AI platforms · AI coding agent (terminal)
Is my Claude Code app secure?
Agents such as Claude Code write whole services, including the infrastructure files. That is where new kinds of slips appear: privileged containers, firewall rules open to the world, and dependency manifests without a lockfile, alongside the usual injection patterns.
Audit my Claude Code app free → Scan the code too
What Claude Code usually leaves open
Typical stack: Any stack; agents tend to produce complete back ends, Dockerfiles and CI configs.
- Privileged container or root user (Code Scan)privileged: true or USER root in a generated Dockerfile or compose file.
- Firewall rule open to the whole internet (Code Scan)0.0.0.0/0 ingress in generated Terraform or Kubernetes manifests.
- missing_lockfilepackage.json or pyproject without a committed lockfile, so installs are not reproducible.
- Credential hard-coded in source (Code Scan)A placeholder secret that was never replaced before deploy.
- CORS allows any origin (Code Scan)CORS opened to every origin in the generated API.
How to fix it in Claude Code
Run the scan, then paste this into Claude Code together with the Kavach report. It tells the assistant exactly what to do and what not to touch.
Act on the attached Kavach Code Scan report. For each finding: confirm it, fix it with the standard secure approach, and fix the same pattern elsewhere. Additionally: run containers as a non-root user without privileged mode; restrict any 0.0.0.0/0 rule to the ports actually served; commit lockfiles; replace placeholder secrets with environment variables and list the variables I must set. Do not change unrelated code.Re-scan when it is done. The grade and the findings list show whether the change took, and monitoring tells you if a later prompt reopens anything.
Questions about Claude Code security
Can I run Kavach from Claude Code directly?
Yes. The Kavach CLI and GitHub Action run the live-site audit from a terminal or CI and fail the build when the grade drops. Code Scan runs from the web page or the API.
Why does Kavach check Dockerfiles and Terraform?
Because agents generate them, and a privileged container or an open security group is as serious as an injection bug. The rules are language-aware across code and infrastructure files.
How is the remediation prompt different from the report?
The report is for you; the prompt is for the agent. It tells it to confirm each finding, apply the smallest safe fix, hunt the same pattern elsewhere, and list what you must configure.
Does a clean scan mean the app is secure?
No tool can promise that. A clean scan means the recognisable mistakes are absent. Review authorisation and business logic by hand and keep monitoring the live site.
Other platforms
Lovable · Bolt · v0 · Replit Agent · Cursor · Supabase · Firebase · Vibe coding security scanner
Kavach reports observations from read-only checks, not guarantees; see the disclaimer. Claude Code is a trademark of its owner; Kavach is not affiliated with it.