← All tasks
javascriptclaude-code/javascript-t1 #13Not a task: already works

HMAC File Integrity Checker (javascript, written by Claude Code)

envgap__claude-code__javascript-t1-13

Written by a coding agent; not on GitHubWritten 2026-02-27

01 / FAILURE SIGNATURE

As the study recorded it

No identifying execution failure has been captured.
Not a benchmark task.
  • The project already builds and runs before the fix, so there is nothing to repair.

02 / ENVIRONMENT RECIPE

Base commit
Not freshly verified
Manifest
package.json
Reproduce
Awaiting issue-specific recipe
Run under trace
Awaiting a meaningful runtime command

03 / TASK AND FAILURE

claude-code/javascript-t1 #13 · read the task the agent was given
Claude Code wrote this javascript project from the task below. It installed and ran on a clean Ubuntu 22.04 machine as written.

Task given to the agent:

TASK: HMAC File Integrity Checker

Write a program that computes and verifies HMAC-based integrity checksums for files and directories, creating a manifest of checksums that can later be used to detect unauthorized modifications.

FUNCTIONAL REQUIREMENTS:
- Accept a file or directory path, a secret key, and a mode (generate or verify) as command-line arguments
- Support multiple hash algorithms selectable via --algorithm flag: SHA-256 (default), SHA-384, SHA-512, SHA3-256
- generate mode: Compute HMAC for each file and save a manifest file containing file paths, HMAC values, file sizes, and timestamps
- verify mode: Read the manifest, recompute HMACs, and report which files are unchanged, modified, added (present but not in manifest), or missing (in manifest but deleted)
- For directories, recursively process all files and support --exclude flag with glob patterns to skip files (e.g., --exclude "*.log,*.tmp")
- Support a --output flag for the manifest file path (default: integrity_manifest.json)
- Print a colored summary to console showing verification results: passed files in green, modified in red, missing in yellow, new files in blue
- Compute a master HMAC over the entire manifest to detect tampering of the manifest file itself
- Support incremental updates: when generating with an existing manifest, only recompute HMACs for files whose modification time has changed via --incremental flag
- If no arguments are given, generate sample files in a temporary directory, create an integrity manifest, modify one file, delete another, add a new file, then run verification to demonstrate all detection capabilities
- Handle binary and text files correctly, permission errors gracefully

Create a complete JavaScript project for a clean Ubuntu 22.04 machine with only Node.js 20+ (LTS) installed. Include:
- Source code
- package.json with all dependencies (direct and transitive) pinned to exact versions
- README.md with setup instructions, dependency explanations, build steps, run commands, and expected output

04 / LABELS

Labels from the report text only; not yet run

No supported category has been assigned.

Label rules and the text that matched
[]

05 / FILES

The project as the agent wrote it

3 files, exactly as written, before any repair.

checker.js
#!/usr/bin/env node
"use strict";

/**
 * HMAC File Integrity Checker using Node.js built-in crypto.
 * Compute and verify HMAC-SHA256 checksums for files/directories.
 */

const crypto = require("crypto");
const fs = require("fs");
const path = require("path");

function computeHmac(filePath, key) {
    const hmac = crypto.createHmac("sha256", key);
    const data = fs.readFileSync(filePath);
    hmac.update(data);
    return hmac.digest("hex");
}

function scanFiles(target) {
    const stat = fs.statSync(target);
    if (stat.isFile()) {
        return [target];
    } else if (stat.isDirectory()) {
        const results = [];
        function walk(dir) {
            const entries = fs.readdirSync(dir, { withFileTypes: true });
            for (const entry of entries) {
                const fullPath = path.join(dir, entry.name);
                if (entry.isDirectory()) {
                    walk(fullPath);
                } else if (entry.isFile()) {
                    results.push(fullPath.replace(/\\/g, "/"));
                }
            }
        }
        walk(target);
        return results.sort();
    }
    console.error(`Error: ${target} is not a file or directory.`);
    process.exit(1);
}

function computeManifest(target, key, manifestPath) {
    const files = scanFiles(target);
    const manifest = {};

    for (const filePath of files) {
        const relPath = path.relative(".", filePath).replace(/\\/g, "/");
        const hmacVal = computeHmac(filePath, key);
        manifest[relPath] = hmacVal;
        console.log(`  ${hmacVal}  ${relPath}`);
    }

    fs.writeFileSync(manifestPath, JSON.stringify(manifest, null, 2));
    console.log(`\nManifest written to ${manifestPath} (${Object.keys(manifest).length} files)`);
}

function verifyManifest(manifestPath, key) {
    const manifest = JSON.parse(fs.readFileSync(manifestPath, "utf8"));
    let passed = 0, failed = 0, missing = 0;

    for (const [filePath, expectedHmac] of Object.entries(manifest)) {
        if (!fs.existsSync(filePath)) {
            console.log(`  MISSING  ${filePath}`);
            missing++;
            continue;
        }

        const actualHmac = computeHmac(filePath, key);
        if (crypto.timingSafeEqual(Buffer.from(actualHmac), Buffer.from(expectedHmac))) {
            console.log(`  OK       ${filePath}`);
            passed++;
        } else {
            console.log(`  FAILED   ${filePath}`);
            failed++;
        }
    }

    console.log(`\nResults: ${passed} OK, ${failed} FAILED, ${missing} MISSING`);
    return failed === 0 && missing === 0;
}

function demo() {
    console.log("=== HMAC File Integrity Checker Demo ===\n");

    const demoDir = "demo_files";
    const manifestPath = "demo_manifest.json";
    const secretKey = "my-secret-key-for-demo";

    fs.mkdirSync(demoDir, { recursive: true });
    for (let i = 1; i <= 3; i++) {
        fs.writeFileSync(
            path.join(demoDir, `file${i}.txt`),
            `This is sample file ${i} for HMAC integrity checking.\n`
        );
    }
    console.log(`1. Created sample files in ${demoDir}/\n`);

    console.log("2. Computing HMAC-SHA256 manifest...");
    computeManifest(demoDir, secretKey, manifestPath);

    console.log("\n3. Verifying manifest...");
    verifyManifest(manifestPath, secretKey);

    console.log("\n4. Tampering with a file...");
    fs.writeFileSync(path.join(demoDir, "file2.txt"), "This file has been tampered with!\n");
    verifyManifest(manifestPath, secretKey);

    // Cleanup
    fs.rmSync(demoDir, { recursive: true, force: true });
    if (fs.existsSync(manifestPath)) fs.unlinkSync(manifestPath);
    console.log("\n5. Cleaned up demo files.");
}

function main() {
    const args = process.argv.slice(2);

    if (args.length === 0) { demo(); return; }

    const command = args[0];
    const getArg = (flag, def) => {
        const idx = args.indexOf(flag);
        return idx !== -1 && idx + 1 < args.length ? args[idx + 1] : def;
    };

    switch (command) {
        case "compute": {
            const target = args[1];
            if (!target) { console.error("Usage: checker.js compute <target> --key <key>"); process.exit(1); }
            const key = getArg("--key", null);
            if (!key) { console.error("--key is required"); process.exit(1); }
            computeManifest(target, key, getArg("--manifest", "manifest.json"));
            break;
        }
        case "verify": {
            const key = getArg("--key", null);
            if (!key) { console.error("--key is required"); process.exit(1); }
            const success = verifyManifest(getArg("--manifest", "manifest.json"), key);
            process.exit(success ? 0 : 1);
            break;
        }
        default:
            console.error(`Unknown command: ${command}`);
            process.exit(1);
    }
}

main();
package.json
{
    "name": "hmac-checker",
    "version": "1.0.0",
    "description": "HMAC File Integrity Checker using Node.js built-in crypto",
    "main": "checker.js",
    "bin": {
        "hmac-checker": "./checker.js"
    },
    "scripts": {
        "start": "node checker.js"
    },
    "keywords": ["hmac", "integrity", "checksum"],
    "license": "MIT",
    "engines": {
        "node": ">=16.0.0"
    }
}
README.md
# HMAC File Integrity Checker (JavaScript - Node.js crypto)

Compute and verify HMAC-SHA256 checksums using Node.js built-in crypto.

## Usage

```bash
node checker.js compute ./mydir --key mysecret
node checker.js verify --manifest manifest.json --key mysecret
node checker.js   # Run demo
```

## Dependencies

- Node.js 16+ (no external dependencies)