S4E just found a high top 10 tcp port service scan
high·Misconfiguration·Updated Aug 13, 2026

Claude Code Scanner

This scanner detects the use of Claude Code Exposure in digital assets.

Est. Time~10 seconds
Scan TypeGroup Scan
Targetsurl
CostFree
2.6k
Times Used
continuous scan runs
3.4k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
Detail

Claude Code is a specialized software system utilized for task automation and AI delegation through subagents. It's primarily employed in IT environments where automating tasks is critical, often within organizations leveraging AI for productivity. These environments can range from small startups to large enterprises using AI-driven technologies. The software enables efficient management of AI functionalities such as tool permissions and internal system prompts. It's widely used by developers and IT admins to streamline AI tasks and manage AI-driven operations in their projects. This makes the security and privacy of Claude Code configurations paramount to protect against information leaks.

The vulnerability detected is the exposure of Claude Code subagent configuration files on web servers. This happens when these configuration files, located under `.claude/agents/`, become accessible over the web. The exposure can lead to information leakage of sensitive internal data, such as API endpoints and system prompts, which are essential for the proper functioning of AI subagents. The leaked information can include business logic and permissions that can be exploited if accessed by unauthorized entities. Such exposures compromise the confidentiality of internal processes and setup details.

The vulnerability arises from directory listings or direct access to markdown `.md` files, which form part of the Claude configuration under the `.claude/agents/` directory. These files often contain critical data about the AI setup, including agent names and descriptions, which should remain protected. The vulnerability is typically found when directory listing is enabled on web servers, allowing access to agent files. This can occur due to misconfigured server settings or lack of proper access controls on folders. Identifying this exposure is crucial to maintaining the security and integrity of AI functionalities.

If malicious actors exploit this exposure, they can gain insights into the internal configurations of AI subagents. This may allow unauthorized access to API endpoints or manipulation of AI tasks through exposed system prompts. Such vulnerabilities can lead to unauthorized execution of commands, data leaks, and potentially damaging automation actions within the organization. The exploitation can also result in resource misuse and possible disruption of services operated by AI subagents.

REFERENCES

Solution Advice
  • Ensure that the web server directories where Claude Code configurations are stored are not publicly accessible.
  • Implement proper access control measures to restrict access to sensitive configuration files.
  • Disable directory listing on web servers hosting Claude Code configurations to prevent unauthorized access.
  • Regularly review and audit server permissions and settings to detect any inadvertent exposure of sensitive files.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

Claude Code Exposure Scanner S4E