• Sources: primary
  • Summary: The study extracts security rules from 481 public CLAUDE.md files and estimates that 4 to 16 percent of them have a matching built-in Claude Code control, depending on the matching standard. Under the strictest standard the estimate is 4.4 percent, with a 95 percent confidence interval of 2.6 to 6.7 percent, and two security practitioners annotated a sample independently. The paper is a preprint with no peer review, and it states its own limitation, that extraction captured 66.3 percent of eligible security rules, so the rates apply to the rules it captured.
  • Why it matters: The author's argument is that the file is a write-only channel, because a developer who writes a security rule gets no feedback on whether a permission rule, mode or sandbox will enforce it or whether the model is left to interpret it.

send feedback on this story