Claude ApiSAFE
Runnable ClaudeCode source code
Overview
From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.
Use the Python Agent SDK when you want Claude Code's agent loop, tools, hooks, and session handling from Python instead of calling the Messages API directly.
Install
pip install claude-agent-sdk
The SDK talks to a local Claude Code CLI, so the machine running your Python code also needs Claude Code installed and authenticated.
Choose the right entrypoint
query(...): one-off tasks. Each call starts a fresh session.ClaudeSDKClient(...): multi-turn or long-lived conversations. Reuses session state and supports interrupts.
Minimal query() example
import asyncio from claude_agent_sdk import query, ClaudeAgentOptions async def main() -> None: async for message in query( prompt="Review the repository and suggest the safest fix.", options=ClaudeAgentOptions( cwd=".", permission_mode="default", ), ): print(message) asyncio.run(main())
Minimal client example
import asyncio
from claude_agent_sdk import ClaudeSDKClient, ClaudeAgentOptions
async def main() -> None:
client = ClaudeSDKClient(
options=ClaudeAgentOptions(cwd=".")
)
await client.connect()
try:
await client.query("Summarize the current branch status.")
await client.query("Now suggest the next test to run.")
finally:
await client.close()
asyncio.run(main())Practical notes
- Prefer
query()for scripts, cron jobs, and single task execution. - Prefer
ClaudeSDKClientwhen later prompts depend on earlier tool results. - Pass
cwd, permission settings, allowed tools, hooks, and custom tools throughClaudeAgentOptions. - For incremental output, enable partial message streaming and handle
StreamEventmessages. - For raw model calls without Claude Code tools, use the Anthropic Python SDK instead of the Agent SDK.
Official references
- Agent SDK quickstart: `https://platform.claude.com/docs/en/age
1667a2c1c2d7OBSERVED · 2026-10-07Install
Commands as the repository documents them. They are shown, not run.
pip install claude-agent-sdk
pip install anthropic
pip install anthropic[aiohttp]
pip install anthropic[bedrock]
pip install anthropic[vertex]
npm install @anthropic-ai/claude-agent-sdk
Host compatibility
What the documentation claims. We have not run a compatibility test.
| Host | Status | Notes |
|---|---|---|
| claude-code | mentioned |
What it tells the agent
The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.
# Claude API
Use this skill when the user is building against Anthropic APIs or SDKs, including `@anthropic-ai/sdk`, `anthropic`, or Agent SDK integrations.
## What This Skill Covers
- Messages API basics across supported languages
- Streaming responses and incremental rendering
- Prompt caching for repeated context
- Tool use and agent-style orchestration
- Batches and Files API workflows
- Model selection and error handling
## Working Rules
- Prefer Anthropic official docs and SDK idioms over generic LLM advice.
- Keep examples aligned with the user’s detected language when possible.
- Use the language-specific `README.md` for standard request flow, auth, and request shape.
- Use the shared docs for topics that cut across all SDKs, such as models, caching, tool-use concepts, and error codes.
- If the user asks for exact current model IDs, feature availability, or pricing, verify against Anthropic’s live docs before answering.
## Reading Guide
- Basic request/response flow: `{lang}/claude-api/README.md`
- Streaming output: `{lang}/claude-api/streaming.md`
- Tool use: `shared/tool-use-concepts.md` and `{lang}/claude-api/tool-use.md`
- Prompt caching: `shared/prompt-caching.md`
- Batch processing: `{lang}/claude-api/batches.md`
- File upload flows: `{lang}/claude-api/files-api.md`
- Model choice or naming: `shared/models.md`
- API and SDK failures: `shared/error-codes.md`
- Live sources for fresh answers: `shared/live-sources.md`
## Response Style
- Give production-usable examples, not pseudocode, when the user asks for implementation help.
- Call out when you are making an inference from the docs rather than repeating an explicit guarantee.
- If the user’s request depends on fast-changing details such as model names or pricing, browse Anthropic docs and cite the relevant page.Trust audit
SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.
| Layer | What it checks | Result |
|---|---|---|
| L0 | Provenance & inventory | PASS |
| L1 | Static analysis of the code | NA |
| L2 | Instruction surface (what it tells the agent) | PASS |
| L3 | Class-specific surface | PASS |
| L4 | Behavioural (sandbox) | SKIPPED |
What the source does
- Filesystem
- none-observed
- Network
- none-observed
- Shell
- none-observed
- Dependencies
- pinned
- Secrets in source
- none-found
Findings (3)
- For structured output, keep your instructions explicit and validate the JSON after receipt.
Gates applied: no_behavioural_pass, no_license.
1667a2c1c2d7full audit observations/trust-audit/skill/oboard__claude-api.json · Report an issue / request a re-scanAudit history
Every audit this skill has had.
| Date | Source | Verdict | Grade | Score | Change |
|---|---|---|---|---|---|
| 2026-10-07 | 1667a2c1c2d7 | SAFE | B | 89 | first audit |
Questions
What does the Claude Api skill do?
Runnable ClaudeCode source code
Is Claude Api safe to install?
The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.
What can Claude Api access on my machine?
The audit observed no filesystem, network or shell use at all in its source.
Which assistants does Claude Api work with?
Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.
How current is this page?
The grade is for one exact copy of the source (1667a2c1c2d7), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.