From the Inside Claude Code: The Claude Code Ecosystem architecture map

Tag mode gives Claude a narrow, workspace-bound tool list

strength · low · verified

prepareTagMode allows only comment updates, git add, commit and rm, a push wrapper, and the GitHub MCP tools the installer registers. Edits run under acceptEdits, which allows files inside the workspace only, and there is no general Bash.

Impact: A prompt-injected run is limited to its own branch and Claude's own comments.

User-supplied claude_args can widen this list, so the narrow default holds only for workflows that do not pass extra allowedTools.

The trail

  1. Tag Mode
  2. MCP Config Installer
  3. GitHub Comment Server
Open on the map

More from this board

© 2026 Syntaxia App Platform Ltd.

Syntaxia App Platform Ltd. Registered in England and Wales, company no. 15272701 Registered office: 3rd Floor, 86–90 Paul Street, London EC2A 4NE, United Kingdom contact@provenmap.com