Claudefeed — Security skill for Claude Code
Live audit log of every command, file, and network connection a Claude Code (or any matched) session makes, from the kernel.
How to install Claudefeed
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open yeet-src/claudefeed and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Claudefeed does
Live audit log of every command, file, and network connection a Claude Code (or any matched) session makes, from the kernel.
Alternatives in Security
- Audit Live Site — audit-live-site 1k ★
- Agentseal — Security toolkit for AI agents 344 ★
- Postgres — Execute safe read-only SQL queries against PostgreSQL databases with multi-connection support and defense-in-d 159 ★
README
`claudefeed`
**`tail -f` for a coding agent.** What it ran, what it opened, what it dialed. From the kernel, not from its own log.
**`claudefeed` is an eBPF agent audit feed for Linux: it streams every command, file open and TCP connection a coding-agent session makes, scoped to that session's process subtree.**
Quick start
curl -fsSL https://yeet.cx | sh # install yeet, once
yeet run github:yeet-src/claudefeed # clone, build and run in one step
With an agent session running anywhere on the box, that is all of it. `claudefeed` finds the live `claude` processes, seeds its tracked set, and starts streaming.
The incumbents each solve a slice and miss the rest. `strace -f` needs a PID you name up front, and a session is a moving tree: the agent spawns a shell, the shell spawns `git`, `git` spawns `ssh`. Auditd catches the tree but hands you a system-wide log to filter afterwards. The agent's own transcript tells you what it believed it did,
Related Skills
Jgs Magic Sysmlv1 MCP
Bring Claude Code and any MCP agent to your live SysML v1 models in CATIA Magic: 130+ tools to query, audit, a
Aegis Activity Logger
Append-only JSONL audit log of every Edit/Write/Bash mutation, one file per UTC day. Provides historical repla
Traceary
Local-first session log and audit trail for AI coding agents (Claude Code, Codex, Gemini)
Audit Tokens
Analyze audit-log.jsonl for ghost-token-waste patterns across the 6 PLAN-047 detectors. Emits a markdown repor
Cost Autopsy
Session token-burn autopsy (TCO v1). Reads the TIS telemetry log and reports per-session token spend (input /
Sanctuary Framework
Open-source security for AI agents: kernel-enforced egress control on macOS and Linux, keys only the operator
Related Agents
Calendar Audit
Use this agent to review calendar events, log what happened, and handle rescheduling. Can run daily or cover m
Sap Basis Consultant
SAP Basis 장애 상황을 체계적으로 라우팅하고 진단하는 한국어 전문 에이전트. ABAP 덤프(ST22), Work Process 행(SM50/SM66), Transport 실패(STMS), R
Docker Log Analyser
MUST BE USED PROACTIVELY for any Docker or container log analysis. Extracts only error lines, never dumps full