Guides

Guides to AI coding agent security

Walk-throughs for the agent on your own machine: what Claude Code writes to disk, what it can read, how to check what it ran, and how to cut what its tokens allow. Each guide is checked against the vendors' own documentation and lists its sources at the end.

01 / Start here

Start with the checklist.

The other guides go deeper on one item each. This one puts them in order.

AI coding agent security: a checklist for your own machine

What a coding agent can reach, the boundary to put around it, what it writes to disk, how to check what it already ran, and how to scope the tokens it holds. Fourteen steps, in the order worth doing them.

02 / Claude Code

What Claude Code keeps, reads and runs.

Claude Code writes every session to a plaintext transcript under ~/.claude/projects. These four guides cover what is in those files and what to do about it.

Where Claude Code keeps your conversation history

Where the transcripts are, what they hold, why they are deleted after 30 days by default, how to change that, and how to purge a project.

How to stop Claude Code reading your .env file

A Read deny rule stops cat and Claude's file tools, not grep -r or a Python script. The sandbox closes that gap. If it already read the file, rotate first.

A Claude Code audit log from what is already on disk

Read back the tool calls in the transcripts you already have, then keep a record from now on with a hook or OpenTelemetry.

Claude Code deleted my files. What now?

Rewind does not restore files a Bash command removed. Find what was deleted and when, restore from git or a backup, and block a repeat.

03 / Tokens

What an agent's tokens allow.

Permission prompts decide which commands run. The token decides what a command can do once it reaches the provider.

Check what the tokens your AI agent holds can do

Check what GitHub, Google, Slack, Stripe and AWS credentials allow with each provider's own tools, see which grants were ever used, then cut them down.

04 / Check now

Or check your own machine now.

One read-only pass over your Claude Code history: the risky actions the agent took, and the credentials left in its transcripts. It changes nothing.

$ uvx ranwhat check
Install

check runs two commands together: ranwhat watch for what your agents ran, and ranwhat clean for secrets in Claude Code transcripts. ranwhat scan is separate, and scores what their credentials allow.