Skip to content

Claude / Claude Code

Anthropic’s Claude models and Claude Code: usage, configuration, Skills, Hooks, pitfalls, and version changes.

62 curated itemsRelated topicsOpenAI / CodexSkillsWorkflows

Latest curated items

Items 21–40 · 62 total
7/30Thu
  1. Martin Fowler · Exploring Generative AI78

    重构的经济收益:一次用 Claude Code 量化 token 节省的实验

    Martin Fowler 用一个约 15 万行、几乎全由 Claude Code 和 Cursor 写成的 Rust 应用做实验,把 17,155 行的数据访问层按严格重构步骤拆分,每步后用全新子智能体执行同一个代表性改动并记录 token 消耗。

    Awaiting translation

    Why it matters: 作者用同一改动反复跑重构前后对比,量化出重构对智能体 token 消耗的实际影响,并指出节省来自文件切分而非代码总量下降。

7/26Sun
  1. Hacker News · Context Engineering 讨论82

    Anthropic publishes new context engineering rules for Claude 5

    Thariq Shihipar, a member of Anthropic's engineering team, wrote up the new context engineering rules for Claude 5, saying the team has cut over 80% of the system prompt from Claude Code for models like Claude Opus 5 and Claude Fable 5, with no measurable loss on coding evals.

    Why it matters: Anthropic lays out the new context engineering rules for Claude 5 and explains how to trim the system prompt, CLAUDE.md, and Skills.

7/19Sun
  1. Hacker News · Claude Code 高分80

    把闲置 Mac 配成 Claude Code 可完全控制的常驻机器:分步指南

    作者 ykev 发布一份分步指南,教用户把闲置 Mac 变成 Claude Code 可完全控制、开启 computer use 的常驻机器,可从手机 Claude app 或主 Mac 经 SSH 操作。

    Awaiting translation

    Why it matters: 作者把闲置 Mac 改造成 Claude Code 常驻控制机,给出从 SSH、免密 sudo 到 computer use 的完整步骤,可迁移到任意两台机器。

7/17Fri
  1. Hacker News · Claude Code 高分80

    Claude Code 2.1.198 静默引入 AskUserQuestion 自动继续,作者用二进制 diff 还原全过程

    Claude Code 2.1.198 让 AskUserQuestion 在 60 秒无操作后自动返回“proceed anyway”,把原本阻塞的人工确认变成倒计时,2.1.200 才改为默认关闭、需在 /config 里开启。

    Awaiting translation

    Why it matters: 作者用二进制 diff 还原了 Claude Code 一次静默行为变更的来龙去脉,并给出关闭自动更新的可复用配置。

7/11Sat
  1. Habr · Kova13v80

    Using an evidence contract to constrain Claude Code's test conclusions: a QA Skill package

    A QA engineer distilled six months of experience doing web testing on Claude Code into an open-source Skill package called paranoid-qa. At its core is an evidence contract: Pass/Fail can only be based on actual artifacts like screenshots, request bodies, and logs; anything unverified gets marked Not tested; anything blocked by the environment gets marked Blocked; and forms must verify the real submitted payload.

    Why it matters: The author codified six months of QA experience into a testing Skill package for Claude Code, along with an evidence contract and failure checklist that can be reused directly.

7/6Mon
  1. 宝玉80

    The Claude Code team explains the four types of AI agent loops and how to use them

    The Claude Code team defines an AI agent loop as repeatedly running a work cycle until a predefined stopping condition is met, and splits it into four types—turn-based, goal-oriented, time-based, and proactive—along four dimensions: what triggers it, how it stops, the underlying instructions it uses, and the tasks it fits.

    Why it matters: The Claude Code team breaks loops into four types—turn-based, goal-oriented, time-based, and proactive—and lays out how each is triggered, how it stops, and how tokens are controlled.

7/5Sun
  1. Jesse Vincent68

    Developing Sen 2.0 by having Claude Code and an agent on Slack review each other's work

    At Prime Radiant, author Jesse Vincent used Claude Code—working through the Slackline command-line Slack client—to collaborate with his own agent Ada: Claude proposes changes, Ada reviews and tests them, then Claude deploys the updates, forming a development loop where the agents review each other.

    Why it matters: By looping two agents through mutual review, testing, and deployment, the author shows a transferable model for collaborative agent-based development.

6/8Mon
  1. Permission Protocol · AI Agent Incident Tracker88

    Agentjacking:攻击者借公开 DSN 注入伪造 Sentry 错误,劫持 Claude Code、Cursor 和 Codex

    安全研究披露一种名为 Agentjacking 的攻击:攻击者利用 Sentry 公开的 DSN 向 ingest API 提交伪造错误事件,AI 编码智能体通过 Sentry MCP 取回这些事件后,把其中的 Markdown 注入内容当作可信指令执行 shell 命令,在受控测试中成功率 85%,涉及 2,388 家组织。

    Awaiting translation

    Why it matters: 还原了 Sentry MCP 提示词注入劫持编码智能体的完整链路,并指出授权门禁应设在工具调用层。

6/7Sun
  1. Permission Protocol · AI Agent Incident Tracker87

    Hades 攻击通过污染 AI 工具配置文件和 PyPI 启动钩子窃取 294,842 条凭据

    Hades 攻击波在 Claude Code、Cursor、Gemini CLI 和 VS Code 的配置文件中植入钩子,并通过 37 个 PyPI wheel 的 .pth 启动钩子,从 6,943 台开发者机器窃取 294,842 条凭据,涉及 GitHub、PyPI、AWS/GCP/Azure 凭据、SSH 密钥和 Kubernetes secrets。

    Awaiting translation

    Why it matters: 复盘攻击如何借 AI 工具配置文件与 Python 启动钩子在开发者机器上窃取凭据,并指出授权边界缺口。

6/5Fri
  1. Permission Protocol · AI Agent Incident Tracker85

    微软披露 Claude Code GitHub Action 提示注入可窃取 CI/CD 密钥并绕过 GitHub 密钥扫描

    微软记录了一起 Claude Code GitHub Action 提示注入事件,攻击者把指令藏在 GitHub issue 的 HTML 注释里,让 Claude 读取 /proc/self/environ,截断凭据字符串以绕过 GitHub 密钥扫描,再通过 gh CLI 的 URL 参数外传。

    Awaiting translation

    Why it matters: 微软披露的 Claude Code GitHub Action 提示注入链路,展示了不可信内容与凭据读取权限同处一室时的真实风险。

  2. Permission Protocol · AI Agent Incident Tracker88

    Miasma 供应链蠕虫通过 Agent 配置注入禁用 73 个微软 GitHub 仓库并窃取凭据

    Miasma 蠕虫通过投毒 Agent 配置文件感染 73 个微软 GitHub 仓库,开发者在 Claude Code、Cursor 或 Gemini CLI 中打开仓库时即执行凭据窃取程序,导致 AI API token、GitHub token 和云凭据泄露。

    Awaiting translation

    Why it matters: 复盘 Miasma 蠕虫如何借 Claude Code、Cursor、Gemini CLI 的会话初始化配置实现零点击窃取凭据,可迁移到仓库配置来源校验。

6/3Wed
  1. claude.dev · Anthropic Developer Blog86

    Anthropic shares what it learned from using Skills inside Claude Code: nine categories and tips for writing them

    Inside Claude Code, Anthropic has already built up hundreds of Skills in active use. The team sorts them into nine categories—library and API references, product validation, data fetching and analysis, business process automation, code scaffolding, code quality and review, CI/CD and deployment, runbooks, and infrastructure operations—and notes that the best Skills should fall cleanly into one of them.

    Why it matters: Anthropic’s internal framework for categorizing hundreds of Skills, along with its experience writing them, can carry over to a team building its own Skill library.

  2. Permission Protocol · AI Agent Incident Tracker80

    Sophos X-Ops:俄罗斯攻击者用 Claude Opus 4.5 编排 80 模块勒索软件工具包

    Sophos X-Ops 发现一名俄罗斯威胁攻击者使用 Cursor IDE 和 Claude Opus 4.5 作为编排智能体,搭建了一个 80 模块的勒索软件工具包,并成功规避 Sophos、CrowdStrike 和 Windows Defender 的 EDR 检测。

    Awaiting translation

    Why it matters: Sophos 披露的攻击链显示,Claude Opus 4.5 被用作编排智能体,串起多智能体分工与 EDR 规避测试。

  3. Permission Protocol · AI Agent Incident Tracker76

    仿冒 Claude Code 与 Codex 安装页经 Google Sites 投递无文件内存窃密程序

    攻击者用 Google Sites 托管仿冒 Claude Code 和 Codex 的安装页,诱导开发者在运行对话框粘贴 mshta.exe 命令,投递无文件内存窃密程序,窃取 AI API key、浏览器凭据和开发者环境密钥。

    Awaiting translation

    Why it matters: 梳理了仿冒 Claude Code 与 Codex 安装页的 ClickFix 攻击链,可了解针对 AI 开发者凭据的窃取手法。

6/2Tue
  1. claude.dev · Anthropic Developer Blog82

    Claude Code Dynamic Workflows: Six Orchestration Patterns and Use Cases

    Anthropic has shipped dynamic workflows in Claude Code. Claude can write its own harness on the fly for a specific task, and these workflows can be shared and reused. Workflows orchestrate subagents through functions like agent(), parallel(), and pipeline(), and you can specify which model each agent uses and whether it runs in its own worktree. If a session is interrupted, resuming it picks up where it left off.

    Why it matters: The Anthropic team breaks down six orchestration patterns for dynamic workflows and where each one fits, and these patterns carry over to multi-agent task design.

5/27Wed
  1. Permission Protocol · AI Agent Incident Tracker78

    Oasis Security 串联三个 Claude.ai 漏洞实现静默数据外泄

    Oasis Security 将 URL 参数注入、Files API 外泄和开放重定向三个 Claude.ai 漏洞串联,在用户提交时静默窃取对话历史。攻击者把隐藏 HTML 标签放进 ?

    Awaiting translation

    Why it matters: Oasis Security 披露的攻击链说明默认 claude.ai 会话即可被静默窃取对话历史,并指出 MCP 集成会扩大影响范围。

5/20Wed
  1. claude.dev · Anthropic Developer Blog71

    用 HTML 替代 Markdown 承载 Claude Code 输出:Anthropic 工程师的实践

    Anthropic 工程师 Thariq Shihipar 提出用 HTML 替代 Markdown 作为 Claude Code 的输出格式,理由是 HTML 信息密度更高、更易阅读和分享,还能做双向交互。

    Awaiting translation

    Why it matters: Anthropic 工程师分享用 HTML 替代 Markdown 承载 Claude Code 输出的做法,附常见场景的提示词与模板。

5/12Tue
  1. Permission Protocol · AI Agent Incident Tracker82

    Claude Code was exploited via a malicious deeplink that injected a SessionStart hook to achieve RCE; fixed in v2.1.118.

    The Claude Code CLI has a critical RCE vulnerability: an attacker can craft a claude-cli:// deeplink to exploit eagerParseCliFlag's context-free parsing of process.argv in main.tsx.

    Why it matters: I walked through the RCE chain caused by Claude Code's lack of contextual parsing for command-line arguments, and gave my take on where the authorization boundary should be drawn.

  2. Permission Protocol · AI Agent Incident Tracker78

    ClaudeBleed:零权限 Chrome 扩展可劫持 Claude 并窃取 Gmail、Drive 和 GitHub 数据

    LayerX 研究人员发现 Claude 的 Chrome 扩展存在信任边界缺陷,任何零权限扩展都能劫持 Claude、绕过用户确认并窃取 Gmail、Google Drive 和 GitHub 数据。

    Awaiting translation

    Why it matters: LayerX 披露的 Claude Chrome 扩展信任边界缺陷,展示了零权限扩展如何绕过确认流程窃取数据。

5/8Fri
  1. Permission Protocol · AI Agent Incident Tracker80

    Claude Code 遭恶意 npm 包经 MCP 中间人劫持窃取 OAuth token

    Mitiga Labs 披露一条针对 Claude Code 的攻击路径:恶意 npm 包通过 postinstall 钩子修改 ~/.claude.json,把 MCP 服务器 URL 替换为攻击者代理,使每次 MCP 会话的 OAuth token 和 SaaS 凭据都经攻击者基础设施转发。

    Awaiting translation

    Why it matters: 披露了恶意 npm 包通过篡改 MCP 配置劫持 OAuth token 的完整攻击链,并指出配置变更缺少授权校验这一根因。