Claude Code and security: what happens when an agent reads code, modifies files, and executes commands
Claude Code is not a writing assistant or an IDE plugin: it is an operational terminal agent with direct permissions on the filesystem, the shell, and the codebase. Unlike chat-based tools, it acts at the heart of the local development environment or pipeline, capable of planning complex refactoring, creating commits, and producing structural changes that affect the very architecture of the application.
The main risk lies in delegation: when you allow an agent to “fix a bug” or “implement a feature,” you entrust it with the power to alter middleware, network configurations, dependencies, and authorization models with unprecedented autonomy. Understanding where the security boundaries lie — and how to guard them — is the starting point for using these tools responsibly.
The agent in the terminal: a new security boundary
Claude Code shifts the security boundary from simple code to permission management in the terminal. The agent does not just suggest: it proposes a plan and executes it operationally. Three areas concentrate the most relevant risks.
Shell and Permission Mode. The agent may request to execute shell commands such as npm install, docker-compose up, or aws configure. Without rigorous supervision via Permission Mode, these commands can expose secrets, alter filesystem permissions, or modify critical security settings for the local or cloud environment.
The CLAUDE.md file. This file is used by the agent to store persistent instructions, context, and project standards. If written inaccurately or manipulated, it can lead the agent to follow insecure code patterns — for example, ignoring CSRF validation in a prototype — or to systematically bypass security controls established by the organization.
MCP (Model Context Protocol) Integration. Claude Code can connect to MCP servers to read documentation, query real databases, or interact with external APIs. Every tool added via MCP expands the attack surface and increases the risk of unintended agentic behavior.
Operational risks specific to the agentic CLI workflow
Permission Fatigue and uncritical acceptance
The constant need to approve shell commands or file reads can lead the developer to so-called Permission Fatigue: one begins to accept everything uncritically, including commands that could expose environment variables, private keys, or cloud configurations that the agent read during the analysis phase. Every unverified approval is a potential opening.
Supply chain manipulation and unverified dependencies
Claude Code may decide to resolve a dependency conflict by adding a new library or modifying the lock file. If the agent suggests a vulnerable version or hallucinates a package name — paving the way for typosquatting — and the developer approves the change without a manual audit, the application instantly inherits a supply chain risk that is difficult to trace later.
Misleading tests and self-validation
The agent has the ability to write and execute tests to validate its own changes, but AI-generated tests tend to cover only the “happy path” of the newly created solution. Logical bugs, authorization bypasses, and regressions on edge cases remain invisible because the agent did not consider them in the original plan and has no incentive to actively look for them.
Context exposure and context leak
The agent reads large portions of the codebase to understand the assigned task. Without proper configuration via .claudeignore, sensitive data, private keys, or local databases can be included in the context sent to Anthropic’s servers, crossing corporate confidentiality boundaries without the operator noticing.
What to verify before and after an operational session
- Every shell command proposed by the agent has been verified line by line, with attention to commands that touch the network or filesystem permissions.
- The instructions in the CLAUDE.md file contain clear security standards and have been reviewed to avoid insecure patterns.
- Files containing secrets, private keys, local databases, and logs are explicitly excluded via
.claudeignore. - After the session, any newly added packages have been verified for reputation and security.
- Structural changes — such as changes to middleware or access policies — have been reviewed by a competent professional.
When independent verification is needed
When a CLI agent has operated on large portions of the codebase, the risk surface is no longer localized to a single file or function. An overview is needed to ensure that authorization consistency has been maintained and that the changes have not introduced transversal vulnerabilities that are difficult to identify with a partial review.
| If Claude Code has modified… | The main risk is… | Recommended ISGroup service |
|---|---|---|
| Controllers, Auth, API | Vulnerabilities in code, broken logic | Code Review |
| Web interfaces, Endpoints | External abuse, BOLA/IDOR | Web Application Penetration Testing |
| CLAUDE.md, MCP, trust boundary | Weak security assumptions | Secure Architecture Review |
| Pipelines, multiple teams | Lack of governance and processes | Software Assurance Lifecycle |
Frequently asked questions
- Is Claude Code safer than an IDE-integrated assistant?
- It offers more granular control via the terminal, but requires constant vigilance by the operator. The risk of executing malicious commands is real if you do not supervise every single permission request.
- How do you protect the CLAUDE.md file?
- The memory file should be treated as critical source code: it must contain only verified instructions and must not become a vector for forcing the agent to adopt insecure code patterns.
- What happens if Claude Code hallucinates a shell command?
- The terminal may return an error, but the real risk is that the hallucination produces a syntactically correct but logically dangerous command, such as recursive file deletion or opening unintended network ports.
Protect your organisation with Web Application Penetration Testing.
Choose ISGroup for a practical, tailored engagement:
- A focused assessment of your environment and requirements
- Clear findings with a prioritised, actionable roadmap
- Direct support from experienced specialists through remediation and implementation
