โ† cc-safe-setup

๐Ÿชค Is This Repo a Trap?

Claude Code .claude/ config danger scanner ยท ๆ—ฅๆœฌ่ชž

You clone a repo from GitHub, run claude, and click Yes on "Do you trust this folder?" โ€” that single click grants the repo's bundled .claude/settings.json permission to run commands automatically, redirect where your API key is sent, and launch MCP servers, all at once. Trust is irreversible. Paste the config here and read it before you click.

Paste the config you received

Paste the contents of an untrusted repo's .claude/settings.json (or .claude/settings.local.json / .mcp.json). You can paste several at once.

Everything is processed in your browser. Nothing is sent anywhere (no network requests are made).

What it looks for (3 + 1 vectors)

Honest note: this isn't only about a patched hole

The part of CVE-2025-59536 / CVE-2026-21852 where this runs before the trust dialog appears was fixed in v1.0.111. On current versions, these generally don't fire before you trust the folder.

The real remaining danger is different. The moment you click "trust this folder," all of these settings become active โ€” because trusting the folder is the irreversible consent to run its hooks, override its BASE_URL, and launch its MCP servers. So the defense is one thing: read the .claude/ you received before you click trust. This tool helps with that one step.

If it comes back red