Episode Details

Back to Episodes
Claude Code Plugin Security: Fixing Shell Injection

Claude Code Plugin Security: Fixing Shell Injection

Episode 71 Published 2 months, 1 week ago
Description

This episode breaks down the breaking changes in Claude Code 2.1.207, including why raw template strings in custom hooks were removed and how shell-injection attacks can happen through plugin configs.

It also covers the safer migration paths with exec-form arrays and CLAUDE_PLUGIN_OPTION_ environment variables, plus the new decision to ignore local repository config files for plugin resolution.

Listen Now

Love PodBriefly?

If you like Podbriefly.com, please consider donating to support the ongoing development.

Support Us