2026-10-11 17:11 UTC

SecretSpec claims Claude Code stores reusable OAuth tokens in plaintext on disk, creating a credential-theft risk that may require keychain storage or stronger host isolation.

state: expiredheat: lowuncertainty: highconvergesscott: mediumagentic-security coding-agents credential-securitySecretSpecAnthropic

What is this?

Security reports claim Claude Code stores OAuth credentials in plaintext JSON files on Linux and Windows, while using the macOS Keychain in a way that may still allow other same-user processes to retrieve them. Stolen bearer tokens could let an attacker act with the user’s connected-tool permissions and potentially bypass MFA. The supplied snippets corroborate the underlying storage risk, but do not establish SecretSpec’s identity, original report, or Anthropic’s current remediation status.

Why it matters to Scott

The claimed Claude Code weakness converges with SiloOS’s credential-separated containment model and Scott’s practical use of OAuth vaulting and sandboxing to deny agents ambient host credentials. It could inform how he deploys coding agents and provides a dated-receipts opportunity, but the report’s provenance and Anthropic’s remediation status remain unestablished.
ip:framework.siloosdev:project.nangodev:technology.bubblewrapradar:concept.credential-isolationradar:concept.coding-agent-securityradar:electron-data-protection-keychain
queries asked of Scott's wikis
  • coding-agent credential threat models
  • OAuth bearer-token storage and rotation
  • OS keychains versus host isolation
  • MCP credential boundaries and plugin isolation
  • agent secrets least-privilege architecture
  • developer-agent sandboxing and process trust

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (2) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnClaude Code Stores OAuth Tokens in Plaintextdomenkozar20
🟧 echo.blog ⭐Claude Code stores OAuth tokens in plaintext, according to SecretSpec's security report.SecretSpec——

Interpretation history

Decision trace