Episode Details
Back to Episodes
Claude Code Plugin Security: Fixing Shell Injection
Episode 71
Published 2 months, 1 week ago
Description
This episode breaks down the breaking changes in Claude Code 2.1.207, including why raw template strings in custom hooks were removed and how shell-injection attacks can happen through plugin configs.
It also covers the safer migration paths with exec-form arrays and CLAUDE_PLUGIN_OPTION_ environment variables, plus the new decision to ignore local repository config files for plugin resolution.