Story · arXiv

When "Do Not" Is Not Deny: Security Rules in CLAUDE.md vs Built-In Controls (arXiv)

paper · Story page

Two doorways side by side: one open with a pinned note beside it and a small robot walking through, one blocked by a turnstile bar with the robot stopped in front.

In 481 public CLAUDE.md files, only about 4% to 16% of the extracted security rules had a matching built-in Claude Code control, depending on how strict the match had to be. The authors' framing: CLAUDE.md is a write-only channel, and you get no feedback on whether anything enforces what you wrote.

In plain words

  • Researchers found most written security rules for Claude Code had no matching built-in block against forbidden actions.
  • Written instructions rely on Claude Code interpreting the words, while built-in controls stop selected actions before they happen.
  • Among 481 public instruction files, only about 4% to 16% of extracted rules matched a built-in control.
  • The extraction method found 66.3% of eligible rules, so the reported matching rates cover only those found rules.
  • Developers may believe a written rule is enforced even when the software offers no matching safeguard or warning.

Appeared in

Subscribe

Get the brief in your inbox

Pick daily, weekly, or both. Nothing is gated either way: every issue is on the site and in the feeds.

  • Weekdays at 8:45am IST, one lead story and 6 to 9 items.
  • Sundays, an argued synthesis rather than a recap.
  • One click to leave, and quiet days say so in the subject line.
How often

Weekdays 8:45am IST + Sundays. Unsubscribe in one click.

You're asking for The Agentic Brief by email at the cadence you picked. You can unsubscribe in one click from any issue, and your address is never sold or shared.