deny-probe tests Claude Code deny rules: 10 of 12 bypass routes leak data
A new Python CLI called deny-probe audits permissions.deny rules in Claude Code against 12 built-in bypass routes. With a typical single Read(./.env) rule, 10 of 12 routes still expose the file, including Grep, Bash and CLAUDE.md @import chains.
- Tool checks 12 bypass routes as concrete (tool, argument) pairs
- With one Read(./.env) rule only 1 of 12 routes is blocked
- Grep(path="./.env", pattern=".") returns the whole file, bypassing Read
- A --live mode uses a canary marker and real claude -p sessions
Read next
Security