{"repo":"yeet-src/claudefeed","free":true,"listed":false,"github":"https://github.com/yeet-src/claudefeed","clone":"git clone https://github.com/yeet-src/claudefeed.git","description":"Live audit log of every command, file, and network connection a Claude Code (or any matched) session makes, from the kernel.","language":"C","stars":13,"topics":["ai-agents","audit","bpf","ebpf","kernel","kprobe","linux","llm","observability","provenance"],"license":null,"category":"ai-agents","readme_excerpt":"claudefeed tail -f for Claude Code. Every command a session runs, every file it opens, every TCP port it reaches or binds — decoded and streamed live to your terminal. Scoped to that session's process subtree. No other PIDs, no noise. claudefeed turns a Claude Code session into a live, decoded audit log: every exec (with full argv), every openat , and every outbound or bound TCP port — for the matched session and its entire subtree. Where its sibling claudetree paints who is running as a live process tree, claudefeed is the companion that tree promised: the tail -f of what they did . [!TIP] You can't just strace this. A session is a moving tree of processes — Claude spawns a shell, the shell spawns git , git spawns ssh . A system-wide feed of every openat would be a firehose, and a per-PID trace misses every child. claudefeed filters in the kernel : a tracked set of session tgids gates the probes, the set self-propagates across exec , and the noise never crosses into userspace. Quick start Manual install guide Linux only With a Claude Code session running anywhere on the box, that's it — claudefeed finds the live claude processes, seeds its tracked set, and starts streaming. Everything after -- is passed to claudefeed: flag default meaning ------------------ -------- ---------------------------------------------------------------- --match= claude session program-name needle; matched against the exec'd basename (case-insensitive prefix) --secs= 0 run for N seconds, 0 = until C","default_branch":null,"files":null,"tree":[],"storefront":"/r/yeet-src","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/yeet-src/claudefeed/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}