Vibe CodingBackslash Security: Definitive Claude Code Hardening GuideBackslash Security·high signalXBlueskyLinkedInCopy linkFour threat categories, managed-settings.json config, three-tier permission model, MCP allowlistsSourceSource pageBackslash Security↳ Follow the threadShared entity / Stack layerClaude Code 2.1.269 Ships a Plugin Eval Runner and a Knob to Raise the Workflow Tool's Concurrent Agent Cap to 256Anthropic (claude-code CHANGELOG)Shared entity / Stack layerCline Ships a Desktop App for Open-Weight Models and Sells Ten of Them From Six Labs for $9.99 FlatCline (corroborated by the Product Hunt leaderboard for 2026-09-11, the GitHub API and newreleases.io for desktop-v0.0.25)Shared entity / Stack layerECC 2.2.1 packages a full agent harness discipline as 68 subagents and 292 skillsGitHubShared entity / Stack layerClaude Code 2.1.268 syncs gateway pricing to clients, caps hung WebFetch at 300 seconds, and adds --json to plugin commandsClaude Code changelog (v2.1.268, Sep 10 2026)Shared entity / Stack layerTip: a plugin eval suite that grants Bash needs bubblewrap and socat on Linux, or WSL2 on WindowsClaude Code DocsShared entity / Stack layerClaude Code 2.1.269 closes three permission-rule escapes: `!` negation scope, Bash `tee` writes, and world-readable plugin archivesClaude Code changelog (v2.1.269, Sep 11 2026)Shared entity / Stack layerClaude Code 2.1.268 fixes deny rules that a symlinked path or an env -C prefix could slip pastGitHubShared entity / Stack layerArize Phoenix ships Claude Code, Codex and Cursor plugins plus an MCP skills root in two releases a day apartGitHub