BlogBLOCK
Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.
Overview
Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.
7e3c9718babeOBSERVED · 2026-10-08Install
Commands as the repository documents them. They are shown, not run.
npm install -g @anthropic-ai/claude-code
npm install -g @anthropic-ai/claude-code &&
uv self update
uv python install 3.14
uv self update
uv python install 3.14
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned | |
| claude-desktop | mentioned | |
| codex | mentioned | |
| copilot | mentioned | |
| cursor | mentioned | |
| openclaw | mentioned |
Trust audit
BLOCKgrade D · trust 66/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | WARN |
| L1 | Static analysis of the code | FAIL |
| L2 | Instruction surface (what it tells the agent) | FAIL |
| L3 | Class-specific surface | WARN |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (25)
"curl -fsSL https://raw.githubusercontent.com/maxritter/pilot-shell/main/uninstall.sh | bash"
The safeguard mechanism is worth understanding precisely, because it changes how the model behaves in practice. Fable 5 does not refuse flagged requests. Instead, a separate set of AI classifiers watc
Access is settled too. On **June 12, 2026**, a US government export-control directive forced Anthropic to disable Fable 5 and Mythos 5 for all customers, on subscriptions and on the API alike. Those c
The hardening numbers are meaningful. An external bug bounty found **no universal jailbreaks in over 1,000 hours** of testing. One external partner found Fable 5's cyber safeguards the strongest of an
Two details are worth carrying forward. The June suspension traced to a non-universal jailbreak, essentially asking the model to read a codebase and patch software flaws, and Anthropic shipped a new c
Fable 5 was **disabled worldwide on June 12, 2026** under a US export-control directive that required blocking all foreign nationals, which Anthropic could not verify in real time. Access was **restor
LicenseRoutes.ts
LicenseBadge.tsx
LicenseGate.tsx
license-recovery-worker.test.ts
license-routes.test.ts
**`allowUnixSockets`**: Controls Unix socket access. Be careful: allowing `/var/run/docker.sock` effectively grants host system access through the Docker socket, bypassing sandbox isolation.
The `allowUnixSockets` setting can inadvertently grant powerful access. Allowing `/var/run/docker.sock` gives the sandboxed process full Docker API access, which effectively means host system access.
Running an AI agent with unrestricted access to your filesystem and network is a liability you can't afford to ignore. Every `npm install` pulls untrusted code. Every build script executes with your u
Three isolated sessions, three branches, zero conflicts. Each session has full access to your codebase history but operates on completely separate file trees.
Desktop scheduled tasks are the primary way to automate recurring work in Claude Code. They run locally on your machine, each firing a fresh session at the time and frequency you choose. Every run has
Send "add the --coverage flag to the test script in package.json" from Telegram. Claude reads the message, makes the change, and replies in your chat. Your session keeps running locally with full acce
| **Local tools** | Full access (filesystem, MCP, git) | Full access (filesystem, MCP, git) | Cloud sandbox only |
Start with a fresh Ubuntu server. Most providers give you root access via password. Your first job is making it secure.
Setup hooks also have access to `CLAUDE_ENV_FILE` for persisting environment variables.
Running an AI agent with unrestricted access to your filesystem and network is a liability you can't afford to ignore. Every `npm install` pulls untrusted code. Every build script executes with your u
- Security policies (deny access to credentials, block destructive commands)
- Global permission rules (like always denying access to `~/.ssh`)
curl -fsSL https://claude.ai/install.sh | bash # macOS/Linux
Gates applied: instruction_override, no_behavioural_pass.
7e3c9718babefull audit observations/trust-audit/skill/maxritter__blog.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-08 | 7e3c9718babe | BLOCK | D | 66 | first audit |
Questions
What does the Blog skill do?
Professional context and harness engineering for Claude Code and OpenAI Codex. Build production-grade software with spec-driven development, TDD, persistent memory, quality gates, code intelligence, human oversight, and end-to-end verification.
Is Blog safe to install?
No — not without reading the findings first. The audit graded it D (66/100) and found 6 critical or high issues in the source. Each one is listed on this page with the file and line it is on.
What can Blog access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Blog work with?
Its documentation mentions claude-code, claude-desktop, codex, copilot, cursor and openclaw. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (7e3c9718babe), read on 2026-10-08. The repository is watched, and a new audit runs when it changes — this is the first audit.