Story · arXiv
When "Do Not" Is Not Deny: Security Rules in CLAUDE.md vs Built-In Controls (arXiv)
paper · Story page

In 481 public CLAUDE.md files, only about 4% to 16% of the extracted security rules had a matching built-in Claude Code control, depending on how strict the match had to be. The authors' framing: CLAUDE.md is a write-only channel, and you get no feedback on whether anything enforces what you wrote.
In plain words
- Researchers found most written security rules for Claude Code had no matching built-in block against forbidden actions.
- Written instructions rely on Claude Code interpreting the words, while built-in controls stop selected actions before they happen.
- Among 481 public instruction files, only about 4% to 16% of extracted rules matched a built-in control.
- The extraction method found 66.3% of eligible rules, so the reported matching rates cover only those found rules.
- Developers may believe a written rule is enforced even when the software offers no matching safeguard or warning.
Appeared in
- Compaction erases agent safety rules, and CLAUDE.md prose isn't a control
Aug 26, 2026 · in the sections
Subscribe
Get the brief in your inbox
Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.
- Weekdays at 8:45am IST, one lead story and 6 to 9 items.
- Sundays, an argued synthesis rather than a recap.
- One click to leave, and quiet days say so in the subject line.
