Security Considerations
Claude Code has powerful capabilities: file system access, command execution, and external service integrations. You need to understand the security principles for using this power safely.
Security Architectureβ
Claude Code is designed around a permission-based architecture:
- Read-only by default: It has read-only permissions by default
- Explicit approval: File edits, command execution, and the like require user approval
- Bash sandbox: A sandbox that isolates the file system and network (enable it with
/sandbox) - Sandbox credential blocking: The
sandbox.credentialssetting blocks commands running in the sandbox from reading credential files and secret environment variables (v2.1.187+) - Scoped write access: Writes are allowed only in the starting directory and below; parent directories cannot be modified
- Prompt-fatigue prevention: Frequently used, safe commands are managed through per-user/per-project/per-organization allowlists
- Accept Edits mode: Instead of approving changes one by one, you can batch them for review/approval together
- Credential encryption: Credentials such as API keys are stored encrypted locally
Core Risk Factorsβ
1. Prompt Injectionβ
An attack where malicious instructions embedded in external data attempt to manipulate Claude's behavior.
Defense mechanisms:
- Permission system: Sensitive actions require explicit approval
- Context-aware analysis: Analyzes the full request to detect potentially harmful instructions
- Input sanitization: Input handling to prevent command injection
- Command blocklist: Commands that fetch web content, such as
curlandwget, are blocked by default - Network request approval: Tools that make network requests require approval by default
- Isolated context: WebFetch runs in a separate context window
- Command injection detection: Suspicious Bash commands require manual approval even if they're on the allowlist
- Fail-closed matching: Commands that don't match are handled as manual approval by default
Best practices:
- Review proposed commands before approving
- Don't pipe untrusted content directly into Claude
- Always confirm proposed changes to important files
- Consider using a VM when interacting with external web services
- Report suspicious behavior with
/bug
CVE-2025-59536 and CVE-2026-21852 are vulnerabilities that allow remote code execution (RCE) and API key theft through malicious project configuration files. Take extra care when cloning untrusted repositories and working on them with Claude Code. It's a good idea to first check whether the .claude/ directory or CLAUDE.md file contains anything suspicious. Always keep Claude Code up to date.
2. Excessive Permissionsβ
// Bad: allow everything
{
"permissions": {
"allow": ["Bash(*)"]
}
}
// Good: allow only what's needed
{
"permissions": {
"allow": [
"Read(*)",
"Edit(src/**)",
"Bash(npm test)",
"Bash(npm run lint)"
],
"deny": [
"Bash(rm *)",
"Bash(git push *)",
"Bash(curl *)"
]
}
}
3. Sensitive Information Exposureβ
# Risky: include the entire .env file in context
cat .env | claude -p "analyze this config file"
# Safe: strip sensitive fields before passing it
env | grep -v "KEY\|TOKEN\|SECRET\|PASSWORD" | claude -p "review this config"
cat api-response.json | jq 'del(.token, .api_key)' | claude -p "analyze this"
4. Untrusted MCP Serversβ
MCP servers access your data through Claude. The list of allowed MCP servers is defined in configuration files in your source code β write them yourself or use only servers from trusted providers. Anthropic does not manage or audit third-party MCP servers.
5. Windows WebDAV Riskβ
When running Claude Code on Windows, do not enable WebDAV or allow access to paths that could include WebDAV subdirectories such as \\*. Microsoft no longer recommends WebDAV due to security risks. With WebDAV enabled, Claude Code could trigger network requests to a remote host and bypass the permission system.
Cloud Execution Securityβ
When using Claude Code on the Web (cloud execution), there are additional security controls:
| Security control | Description |
|---|---|
| Isolated VM | Each cloud session runs in an isolated, Anthropic-managed VM |
| Network access control | Restricted by default; can be disabled or limited to specific domains |
| Credential protection | Authentication through a secure proxy, using scope-limited credentials inside the sandbox |
| Branch restriction | git push is restricted to the current working branch |
| Audit logging | All actions are logged for compliance and audit purposes |
| Automatic cleanup | The cloud environment shuts down automatically after the session completes |
Remote Control sessions are different. The web interface connects to a Claude Code process on your local machine, so all code execution and file access happen locally. No cloud VM or sandboxing is involved, and data is transmitted over TLS.
Required .gitignore Settingsβ
# Claude Code local settings (may contain API keys)
.claude/settings.local.json
# Local-only settings
.env
.env.local
.env.*.local
*.pem
*.key
The project-level .claude/settings.json can be shared with the team, but never include API keys or personal information in it.
Organization-Level Security Policiesβ
Managed Settingsβ
In Enterprise/Team, managed settings enforce organization-wide security standards:
// Example managed policy
{
"permissions": {
"deny": [
"Bash(rm -rf *)",
"Bash(git push --force *)",
"Edit(*.env)"
]
},
"disableBypassPermissionsMode": "disable"
}
Managed settings take precedence over all lower-level settings.
Specifying Security Policies in CLAUDE.mdβ
## Security Policy
### Never do
- Connect directly to the production database and use Claude
- Include files containing customer PII (personally identifiable information) in context
- Hardcode API keys or passwords in code
- Deploy Claude-generated code to production without review
### Recommended
- Work in a local development or staging environment
- Require the security team to review security-related code
- Verify behavior with a test run before large-scale automation work
Team Security Best Practicesβ
- Enforce organization standards with managed settings
- Share approved permission settings under version control
- Train team members on security best practices
- Monitor Claude Code usage with OpenTelemetry metrics
- Audit or block configuration changes during a session with the
ConfigChangehook
Audit Logsβ
Use hooks to leave an audit log of important actions:
{
"hooks": {
"PreToolUse": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "echo \"[$(date -u '+%Y-%m-%dT%H:%M:%SZ')] USER:$(whoami) CMD:$CLAUDE_TOOL_INPUT_COMMAND\" >> ~/.claude-audit.log"
}
]
}
]
}
}
Subagent execution can also be audited with the SubagentStart/SubagentStop hooks.
Claude Security Plugin (/claude-security)β
A multi-agent vulnerability detection plugin available from Anthropic's official marketplace. Unlike traditional static analysis (SAST), it performs reasoning-based, multi-agent collaboration to map architecture, model threats, detect vulnerabilities, and cross-validate findings.
1. Installation and activationβ
> /plugin install claude-security@claude-plugins-official
> /reload-plugins
2. Key features and scan scopeβ
- Full repository scan: analyzes the architecture and potential security vulnerabilities across the entire codebase
- Diff/PR/commit scan: focuses only on the changes in a specific branch, PR, or single commit
- Automatic patch generation: converts discovered vulnerabilities into safe code patches for you to review and apply
- Standalone report generation: all results are saved as markdown reports under a
CLAUDE-SECURITY-<timestamp>/directory
> /claude-security
- Security Guidance plugin: inline guidance in real time as Claude writes code
/security-review(built-in): a single-pass security check on the current branch's changes- Claude Security plugin: multi-agent, in-depth threat modeling and automated patch suggestions
- Enterprise Claude Security: fully managed enterprise monitoring built on Claude Mythos 5
Sandbox Credential Maskingβ
On Linux and WSL2, you can apply mode: "mask" to credential files used during sandboxed execution.
- Sentinel substitution: commands running inside the sandbox read masked sentinel (fake) values; on egress, the sandbox proxy substitutes the real credential values.
- Advanced parsing options: beyond plain text, it supports
extract, JWT-awaredecode, and AWS SigV4 signature rewriting options to prevent token theft.
Containment Escape Prevention and Restricted Executionβ
1. Containment escape prevention rules (v2.1.257+)β
Auto mode now ships with built-in containment escape blocking rules:
- Blocks lookups of cloud instance metadata credentials (AWS
169.254.169.254, GCP metadata, etc.) - Blocks attempts to evade network egress controls
- Blocks cross-tenant access and unauthorized network reachability
2. Restricted mode for untrusted repositories (--restricted, v2.1.248+)β
When reviewing an untrusted external repository, claude --restricted removes all code/command execution tools and WebFetch, and forces file access to stay within the working directory.
3. Organization-managed MCP (managedMcpServers, v2.1.259+)β
Enterprise/Team organization admins can use the managedMcpServers setting to centrally deploy safe HTTP/SSE MCP servers to all users. MCP entries that execute arbitrary shell commands are automatically excluded to protect client-side security.
Security Checklistβ
Check before adopting Claude Code:
- API keys managed as environment variables (never hardcoded in code)
- Only minimal permissions granted in
settings.json - Claude-related sensitive files added to
.gitignore - Team security policy specified in
CLAUDE.md - MCP server source code reviewed
- Tools restricted with
--allowedToolsin CI environments - Audit logging configured (if needed)
- WebDAV confirmed disabled on Windows
- Permission settings audited regularly with
/permissions - Consider using a devcontainer for sensitive code work
If your security settings are too strict, productivity drops. Apply deny rules only to genuinely risky commands (rm, deploys, external transmission), and allow ordinary development tools to keep productivity up.
If you find a security vulnerability in Claude Code, don't disclose it publicly β report it through Anthropic's HackerOne program. Include detailed reproduction steps, and give Anthropic time to fix the issue before disclosure.
μ΄ μ±ν°λ₯Ό μλ£νμ ¨λμ?
νμ΅ μ§λλ₯Ό 체ν¬νμ¬ λμ λ‘λλ§΅ λ¬μ±λ₯ μ λμ¬λ³΄μΈμ.