Preliminary research
Claude Code audit: unrestricted environment mutation over remote-worker transport
Claude Code audit
AI-collected research leads through 2 October 2026, including bounded month-by-month reviews of selected social and community sources from April through September. Unranked, incomplete, not community-vetted, and subject to change.
Audits Claude Code's remote-worker transport and finds that an unauthenticated server message can mutate arbitrary worker environment variables. Setting NODE_OPTIONS makes a later child-process spawn load attacker-controlled JavaScript, demonstrating remote code execution despite the underlying issue being presented as defense in depth.
Record
- Document
- Claude Code audit
- Researcher
- Zack Skolnik
- Date
In the archive
Related sources
- PoC Repository
Tags
This page is the archive's own catalogue record. The research is the work of Zack Skolnik, first published at the original source. Preserved copies are kept so the citation survives its host.