Tag: Claude Code
105 posts tagged with "Claude Code" — Page 1 of 5
Claude Code plugin security has critical unresolved flaws even after patching the Plugin4Shell zero-click RCE vulnerability. SHA-pinning and reviewed marketplace entries no longer provide a dependable trust boundary, and additional policy gaps expose enterprise environments to supply-chain and local execution risks.
AI coding agents ignore repository instructions due to mechanical failures in discovery, precedence, and content quality, not deliberate disobedience. Most issues stem from tool-specific loading rules and precedence hierarchies that nullify instruction files before code generation begins. Standardizing on a single cross-vendor AGENTS.md file and verifying load paths per tool resolves most gaps.
Sixteen percent of AI coding agent setups in public GitHub repositories carry a security defect, according to a study of 3,171 repos published this month — and almost none of those defects have anything to do with the model. That's the uncomfortable truth about AI coding agent configuration poisoning: the attack surface isn't the LLM.
Claude Code Projects is a multi-thread cloud orchestrator that multiplies subscription usage, launched three days after Anthropic cut every user's effective weekly limit by 17%. Each parallel thread consumes a full session's worth of quota, so the feature accelerates consumption exactly when the subscription ceiling dropped, pushing users toward pay-as-you-go usage credits.
Seat-based AI budgeting systematically underbudgets agent workloads by 5 to 30x, as agent spend scales with execution loops and task complexity rather than headcount. Runtime spend governance that enforces hard caps at the execution layer, not post-hoc billing dashboards, is the only reliable way to prevent runaway overruns.
Claude Code for Spring Boot teams requires Team Premium at $125 per seat, not the cheaper $25 Standard tier that excludes Code access entirely. It offers valuable MCP integrations for live JVM debugging and Spring Tools IDE support, but shared usage pools can silently consume coding limits with high non-coding Claude activity.
Seventy-four percent of enterprises have rolled back or shut down a deployed agent after launch, exposing a critical gap in agent rollback patterns: customer data exposure is the leading trigger, and code reverts don't fix it. That number comes from Get Ready for Agents, and it's part of a larger pattern.
Unconfigured Claude Code generates NestJS code with broken dependency injection and module patterns that bypass the framework's lifecycle management. A committed CLAUDE.md encoding your project's DI rules, module boundaries, and conventions eliminates these predictable failure modes for consistent, testable output.
Human review is the weakest link in AI safety: in Anthropic's study humans caught just 13.6% of dangerous commands while an AI classifier blocked 89%, and developers approve 97% of prompts. Freeze annotation budgets and redirect investment toward AI-managed evaluation loops with irreversibility gating rather than more reviewers.
Constraint-first prompting eliminates the bimodal intent tax that causes 54.5% hidden violations in AI coding. Claude Sonnet 4.6 passes 94.3% of visible tests yet fails hidden constraints deterministically at 95.7% bimodal concentration, making structured spec contracts the only reliable fix over model upgrades.
Codex is the cheapest multi-surface agent for Go at $8 per month, but it requires unofficial SDK bridges and strict quota management. Claude Code and Cursor avoid the SDK gap yet cost $17 to $20 monthly and lock you into terminal or editor workflows. A 50-developer team pays $12,000 yearly in base subscriptions before token overage hits.