subtree.**

Quick start

curl -fsSL https://yeet.cx | sh          # install yeet, once
yeet run github:yeet-src/claudefeed      # clone, build and run in one step

With an agent session running anywhere on the box, that is all of it. `claudefeed` finds the live `claude` processes, seeds its tracked set, and starts streaming.

The incumbents each solve a slice and miss the rest. `strace -f` needs a PID you name up front, and a session is a moving tree: the agent spawns a shell, the shell spawns `git`, `git` spawns `ssh`. Auditd catches the tree but hands you a system-wide log to filter afterwards. The agent's own transcript tells you what it believed it did,