If you discover a security vulnerability in claude-kit, please report it responsibly:
- Do NOT open a public issue
- Email: Open a private security advisory on GitHub
- Include: description, reproduction steps, and impact assessment
You should receive a response within 48 hours.
claude-kit generates configuration files for Claude Code. Security concerns include:
- Hook scripts (
template/hooks/,stacks/*/hooks/) — shell scripts that execute during Claude Code sessions - Deny lists (
settings.json) — files that should be blocked from reading - Rules — markdown files loaded into Claude's context (potential prompt injection vector)
block-destructive.sh— blocks dangerous bash commands (configurable profiles: minimal/standard/strict)- Deny list template covers:
.env,*.key,*.pem,*credentials*,*secret* - Audit item 12: prompt injection scan on rules and CLAUDE.md
tests/test-config.shvalidates deny list completeness
| Version | Supported |
|---|---|
| 2.0.x | Yes |
| < 2.0 | No |