Get a Quote

Claude Code App Security Audit - Autonomous Doesn't Mean Audited

Claude Code is Anthropic's agentic CLI - also shipped as a VS Code/JetBrains extension, a web/cloud version, and the Claude Agent SDK - and it reads, writes, and runs shell commands on its own, gated by a permission and allowlist system rather than a hosted stack. That system controls what Claude Code can do on your machine; it doesn't guarantee the code it writes is secure. We audit Claude Code-built apps for the access-control and secrets gaps that slip through, plus the permission-model and MCP risks specific to how it operates.

Run a free 30-second scan Book an audit
What Claude Code is

An autonomous CLI agent, not an opinionated app builder

Claude Code is Anthropic's agentic command-line coding tool - also shipped as a VS Code/JetBrains extension, a web/cloud version, and the Claude Agent SDK. It runs in the terminal, reads and writes files in the working directory, and executes shell commands to complete coding tasks with minimal supervision. Security is built on a permission/allowlist model across project, user, and enterprise "managed settings" tiers: read-only by default, with explicit approval required for writes and commands, plus MCP servers, subagents, and hooks that run shell commands on events. Usage is broadening fast - from professional developers to non-technical teams building internal tools, scripts, and even docs - which means the guardrails matter for more people who don't have a security background to fall back on.

What we find

What Claude Code-built apps get wrong

These are the specific, recurring patterns we see when we audit apps built with Claude Code - not generic AI-code warnings.

1. Secrets leaked in AI-assisted commits

GitGuardian: Claude Code-assisted commits leak secrets at 3.2% vs 1.5% human baseline

Roughly double the leak rate of human-only commits - part of a bigger picture where 28.6 million new secrets hit public GitHub in 2025 (up 34% year over year) and AI-service credential leaks alone rose 81%.

We fix it by moving every secret into environment variables or a secrets manager, then scanning history for anything already exposed.

2. Vulnerable code at a meaningful rate, even from strong models

Veracode: Claude Opus 4.7 included a vulnerability in 52% of coding attempts

That's higher than the roughly 30% rate Veracode measured for comparable OpenAI models. Models tend to optimize for "it works" over "it's secure," and Claude Code will confidently ship code that runs but isn't safe unless someone checks it.

We fix it by testing for the specific vulnerability classes models miss, not assuming a capable model means secure output.

3. Insecure defaults and over-broad permissions

an overly broad default allowlist already enabled silent data exfiltration once (CVE-2025-55284)

Claude Code's permission system is opt-in security - an allowlist that's too permissive, or a repo run with --dangerously-skip-permissions, removes the barriers meant to catch a mistake or a malicious instruction before it executes.

We fix it by auditing the actual permission settings and allowlist your team is running, not just the defaults from the setup guide.

4. Prompt injection via untrusted repo content and MCP

malicious instructions hidden in files, PRs, or MCP output can hijack the agent

Several of Claude Code's disclosed CVEs trace back to this pattern: content the agent treats as data - a README, a dependency, an MCP tool's response - actually contains instructions it follows, sometimes before you've even approved the folder as trusted.

We fix it by auditing MCP server trust boundaries and treating repo content as untrusted input by default.

Separate issue

Claude Code's own security posture (not the same thing as your app)

This is about Claude Code the product, not the code it writes for you. Anthropic holds SOC 2 Type I & II, ISO/IEC 27001:2022, ISO/IEC 42001:2023, CSA STAR, and NIST 800-171, and describes itself as HIPAA-ready - strong certifications, but they cover Anthropic's own systems, not the correctness of what Claude Code generates. Commercial plans (Team, Enterprise, API) aren't used for training; consumer plans (Free, Pro, Max) are, by default, since a September 2025 policy change, with retention up to five years when training is allowed. --dangerously-skip-permissions disables every guardrail at once and should be treated as a deliberate, logged exception, not a convenience setting.

ItemStatus
SOC 2 / ISO 27001 / ISO 42001Anthropic holds all three; certifies Anthropic's systems, not your generated code
HIPAA / BAA"HIPAA-ready," but BAA coverage is narrow - only ZDR-enabled CLI via API/Enterprise OAuth or Desktop local mode
Training on your codeOff for Team / Enterprise / API; consumer Free / Pro / Max trains by default since Sept 2025
Default permission modelRead-only by default; writes and commands require explicit approval unless allowlisted
--dangerously-skip-permissionsDisables all guardrails - treat as a logged, deliberate exception only
Audit loggingOpenTelemetry monitoring and admin controls - Enterprise tier
Claude Code's own CVEs

Vulnerabilities disclosed in Claude Code itself

These affect the Claude Code tool, not necessarily your app - but if you're running an unpatched version, they're worth knowing about.

CVE / IssueSeverityWhat it means
CVE-2025-52882High (CVSS v4 8.8)IDE extensions ran an unauthenticated local WebSocket server; a malicious website could connect to it and achieve remote code execution. Vulnerable versions were pulled.
CVE-2025-55284High (CVSS 7.1)A permissive default command allowlist let data be read and exfiltrated over DNS - encoding secrets as subdomains via ping/nslookup - with no prompt or log. Fixed in v1.0.4.
CVE-2025-59536High (CVSS ~8.7)A repo's .claude/settings.json could enable MCP servers or run hooks before the "trust this folder?" prompt ever appeared - consent bypass plus RCE. Fixed ~v1.0.111+.
CVE-2026-21852Moderate (CVSS 5.3)A malicious repo could override ANTHROPIC_BASE_URL in settings to redirect traffic and steal a plaintext API key before the trust dialog. Fixed ~v2.0.65+.
CVE-2025-66032High (CVSS 8.7)The Claude Code GitHub Action could be tricked by a crafted issue into leaking OIDC credentials, gaining write access for supply-chain code injection. Patched within 4 days of disclosure.
How we work

What our Claude Code audit checks

  • Server-side auth and ownership checks on every route Claude Code scaffolded, not just the obvious ones
  • No secrets hardcoded in source, in the frontend bundle, or sitting in git history
  • Permission settings and allowlists reviewed for anything left too permissive from setup or testing
  • MCP servers and repo content (README, PRs, tool output) treated as untrusted input, not implicit instructions
  • .claude/settings.json and any hooks audited for repo-controlled config risk
  • Claude Code pinned to a patched version, with any --dangerously-skip-permissions usage reviewed and logged
FAQ

Common questions about Claude Code security

Is code written with Claude Code secure?

Not automatically. Veracode found Claude Opus 4.7 included a vulnerability in 52% of coding attempts - higher than comparable OpenAI models - because models tend to optimize for working code over secure code. Treat Claude Code output like any AI-generated code: reviewed before it ships.

Does Claude Code train on my code?

It depends on the plan. Team, Enterprise, and API usage (including Claude Code via API) is not used for training. Consumer plans - Free, Pro, and Max - are used for training by default since a September 2025 policy change, with retention up to five years when that setting is on, unless you opted out.

What does --dangerously-skip-permissions actually disable?

All of it - the read-only default, the approval prompts for writes and commands, everything. It exists for specific automation cases, but running it routinely on real code removes every checkpoint that would otherwise catch a mistake or an injected instruction.

What does an audit cost?

The initial scan is free and takes about 30 seconds. A full audit starts at and any fixes we recommend are quoted separately based on what we actually find in your app.

Built it with Claude Code. Let's make sure it's safe to launch.

Free 30-second scan, then a clear list of what needs fixing before real users touch it.

Run a free 30-second scan