Disclosure summary
Cantina identified and human-verified this vulnerability in Claude Code. The finding was coordinated with the affected maintainer through responsible disclosure before publication.
Repository settings can skip the workspace trust prompt.
Verification standard
Cantina publishes a disclosure only after reproducing the behavior, validating its security impact, and coordinating remediation with the affected project.