AI News DailyTips한국어RSS
← AI tool tips
Claude Code✓ Confirmed in official docsOct 8

Session logs keep your prompts and file contents in full; if a machine was ever exposed, run claude purge

The hacker behind the Korean bank breaches, described in CrowdStrike's October 8 report, had directory listing enabled on his own server. Researchers found his CLAUDE.md and Claude Code session logs there and read what he had asked Claude. It happened to a criminal, but the mechanics apply to everyone.

Claude Code stores whole conversations as .jsonl under ~/.claude/projects/: prompts, the contents of files it read, commands and their output. Subagent transcripts sit next to them under subagents/.

  • If you ran Claude Code on a shared server or CI machine, purge that project's state. It removes the transcripts and auto memory under projects/, per-session tasks, debug and file-history entries, and the matching lines in history.jsonl, and it shows the plan and asks before deleting (this name since v2.1.288).
claude purge ~/work/my-repo --dry-run   # see what would go first
claude purge ~/work/my-repo

Pasted images live in the temp directory, so this command doesn't remove them.

  • Logs are kept for 30 days by default. Shorten it in settings.
// ~/.claude/settings.json
{ "cleanupPeriodDays": 7 }
  • Never put .claude/ or CLAUDE.md under a web server's public path, and turn directory listing (autoindex) off.

Get notified when a new tip lands

Tip alerts only go out in the app. Install it and turn notifications on.

Get the app

All tips →