Atlas / Skills / oboard / Claude Api

Claude ApiSAFE

skills/oboard/claude-api

Runnable ClaudeCode source code

Verdict
SAFE
Grade
B
Trust score
89 /100
Version
—
Hosts
1 documented
License
—
Stars
3,313
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

Use the Python Agent SDK when you want Claude Code's agent loop, tools, hooks, and session handling from Python instead of calling the Messages API directly.

Install

pip install claude-agent-sdk

The SDK talks to a local Claude Code CLI, so the machine running your Python code also needs Claude Code installed and authenticated.

Choose the right entrypoint

  • query(...): one-off tasks. Each call starts a fresh session.
  • ClaudeSDKClient(...): multi-turn or long-lived conversations. Reuses session state and supports interrupts.

Minimal query() example

import asyncio
from claude_agent_sdk import query, ClaudeAgentOptions


async def main() -> None:
async for message in query(
prompt="Review the repository and suggest the safest fix.",
options=ClaudeAgentOptions(
cwd=".",
permission_mode="default",
),
):
print(message)


asyncio.run(main())

Minimal client example

import asyncio
from claude_agent_sdk import ClaudeSDKClient, ClaudeAgentOptions


async def main() -> None:
client = ClaudeSDKClient(
options=ClaudeAgentOptions(cwd=".")
)
await client.connect()
try:
await client.query("Summarize the current branch status.")
await client.query("Now suggest the next test to run.")
finally:
await client.close()


asyncio.run(main())

Practical notes

  • Prefer query() for scripts, cron jobs, and single task execution.
  • Prefer ClaudeSDKClient when later prompts depend on earlier tool results.
  • Pass cwd, permission settings, allowed tools, hooks, and custom tools through ClaudeAgentOptions.
  • For incremental output, enable partial message streaming and handle StreamEvent messages.
  • For raw model calls without Claude Code tools, use the Anthropic Python SDK instead of the Agent SDK.

Official references

  • Agent SDK quickstart: `https://platform.claude.com/docs/en/age
Read from source at commit 1667a2c1c2d7OBSERVED · 2026-10-07
02

Install

Commands as the repository documents them. They are shown, not run.

pip install claude-agent-sdk
pip install anthropic
pip install anthropic[aiohttp]
pip install anthropic[bedrock]
pip install anthropic[vertex]
npm install @anthropic-ai/claude-agent-sdk
03

Host compatibility

What the documentation claims. We have not run a compatibility test.

HostStatusNotes
claude-codementioned
04

What it tells the agent

The instruction file, verbatim from the audited commit — this is the text the model reads, and the surface the audit's instruction layer examines. Quoted here so you can judge it without cloning anything.

# Claude API

Use this skill when the user is building against Anthropic APIs or SDKs, including `@anthropic-ai/sdk`, `anthropic`, or Agent SDK integrations.

## What This Skill Covers

- Messages API basics across supported languages
- Streaming responses and incremental rendering
- Prompt caching for repeated context
- Tool use and agent-style orchestration
- Batches and Files API workflows
- Model selection and error handling

## Working Rules

- Prefer Anthropic official docs and SDK idioms over generic LLM advice.
- Keep examples aligned with the user’s detected language when possible.
- Use the language-specific `README.md` for standard request flow, auth, and request shape.
- Use the shared docs for topics that cut across all SDKs, such as models, caching, tool-use concepts, and error codes.
- If the user asks for exact current model IDs, feature availability, or pricing, verify against Anthropic’s live docs before answering.

## Reading Guide

- Basic request/response flow: `{lang}/claude-api/README.md`
- Streaming output: `{lang}/claude-api/streaming.md`
- Tool use: `shared/tool-use-concepts.md` and `{lang}/claude-api/tool-use.md`
- Prompt caching: `shared/prompt-caching.md`
- Batch processing: `{lang}/claude-api/batches.md`
- File upload flows: `{lang}/claude-api/files-api.md`
- Model choice or naming: `shared/models.md`
- API and SDK failures: `shared/error-codes.md`
- Live sources for fresh answers: `shared/live-sources.md`

## Response Style

- Give production-usable examples, not pseudocode, when the user asks for implementation help.
- Call out when you are making an inference from the docs rather than repeating an explicit guarantee.
- If the user’s request depends on fast-changing details such as model names or pricing, browse Anthropic docs and cite the relevant page.
05

Trust audit

SAFEgrade B · trust 89/100 Nothing in the source contradicts what it says it does. Grade A is reserved for packages that have also passed the behavioural sandbox.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeNA
L2Instruction surface (what it tells the agent)PASS
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
none-observed
Network
none-observed
Shell
none-observed
Dependencies
pinned
Secrets in source
none-found

Findings (3)

LOWInventory / provenance · inv.no_license · CWE-1104
Why it matters. no LICENSE file and no repo licence
Fix. add a licence
LOWPrompt injection · prompt.read_system · CWE-94, CWE-1427
csharp/claude-api.md:65
- For structured output, keep your instructions explicit and validate the JSON after receipt.
LOWInventory / provenance · skill.no_frontmatter · CWE-1104
SKILL.md:1
Why it matters. SKILL.md lacks name/description frontmatter

Gates applied: no_behavioural_pass, no_license.

Audited 2026-10-07 · audit v0.4.1 · source sha 1667a2c1c2d7full audit observations/trust-audit/skill/oboard__claude-api.json · Report an issue / request a re-scan
06

Audit history

Every audit this skill has had.

DateSourceVerdictGradeScoreChange
2026-10-071667a2c1c2d7SAFEB89first audit
07

Questions

What does the Claude Api skill do?

Runnable ClaudeCode source code

Is Claude Api safe to install?

The audit found nothing in the source that contradicts what it says it does, and graded it B (89/100). Grade A is held back for packages that have also passed a sandboxed behavioural run, which is why a clean skill reads B.

What can Claude Api access on my machine?

The audit observed no filesystem, network or shell use at all in its source.

Which assistants does Claude Api work with?

Its documentation mentions claude-code. That is what the text claims, not a compatibility test we ran.

How current is this page?

The grade is for one exact copy of the source (1667a2c1c2d7), read on 2026-10-07. The repository is watched, and a new audit runs when it changes — this is the first audit.

Advertisement