claude-code-headless
Warn
Audited by Socket on Jul 28, 2026
1 alert found:
SecuritySecurityreferences/integration-patterns.md
MEDIUMSecurityMEDIUM
references/integration-patterns.md
No direct evidence of classic embedded malware (no hardcoded secrets, obfuscated payloads, persistence, or explicit malicious system/network operations) is present in the provided fragment. However, the code functions as an unauthenticated remote agent-execution gateway for a powerful local CLI. Caller-controlled prompt content and especially unvalidated caller-controlled --allowedTools create a significant abuse-of-capability risk, with potential data exposure via returned/recorded outputs. This should be treated as a security alert requiring strict server-side tool allowlisting, authentication/authorization, and execution/resource constraints (timeouts/rate limits/sandboxing) around claude.
Confidence: 66%Severity: 72%
Audit Metadata