If you believe you have found a security vulnerability in Claw Code, please do not open a public issue with exploit details.
Preferred reporting path:
- use GitHub private vulnerability reporting / Security Advisories for this repository
If private reporting is not available, contact the maintainer at chenchunrun@gmail.com and include:
- a clear description of the issue
- affected files, commands, or features
- reproduction steps
- impact assessment
- any suggested mitigation
Please avoid publishing proof-of-concept details until the issue has been reviewed and a fix or mitigation is available.
Security-sensitive areas in this repository include:
- local command execution
- file read and write tooling
- plugin loading and lifecycle execution
- OAuth credential handling
- network-fetching utilities
- agent and subagent permission boundaries
The project is maintained on a best-effort basis. Triage time may vary, but reports that include a precise reproduction path and impact summary are much easier to act on quickly.