# Claude Code fake-secret access review

Review direct file, search and shell operations against the same harmless marker.

Synthetic canaries and blank observations. No current Claude Code or Aona behaviour has been tested here.

Source: https://aona.ai/resources/guides/claude-code-env-secrets-permissions/
Sources checked: 2026-09-21

| Fixture | Purpose | State |
| --- | --- | --- |
| allowed-marker.txt | Confirm the baseline can be read | Untested |
| env-canary.txt | Copy to .env.canary in the test folder | Synthetic only |
| operations.csv | Separate permission action and output | Blank observations |

## Review checklist

- [ ] Use a new folder with fake values only
  Do not point the exercise at a repository containing credentials or customer records.
- [ ] Identify the effective rules and sandbox
  Record their source, supported platform and mode before the first operation.
- [ ] Separate each operation and result
  Keep rule presence, approval decision and content returned in different columns.

## Included example files

- README.md
- allowed-marker.txt
- env-canary.txt
- operations.csv
- review-note.md
- claude-settings.fragment.json

## Source references

- Claude Code: Configure permissions: https://code.claude.com/docs/en/permissions (2026-09-21)
- Claude Code: Sandboxed Bash tool: https://code.claude.com/docs/en/sandboxing (2026-09-21)
- Claude Code: version-specific recursive-read report: https://github.com/anthropics/claude-code/issues/91690 (2026-09-21)
- Aona: AI security coverage: https://aona.ai/resources/ai-security-coverage/ (2026-09-21)

Use the worksheet within the relevant legal, contractual and technical scope. It is not a certification or a record of an installed-product test.
