How to audit what Claude Code does
Claude Code exposes lifecycle hooks (PreToolUse, PostToolUse, Stop). Install Scopebond's hook with npx @scopebond/hook@latest init; every tool call — a shell command, a file edit, a git push, an MCP call — is mapped to a normalized action and written to a signed local receipt. scopebond-hook log shows recent decisions and scopebond-hook verify checks them offline. Records carry the action, the deciding rule and cryptographic fingerprints — never file contents or prompts.
On Windows, type npx.cmd instead of npx in PowerShell: its default script policy blocks npx, and npx.cmd works in PowerShell and Command Prompt alike.
1. Install the hook
One command scaffolds a signing key and a starter policy and wires the PreToolUse hook into Claude Code:
npx @scopebond/hook@latest init # or: npm i -g @scopebond/hook@latest && scopebond install
2. Work as usual, then read the record
Every decision is recorded locally. Look at what happened and check it cryptographically, with no network and no account:
scopebond-hook log # recent decisions
scopebond-hook verify # every receipt verifies offline
scopebond-hook test "rm -rf /" # see a decision without running anything
3. What's in a record
- The normalized action (for example
shell.exec,git.push,file.write). - The rule that decided it and whether it was allowed or blocked.
- Cryptographic fingerprints of the inputs — never the file contents, the prompt, or secrets (secrets are scrubbed before anything is signed).
What this does not do
The hook checks actions Claude Code sends through its own tool system. A process a person starts outside the agent is not covered, and a valid signature proves what the signer recorded — it does not by itself prove an outside result or compliance. For money or system actions that must always be checked, put the gateway in front of the tool.
Alternatives
- Claude Code's own settings and Compliance API — native managed settings and audit export; Scopebond adds an offline-verifiable signed record and cross-vendor policy.
- Hand-written PreToolUse hooks — full control, but you maintain the shell parsing and the record format yourself.
FAQ
Does Scopebond see my code or my prompts?
No. It checks the action an agent tries to take against your rules, not the content it is working on. Records carry identifiers and fingerprints, never file contents or prompts, and secrets are scrubbed before anything is written.
Does the record verify without Scopebond?
Yes. Each receipt is an Ed25519-signed scopebond:receipt; scopebond-hook verify (or npx @scopebond/verify@latest) checks it offline against the signer's public key, with no account and no network.
Is this production-ready?
Scopebond is in early access, with paid plans live. The open-source hook enforces your rules on the actions routed through it today; roll it out to one team or project first, then widen it.
Last verified 2026-09-22. Commands are covered by the public repo's tests (packages/hook/test/cli.test.mjs).