Skip to content
Rung 06 Agent SecuritySwitch rung

Claude Code

product
coding-agentanthropicagent-security

Type: Product (Anthropic's command-line coding agent)

Claude Code appears on this rung twice, once as the target of a fixed set of real vulnerabilities and once as the production system an attack was tested against.

Fixed vulnerabilities in project config. Check Point Research found three ways a repository's own settings could act before the user trusted it: repo-defined hooks (GHSA-ph6w-f82w-28w6, fixed in 1.0.87), auto-approved MCP servers (CVE-2025-59536, fixed in 1.0.111) and a redirected API address that leaked the user's key (CVE-2026-21852, fixed in 2.0.65). All were fixed before the write-up was published on 2026-02-25 (Caught in the Hook). See Project Config as an Attack Path.

A tool-description attack against it. ContextLeak's trained malicious tool was picked 22% of the time against Claude Code on Claude Sonnet 4.6 over 100 test cases, against 92% in simulation (ContextLeak).

This project runs Claude Code daily, with a committed .claude/settings.json that defines hooks — which is why the rung's standing on the config attacks is did it on the posture, while none of the attacks has been re-run here.

Mentioned In

Related Entities

  • OpenClaw — the other deployed agent studied on this rung.

Related concepts