AI called this Suspicious at 90.0% confidence as Dangerous Capability with low false-positive risk.
Evidence for warning
- `analyze-claude-sessions` reads Claude and Cowork transcript files then submits envelopes.
- `coolhand claude` starts an HTTPS MITM proxy and forwards matched LLM request/response bodies.
- Captured headers redact common credential fields, but request/response content is uploaded.
- Uploads target `https://coolhandlabs.com/api/v2/llm_request_logs`.
Evidence against
- `package.json` has no preinstall/install/postinstall hook.
- Capture and session upload require explicit CLI commands.
- No dynamic code loading, shell execution of untrusted data, or stealth persistence found.
- Config, state, and generated CA files are stored with restrictive modes where supported.
Behavioral surface
SourceChildProcessCryptoEnvironmentVarsFilesystemNetworkShell
Supply chainHighEntropyStringsUrlStrings
ManifestNo manifest risk signals triggered.
scanned 46 file(s), 157 KB of source, external domains: 127.0.0.1, coolhandlabs.com