A finding quotes the offending line, so when the reviewer flagged a hardcoded secret the Stop hook's feedback and the previous_findings snapshot in ~/.claude/security carried the credential itself back into the main conversation and onto disk (#96276, follow-up report). Values recognized as credentials in vulnerableCode / fix / evidence text are now masked to **** plus the last two characters at every boundary to the main session and before they are stored: the value after a password / secret / token / api_key-style key (code, JSON, YAML, .env, XML, Dockerfile ENV), passwords in connection URLs, Authorization and curl -u credentials, CLI credential flags, well-known API-key formats and private-key blocks, plus, in findings classed as hardcoded secrets, other quoted literals and long opaque tokens. The reviewer prompts are unchanged so diff anchoring and the refute pass keep working on the raw quote; masking happens on the way out. The commit-review guidance formatter now reuses format_findings.
Claude Code
Claude Code is an agentic coding tool that lives in your terminal, understands your codebase, and helps you code faster by executing routine tasks, explaining complex code, and handling git workflows -- all through natural language commands. Use it in your terminal, IDE, or tag @claude on Github.
Learn more in the official documentation.
Get started
Note
Installation via npm is deprecated. Use one of the recommended methods below.
For more installation options, uninstall steps, and troubleshooting, see the setup documentation.
-
Install Claude Code:
MacOS/Linux (Recommended):
curl -fsSL https://claude.ai/install.sh | bashHomebrew (MacOS/Linux):
brew install --cask claude-codeWindows (Recommended):
irm https://claude.ai/install.ps1 | iexWinGet (Windows):
winget install Anthropic.ClaudeCodeNPM (Deprecated):
npm install -g @anthropic-ai/claude-code -
Navigate to your project directory and run
claude.
Plugins
This repository includes several Claude Code plugins that extend functionality with custom commands and agents. See the plugins directory for detailed documentation on available plugins.
Reporting Bugs
We welcome your feedback. Use the /bug command to report issues directly within Claude Code, or file a GitHub issue.
Connect on Discord
Join the Claude Developers Discord to connect with other developers using Claude Code. Get help, share feedback, and discuss your projects with the community.
Data collection, usage, and retention
When you use Claude Code, we collect feedback, which includes usage data (such as code acceptance or rejections), associated conversation data, and user feedback submitted via the /bug command.
How we use your data
See our data usage policies.
Privacy safeguards
We have implemented several safeguards to protect your data, including limited retention periods for sensitive information, restricted access to user session data, and clear policies against using feedback for model training.
For full details, please review our Commercial Terms of Service and Privacy Policy.