SecretSpec claims Claude Code stores reusable OAuth tokens in plaintext on disk, creating a credential-theft risk that may require keychain storage or stronger host isolation.
state: expiredheat: lowuncertainty: highconvergesscott: mediumagentic-security coding-agents credential-securitySecretSpecAnthropic
What is this?
Security reports claim Claude Code stores OAuth credentials in plaintext JSON files on Linux and Windows, while using the macOS Keychain in a way that may still allow other same-user processes to retrieve them. Stolen bearer tokens could let an attacker act with the user’s connected-tool permissions and potentially bypass MFA. The supplied snippets corroborate the underlying storage risk, but do not establish SecretSpec’s identity, original report, or Anthropic’s current remediation status.
Why it matters to Scott
The claimed Claude Code weakness converges with SiloOS’s credential-separated containment model and Scott’s practical use of OAuth vaulting and sandboxing to deny agents ambient host credentials. It could inform how he deploys coding agents and provides a dated-receipts opportunity, but the report’s provenance and Anthropic’s remediation status remain unestablished.
ip:framework.siloosdev:project.nangodev:technology.bubblewrapradar:concept.credential-isolationradar:concept.coding-agent-securityradar:electron-data-protection-keychain
queries asked of Scott's wikis
- coding-agent credential threat models
- OAuth bearer-token storage and rotation
- OS keychains versus host isolation
- MCP credential boundaries and plugin isolation
- agent secrets least-privilege architecture
- developer-agent sandboxing and process trust
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (2) — ⭐ canonical anchor
Interpretation history
2026-09-05T03:22:37Z
The 48-hour stale check brings no substantive follow-up to the echoed allegation, and no confirming event is expected. Retire this episode as unresolved—not disproved; reproduction showing affected versions, credential access boundaries and token reuse would warrant reopening.
2026-09-03T02:38:09Z
No independent reproduction, technical detail, affected-version evidence, or Anthropic response has appeared; the minor engagement change adds no substance, so this remains an uncorroborated allegation and can cool.
2026-09-03T02:28:46Z
grounded: converges/medium — The claimed Claude Code weakness converges with SiloOS’s credential-separated containment model and Scott’s practical use of OAuth vaulting and sandboxing to de
2026-09-03T02:26:58Z
case created — This is a specific, consequential credential-handling allegation about a widely deployed coding agent.
Decision trace
- 09-05 13:22expireThe 48-hour stale check brings no substantive follow-up to the echoed allegation, and no confirming event is expected. Retire this episode as unresolved—not disproved; reproduction showing affected ve
- 09-05 13:22alert_silentThere is no new consequential delta. The supplied evidence still lacks enough technical detail or independently established source standing to justify an actionable security alert; the hot surrounding
- 09-05 13:22alert_routeThere is no new consequential delta. The supplied evidence still lacks enough technical detail or independently established source standing to justify an actionable security alert; the hot surrounding
- 09-03 12:38repriceNo independent reproduction, technical detail, affected-version evidence, or Anthropic response has appeared; the minor engagement change adds no substance, so this remains an uncorroborated allegatio
- 09-03 12:38alert_silentThe new delta is only negligible engagement on unchanged evidence. It can wait unless reproduction steps, token scope and reuse evidence, or an Anthropic remediation statement emerges.
- 09-03 12:38alert_routeThe new delta is only negligible engagement on unchanged evidence. It can wait unless reproduction steps, token scope and reuse evidence, or an Anthropic remediation statement emerges.
- 09-03 12:36alert_silentThe supplied evidence establishes only that SecretSpec published the claim; it does not provide the token location, file permissions, token scope or reusability, affected versions, reproduction steps,
- 09-03 12:36surface_candidateThe supplied evidence establishes only that SecretSpec published the claim; it does not provide the token location, file permissions, token scope or reusability, affected versions, reproduction steps,
- 09-03 12:36alert_routeThe supplied evidence establishes only that SecretSpec published the claim; it does not provide the token location, file permissions, token scope or reusability, affected versions, reproduction steps,
- 09-03 12:28groundThe claimed Claude Code weakness converges with SiloOS’s credential-separated containment model and Scott’s practical use of OAuth vaulting and sandboxing to deny agents ambient host credentials. It c
- 09-03 12:26createThis is a specific, consequential credential-handling allegation about a widely deployed coding agent.