Is My Claude Code App Secure? What Agents Quietly Skip

By Pouyan · Updated August 2026

I use Claude Code every day. I am not going to tell you to stop, and I would be a hypocrite if I did.

I want to talk about one thing only. You told the AI what you wanted, it worked for about forty minutes, it changed thirty-one files, and you read maybe four of them. Nobody reads thirty-one files at eleven at night when it all works. I do not either.

Here is the uncomfortable bit. Almost everything that goes wrong in apps built this way is sitting in plain sight in those files you did not read, and is completely invisible when you use the app. It works. It has always worked. Clicking around your own product tells you nothing at all.

What this actually looks like

Let me be specific, because I think people imagine hackers and clever tricks, and it is nothing like that.

Your app keeps its information in a database. Your website needs to reach that database, so it carries a key, and that key is inside the page your website sends to every single visitor. That part is normal and fine.

What is supposed to stop that key handing over everything is a rule saying who is allowed to read what. On a table your AI created, that rule is off unless somebody switched it on.

If it is off, then right now, from a phone, on the bus, a stranger can put one address into a browser and read your entire customer list. Names. Email addresses. Whatever else you collected. No password, no hacking, no skill. They ask, and your database answers, politely, the way it was built to.

I am not saying this is definitely happening to you. I am saying it is the single most common thing I find, it takes about a minute to exploit, and you would have no way of knowing.

Three things you can check yourself

All from your own browser. No code. About ten minutes for all three, and they cover most of what actually goes wrong.

Can strangers read your customer list?

Open your database dashboard. If you used Supabase, that is the Table Editor. Look down the list of tables for the word Unrestricted.

That word means there is no rule. Anyone can read it. If you see it next to a table holding anything about a person, stop reading this page and go and deal with it. The step by step is here.

Does your login actually keep people out?

There is a difference between hiding a door and locking it. AI is very good at hiding doors. If your app decides what to show by hiding buttons, then everything behind those buttons is still sitting there for anyone who knows the address.

Open a private browsing window. Do not sign in. Type in your dashboard or admin address directly. If it sends you to a login screen, good. If your information loads, the lock was painted on.

Can one customer read another customer's things?

Sign in as yourself and look at your web address while you are viewing something of yours. If there is a number in it, change it. Try a few.

You should see nothing, or an error. If you can see somebody else's details, then every one of your customers can read every other customer's details, and has been able to since the day you launched. This is the one I find most often after the database, and it is usually a small fix once somebody knows to look.

The one that caught me

There is a fourth thing, and it is the one I got wrong myself, so I will tell it properly.

When your app connects to something else, like Google or GitHub, it has to ask that service for permission. There is a wide version of that request and a narrow one. The wide one always works first time. The narrow one sometimes takes another go.

You can guess which one an AI picks when it is trying to make your feature work.

On a tool I built, mine was asking every person who signed up for full access to everything they had ever written. All of it. I never asked for that and I did not know it was happening. A developer signed up, saw the request, refused, and told me. He was being kind. Most people would have closed the tab, and I would have sat there wondering why nobody was signing up.

If your app connects to anything, go and read what it asks people for. Imagine a stranger's app asking you for that. Your users are being asked exactly that, and most of them are not reading it.

What I honestly cannot tell you from here

Those checks are worth doing and they catch most of it. But I would rather be straight with you about what a web page cannot do.

It cannot see the half of your app that sits behind the login, which is usually where the information worth stealing lives. And it cannot tell you whether a rule that exists is the rule you meant, which is a different question and a harder one.

For that, somebody has to actually sit down with it.

If you would rather not do this on your own

Send me the address of your app. I will go through it myself before we speak, then we take half an hour and I will tell you what I found in normal words, no jargon, no lecture.

It is free and there is nothing to buy at the end of it. And if your app turns out to be in good shape, I will tell you that and you will have lost half an hour, which is a perfectly good afternoon's work. It is more than I managed on my own.

You will not get told off for using AI to build it. I used it this morning.

Common questions

Is an app built with Claude Code safe?

It is as safe as what you asked for. The AI builds the thing you describe. It does not stop and say that you forgot to decide who is allowed to see your customers' details, and the app works perfectly either way, so you never find out by using it.

What goes wrong most often?

Somebody who is not you being able to read your customer list. That is the big one. After that: a login screen that looks like it protects things but does not, and your app asking your users for far more access to their accounts than it needs.

How do I check without being technical?

Three things you can do in about ten minutes, all from your own browser. Open your database dashboard and look for the word Unrestricted. Open your own site in a private window while signed out and try to reach your admin page. And change a number in your web address to somebody else's and see whether their information appears.

My app works fine. Doesn't that mean it's OK?

Unfortunately not, and this is the hard part to accept. An app where anyone can read everything and an app that is properly locked look exactly the same when you are the one using it. The difference only shows up when a stranger goes looking, and by then they have already looked.

Not sure if yours is affected?

Send me your app's address. I'll look at it myself before we speak, then we take half an hour and I'll tell you what I found in normal words. Free, no pitch, and if it's in good shape I'll tell you that too.

Would rather just talk? Book a call without filling this in. Bring your app's address and we'll look at it together.

Free · 30 minutes · no signup · no card

Pouyan Ahmadpour · engineer · Amsterdam

Keep reading