Rung 06 Agent SecuritySwitch rungClose
Claude Code
productType: Product (Anthropic's command-line coding agent)
Claude Code appears on this rung twice, once as the target of a fixed set of real vulnerabilities and once as the production system an attack was tested against.
Fixed vulnerabilities in project config. Check Point Research found three ways a repository's own settings could act before the user trusted it: repo-defined hooks (GHSA-ph6w-f82w-28w6, fixed in 1.0.87), auto-approved MCP servers (CVE-2025-59536, fixed in 1.0.111) and a redirected API address that leaked the user's key (CVE-2026-21852, fixed in 2.0.65). All were fixed before the write-up was published on 2026-02-25 (Caught in the Hook). See Project Config as an Attack Path.
A tool-description attack against it. ContextLeak's trained malicious tool was picked 22% of the time against Claude Code on Claude Sonnet 4.6 over 100 test cases, against 92% in simulation (ContextLeak).
This project runs Claude Code daily, with a committed .claude/settings.json that defines hooks —
which is why the rung's standing on the config attacks is did it on the posture, while none of
the attacks has been re-run here.
Mentioned In
Related Entities
- OpenClaw — the other deployed agent studied on this rung.