Claude Colab — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited Claude Colab (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Give Claude Code GPU access via Google Colab.
AI coding agents can read files, run bash, and edit code — but they have zero GPU access. claude-colab bridges that gap using Colab's free T4 GPU.
Colab (T4 GPU) Your Mac / PC
┌─────────────────────────┐ ┌──────────────────────┐
│ Flask API │ │ claude-colab CLI │
│ /exec, /python, │◄── HTTPS ──────►│ or │
│ /upload, /download │ (cloudflared) │ MCP Server │
│ │ E2E encrypted │ (Claude Code tools) │
│ Bearer token + Fernet │ │ │
└─────────────────────────┘ └──────────────────────┘pip install claude-colabOpen notebooks/claude_colab_server.ipynb in Google Colab. Set runtime to T4 GPU. Run all cells. Copy the connection string.
claude-colab connect cc://TOKEN:[email protected]claude-colab status # GPU info
claude-colab exec "nvidia-smi" # Run shell commands
claude-colab python -c "import torch; print(torch.cuda.get_device_name(0))"
claude-colab upload model.py /content/model.py
claude-colab download /content/results.csv ./results.csvAdd to ~/.claude/settings.json:
{
"mcpServers": {
"claude-colab": {
"command": "claude-colab",
"args": ["mcp-serve"]
}
}
}Claude Code now has 5 GPU tools:
| Tool | What it does |
|---|---|
colab_status | GPU info, VRAM, disk, uptime |
colab_exec | Run shell commands |
colab_python | Execute Python code |
colab_upload | Upload files to Colab |
colab_download | Download files from Colab |
You: "Benchmark this model on the GPU"
Claude:
1. colab_status → Tesla T4, 15GB VRAM
2. colab_upload → sends model.py
3. colab_exec → "pip install torch transformers"
4. colab_exec → "python model.py"
5. colab_download → fetches results.jsonThe connection string contains your auth token and encryption key. Three ways to connect:
# Direct (convenient, visible in shell history)
claude-colab connect cc://TOKEN:KEY@host
# Interactive prompt (nothing in history)
claude-colab connect
# Pipe from clipboard (nothing in ps aux or history)
pbpaste | claude-colab connect -All request and response bodies are encrypted with Fernet (AES-128-CBC + HMAC-SHA256). The encryption key is generated per Colab session and is separate from the bearer token.
| Actor | Can see | Cannot see |
|---|---|---|
| Random user | Nothing (no token) | Everything |
| Cloudflare | URL paths, timing, token | Request/response bodies |
| Google (Colab) | Everything on the VM | Your local files |
~/.claude-colab.jsoncolab_exec "python train.py > output.log 2>&1"colab_exec with wget or gdown./python call runs in a fresh namespace.MIT
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.