When "Do Not" Is Not Deny: Security Rules in CLAUDE.md vs Built-In Controls
The paper compares natural-language safety rules written in CLAUDE.md files against Claude Code's built-in enforcement mechanisms, finding a significant gap between instructional constraints and executable controls. By analyzing 481 public files and validating findings through security practitioner review, the authors quantify how many stated security goals lack corresponding technical enforcement.
Why this matters
The paper compares natural-language safety rules written in CLAUDE.md files against Claude Code's built-in enforcement mechanisms, finding a significant gap between instructional constraints and executable controls. By analyzing 481 public files and validating findings through security practitioner review, the authors quantify how many stated security goals lack corresponding technical enforcement.
Check the original work
This explanation is Korpalis’s guide to the material, not a replacement for it. Read the publisher’s page for the full method, evidence and limitations.