Skip to content
Back to skills

Claude Exec

ASecurity

Run one prompt through headless Claude with scoped permissions and a time bound. Use when: scripting or automating a `claude -p` call, even a simple one.

  • 446 stars
  • 0 votes
  • 0 copies
  • 0 views
  • Added October 5, 2026
ai-agentsgobashapi

Works with

  • claude code
  • api
  • mcp

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add boshu2/agentops --skill claude-exec --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Claude Exec?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Claude Exec
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/boshu2-claude-exec/badge)](https://www.skillsdirectory.com/skills/boshu2-claude-exec)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: claude-exec
description: 'Run one prompt through headless Claude with scoped permissions and a time bound. Use when: scripting or automating a `claude -p` call, even a simple one.'
skill_api_version: 1
user-invocable: true
hexagonal_role: driving-adapter
practices: [pragmatic-programmer, design-by-contract]
consumes: [claude-command-packet]
produces: [claude-run-output]
context_rel:
- kind: supplier-to
  with: validate
- kind: separate-ways
  with: codex-exec
context: {window: inherit, intent: {mode: none}, sections: {exclude: [HISTORY]}}
metadata:
  tier: orchestration
  dependencies: []
  capabilities: [claude_exec]
  effects: [run_claude_process, permission_tiered_workspace_effects]
  canonical_status: canonical
  disposition: keep_optional_adapter
  stability: stable
output_contract: process exit status and captured Claude output artifact
---
# Claude Exec — one-shot runtime adapter

Run one caller-supplied prompt through Claude Code print mode and capture the
result, only when the caller selects Claude: the native agent stays the
default and batches belong to `agent-native`. Flags match `claude --help` for
2.1.282; recheck it on other versions.

## Failure modes of a quick `claude -p`

1. **Inherited posture.** A bare run loads the user's settings, hooks,
   plugins, MCP servers and CLAUDE.md; a settings `bypassPermissions` default
   held even under `--safe-mode`. Use the clean flags below and set `--tools`
   and `--permission-mode` to the task's effects.
2. **Renewed time.** One bound, from the caller's remaining time: a retry
   spends it instead of renewing it. Make one attempt; any other is the
   caller's decision.
3. **Exit 0 as proof.** A denied call still exits 0 with `is_error: false`
   and "done", and a bare file name once landed in the run's scratchpad, not
   `$WORKDIR`. Name targets by path, check effects there, and leave
   acceptance to a fresh validator.
4. **Silent fallback.** With no `claude`, login or model, report and stop
   instead of switching runtimes or passing `--fallback-model`.
5. **Self-review.** Review runs as a separate session, never the author's.

## Run

Redirect the prompt from a file, or pass it as the argument with `</dev/null`,
because print mode reads stdin to EOF: a pipe left open hangs until the bound
kills it. Stock macOS lacks `timeout`: use GNU `timeout` or Homebrew's
`gtimeout`, and launch nothing without one.

```bash
TO=$(command -v timeout || command -v gtimeout) || { echo "no timeout: not launching" >&2; exit 2; }
cd "$WORKDIR" || exit 2
# Read-only: review, research, questions.
"$TO" -k 10 "$SECS" claude -p --model "$MODEL" --output-format json \
  --setting-sources "" --strict-mcp-config --disable-slash-commands \
  --tools "Read,Grep,Glob" --permission-mode dontAsk \
  <"$PROMPT_FILE" >"$OUT" 2>"$ERR"; echo "exit=$?"
# Edit-capable: authorized file changes under $WORKDIR.
"$TO" -k 10 "$SECS" claude -p --model "$MODEL" --output-format json \
  --setting-sources "" --strict-mcp-config --disable-slash-commands \
  --tools "Read,Grep,Glob,Edit,Write" --permission-mode acceptEdits \
  <"$PROMPT_FILE" >"$OUT" 2>"$ERR"; echo "exit=$?"
```

Print mode never prompts: unapproved calls are denied and listed in
`permission_denials`. Add `Bash` to `--tools` only for authorized commands
named in `--allowedTools`, e.g. `"Bash(go test *)"`; with settings hooks
dropped, that list is the guard. `--max-budget-usd` stops after the call that
crosses it, and `--help` lists no turn cap, so bound a run by time and budget.
`--no-session-persistence` keeps no transcript.

## Result

JSON carries `result`, `is_error`, `session_id`, `total_cost_usd`,
`num_turns`, `permission_denials`, and `modelUsage` keyed by the models
billed; identity evidence needs `stream-json --verbose` per the
[model-dispatch recipe](../agent-native/references/model-dispatch.md). Judge
by exit status and `is_error`: an unknown model exited 1 with
`subtype: "success"`. Exit 1 also covers a spent budget or missing input;
`timeout` gives 124, or 137 when KILL follows 10 seconds later. Keep at most
the caller's byte cap (10 MiB default), mark a cut file truncated, return
this, and stop:

```text
command: <exact argv>    posture: <tools; permission mode; clean flags>
model: <requested> -> <modelUsage keys>    exit: <status | timeout at N s>
session_id: <id | none>    output: <path, bytes, truncated: yes|no>
permission_denials: <count and tools>
```

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…