• Sources: primary, discussion
  • Summary: Immersive Labs reports that checking out an untrusted pull request branch inside an already-trusted repository and then opening Claude Code runs any command declared in the branch's project-scoped .mcp.json. Execution happens before the user types anything and without an active account. Anthropic's bug bounty response states the workspace trust model places the boundary at the folder trust decision, so the behaviour is treated as designed rather than as a defect. No affected Claude Code versions are named and no fix is planned.
  • Why it matters: The practical control is reviewing .mcp.json and .claude/ as executable code before switching to a contributor branch.
  • Follow-up: Track whether Anthropic moves the trust boundary below the folder level.

send feedback on this story