Skip to content

chore: add nucleus security scan for Claude settings#5

Merged
brandon-coproduct merged 1 commit intomasterfrom
add-nucleus-scan
Mar 7, 2026
Merged

chore: add nucleus security scan for Claude settings#5
brandon-coproduct merged 1 commit intomasterfrom
add-nucleus-scan

Conversation

@brandon-coproduct
Copy link

Test run of nucleus scan action on fork

Adds `.claude/settings.json` with restrictive permissions:
- Read-only access + python/pip/pytest/git commands allowed
- Exfiltration commands denied (curl, wget, nc, ssh, scp)
- Sensitive paths denied (.env, credentials, secrets)
- Write/edit/commit require approval

Adds `nucleus-scan.yml` workflow that scans the Claude settings
on every PR that modifies agent config files.

Generated with [Claude Code](https://claude.ai/code)
via [Happy](https://happy.engineering)

Co-Authored-By: Claude <noreply@anthropic.com>
Co-Authored-By: Happy <yesreply@happy.engineering>
@brandon-coproduct brandon-coproduct merged commit d7455a8 into master Mar 7, 2026
22 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant