Kavach

AI platforms · AI coding agent (terminal)

Is my Claude Code app secure?

Agents such as Claude Code write whole services, including the infrastructure files. That is where new kinds of slips appear: privileged containers, firewall rules open to the world, and dependency manifests without a lockfile, alongside the usual injection patterns.

Audit my Claude Code app free → Scan the code too

What Claude Code usually leaves open

Typical stack: Any stack; agents tend to produce complete back ends, Dockerfiles and CI configs.

How to fix it in Claude Code

Run the scan, then paste this into Claude Code together with the Kavach report. It tells the assistant exactly what to do and what not to touch.

Paste into Claude Code
Act on the attached Kavach Code Scan report. For each finding: confirm it, fix it with the standard secure approach, and fix the same pattern elsewhere. Additionally: run containers as a non-root user without privileged mode; restrict any 0.0.0.0/0 rule to the ports actually served; commit lockfiles; replace placeholder secrets with environment variables and list the variables I must set. Do not change unrelated code.

Re-scan when it is done. The grade and the findings list show whether the change took, and monitoring tells you if a later prompt reopens anything.

Questions about Claude Code security

Can I run Kavach from Claude Code directly?

Yes. The Kavach CLI and GitHub Action run the live-site audit from a terminal or CI and fail the build when the grade drops. Code Scan runs from the web page or the API.

Why does Kavach check Dockerfiles and Terraform?

Because agents generate them, and a privileged container or an open security group is as serious as an injection bug. The rules are language-aware across code and infrastructure files.

How is the remediation prompt different from the report?

The report is for you; the prompt is for the agent. It tells it to confirm each finding, apply the smallest safe fix, hunt the same pattern elsewhere, and list what you must configure.

Does a clean scan mean the app is secure?

No tool can promise that. A clean scan means the recognisable mistakes are absent. Review authorisation and business logic by hand and keep monitoring the live site.

Other platforms

Lovable · Bolt · v0 · Replit Agent · Cursor · Supabase · Firebase · Vibe coding security scanner

Kavach reports observations from read-only checks, not guarantees; see the disclaimer. Claude Code is a trademark of its owner; Kavach is not affiliated with it.