adversa.ai/claude-code-...
I *gather* the TL;DR is "Claude only checks your restrictions against the first fifty commands it will run on your machine, after that it just trusts them" 🙃
Critical Claude Code vulnerabi... Critical Claude Code vulnerability: Deny rules silently bypassed because security checks cost too many tokens
Adversa AI Red Team found Claude Code's deny rules silently stop working after 50 subcommands. The fix exists in Anthropic's codebase. They never shipped it
Adversa AI | Agentic AI Security