From the Inside Claude Code: The Claude Code Ecosystem architecture map

Command-line construction is hardened against argument injection

strength · low · verified

The transport passes resume, session_id, resume_session_at and resume_drops_turn as --flag=value so a dash-leading value cannot become a new flag, applies the same rule to extra_args, refuses .bat/.cmd CLIs on Windows (the BatBadBut class, CVE-2024-27980), rejects cmd.exe metacharacters in session values, and validates skill names before formatting them into --allowedTools rules.

Session titles and IDs are often taken from end users, so these guards are what keeps a hostile resume value from rewriting the CLI's permission flags. New options that take untrusted strings should use the same equals form.

The trail

  1. Subprocess CLI Transport
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com