HMAC File Integrity Checker (javascript, written by Claude Code)
envgap__claude-code__javascript-t1-13
Written by a coding agent; not on GitHubWritten 2026-02-27
01 / FAILURE SIGNATURE
As the study recorded it
No identifying execution failure has been captured.
Not a benchmark task.
- The project already builds and runs before the fix, so there is nothing to repair.
02 / ENVIRONMENT RECIPE
- Base commit
Not freshly verified- Manifest
package.json- Reproduce
Awaiting issue-specific recipe- Run under trace
Awaiting a meaningful runtime command
03 / TASK AND FAILURE
claude-code/javascript-t1 #13 · read the task the agent was given
Claude Code wrote this javascript project from the task below. It installed and ran on a clean Ubuntu 22.04 machine as written. Task given to the agent: TASK: HMAC File Integrity Checker Write a program that computes and verifies HMAC-based integrity checksums for files and directories, creating a manifest of checksums that can later be used to detect unauthorized modifications. FUNCTIONAL REQUIREMENTS: - Accept a file or directory path, a secret key, and a mode (generate or verify) as command-line arguments - Support multiple hash algorithms selectable via --algorithm flag: SHA-256 (default), SHA-384, SHA-512, SHA3-256 - generate mode: Compute HMAC for each file and save a manifest file containing file paths, HMAC values, file sizes, and timestamps - verify mode: Read the manifest, recompute HMACs, and report which files are unchanged, modified, added (present but not in manifest), or missing (in manifest but deleted) - For directories, recursively process all files and support --exclude flag with glob patterns to skip files (e.g., --exclude "*.log,*.tmp") - Support a --output flag for the manifest file path (default: integrity_manifest.json) - Print a colored summary to console showing verification results: passed files in green, modified in red, missing in yellow, new files in blue - Compute a master HMAC over the entire manifest to detect tampering of the manifest file itself - Support incremental updates: when generating with an existing manifest, only recompute HMACs for files whose modification time has changed via --incremental flag - If no arguments are given, generate sample files in a temporary directory, create an integrity manifest, modify one file, delete another, add a new file, then run verification to demonstrate all detection capabilities - Handle binary and text files correctly, permission errors gracefully Create a complete JavaScript project for a clean Ubuntu 22.04 machine with only Node.js 20+ (LTS) installed. Include: - Source code - package.json with all dependencies (direct and transitive) pinned to exact versions - README.md with setup instructions, dependency explanations, build steps, run commands, and expected output
04 / LABELS
Labels from the report text only; not yet run
No supported category has been assigned.
Label rules and the text that matched
[]
05 / FILES
The project as the agent wrote it
3 files, exactly as written, before any repair.
checker.js
#!/usr/bin/env node
"use strict";
/**
* HMAC File Integrity Checker using Node.js built-in crypto.
* Compute and verify HMAC-SHA256 checksums for files/directories.
*/
const crypto = require("crypto");
const fs = require("fs");
const path = require("path");
function computeHmac(filePath, key) {
const hmac = crypto.createHmac("sha256", key);
const data = fs.readFileSync(filePath);
hmac.update(data);
return hmac.digest("hex");
}
function scanFiles(target) {
const stat = fs.statSync(target);
if (stat.isFile()) {
return [target];
} else if (stat.isDirectory()) {
const results = [];
function walk(dir) {
const entries = fs.readdirSync(dir, { withFileTypes: true });
for (const entry of entries) {
const fullPath = path.join(dir, entry.name);
if (entry.isDirectory()) {
walk(fullPath);
} else if (entry.isFile()) {
results.push(fullPath.replace(/\\/g, "/"));
}
}
}
walk(target);
return results.sort();
}
console.error(`Error: ${target} is not a file or directory.`);
process.exit(1);
}
function computeManifest(target, key, manifestPath) {
const files = scanFiles(target);
const manifest = {};
for (const filePath of files) {
const relPath = path.relative(".", filePath).replace(/\\/g, "/");
const hmacVal = computeHmac(filePath, key);
manifest[relPath] = hmacVal;
console.log(` ${hmacVal} ${relPath}`);
}
fs.writeFileSync(manifestPath, JSON.stringify(manifest, null, 2));
console.log(`\nManifest written to ${manifestPath} (${Object.keys(manifest).length} files)`);
}
function verifyManifest(manifestPath, key) {
const manifest = JSON.parse(fs.readFileSync(manifestPath, "utf8"));
let passed = 0, failed = 0, missing = 0;
for (const [filePath, expectedHmac] of Object.entries(manifest)) {
if (!fs.existsSync(filePath)) {
console.log(` MISSING ${filePath}`);
missing++;
continue;
}
const actualHmac = computeHmac(filePath, key);
if (crypto.timingSafeEqual(Buffer.from(actualHmac), Buffer.from(expectedHmac))) {
console.log(` OK ${filePath}`);
passed++;
} else {
console.log(` FAILED ${filePath}`);
failed++;
}
}
console.log(`\nResults: ${passed} OK, ${failed} FAILED, ${missing} MISSING`);
return failed === 0 && missing === 0;
}
function demo() {
console.log("=== HMAC File Integrity Checker Demo ===\n");
const demoDir = "demo_files";
const manifestPath = "demo_manifest.json";
const secretKey = "my-secret-key-for-demo";
fs.mkdirSync(demoDir, { recursive: true });
for (let i = 1; i <= 3; i++) {
fs.writeFileSync(
path.join(demoDir, `file${i}.txt`),
`This is sample file ${i} for HMAC integrity checking.\n`
);
}
console.log(`1. Created sample files in ${demoDir}/\n`);
console.log("2. Computing HMAC-SHA256 manifest...");
computeManifest(demoDir, secretKey, manifestPath);
console.log("\n3. Verifying manifest...");
verifyManifest(manifestPath, secretKey);
console.log("\n4. Tampering with a file...");
fs.writeFileSync(path.join(demoDir, "file2.txt"), "This file has been tampered with!\n");
verifyManifest(manifestPath, secretKey);
// Cleanup
fs.rmSync(demoDir, { recursive: true, force: true });
if (fs.existsSync(manifestPath)) fs.unlinkSync(manifestPath);
console.log("\n5. Cleaned up demo files.");
}
function main() {
const args = process.argv.slice(2);
if (args.length === 0) { demo(); return; }
const command = args[0];
const getArg = (flag, def) => {
const idx = args.indexOf(flag);
return idx !== -1 && idx + 1 < args.length ? args[idx + 1] : def;
};
switch (command) {
case "compute": {
const target = args[1];
if (!target) { console.error("Usage: checker.js compute <target> --key <key>"); process.exit(1); }
const key = getArg("--key", null);
if (!key) { console.error("--key is required"); process.exit(1); }
computeManifest(target, key, getArg("--manifest", "manifest.json"));
break;
}
case "verify": {
const key = getArg("--key", null);
if (!key) { console.error("--key is required"); process.exit(1); }
const success = verifyManifest(getArg("--manifest", "manifest.json"), key);
process.exit(success ? 0 : 1);
break;
}
default:
console.error(`Unknown command: ${command}`);
process.exit(1);
}
}
main();
package.json
{
"name": "hmac-checker",
"version": "1.0.0",
"description": "HMAC File Integrity Checker using Node.js built-in crypto",
"main": "checker.js",
"bin": {
"hmac-checker": "./checker.js"
},
"scripts": {
"start": "node checker.js"
},
"keywords": ["hmac", "integrity", "checksum"],
"license": "MIT",
"engines": {
"node": ">=16.0.0"
}
}
README.md
# HMAC File Integrity Checker (JavaScript - Node.js crypto) Compute and verify HMAC-SHA256 checksums using Node.js built-in crypto. ## Usage ```bash node checker.js compute ./mydir --key mysecret node checker.js verify --manifest manifest.json --key mysecret node checker.js # Run demo ``` ## Dependencies - Node.js 16+ (no external dependencies)