html injection testing
zebbern/claude-code-guide · skills.sh
Open source Repository Open in the app JSON README (API)
About
Skill publicada por zebbern/claude-code-guide no skills.sh. Instale com: npx skills add zebbern/claude-code-guide@html-injection-testing
Details
- Kind
- Agent skills
- Topic
- Developer tools
- Publisher
- zebbern
- Origin
- skillssh
- Category
- ferramentas
- Stars
- 4,649
- Forks
- 470
- Open pull requests
- 1
- Last push
- 2026-10-07T01:04:51Z
- Repository state
- ativo
- Language
- Python
- License
- MIT
- Added
- 2026-10-07 05:30:51
- Updated
- 2026-10-07 05:30:51
- Origin id
zebbern/claude-code-guide/html-injection-testing
README
<div align="center">
<h2 id="claude-code-community-guide">Claude Code Guide</h2>
_For reference and contributions, visit the [official Claude Code documentation](https://code.claude.com/docs/en/overview)_
_Commands and provider model mappings change quickly; the linked official references remain authoritative._

[](https://github.com/anthropics/claude-code)
[](LICENSE)
</div>
<div align="center">
<kbd>
| Section | Status | Other Resources |
| ------------------------------------- | ------ | ------------------------------------------------------------------------------------------------------- |
| Getting Started | ✅ | **Claude-Code** [Docs](https://code.claude.com/docs/en/overview) |
| Configuration & Environment Variables | ✅ | **Claude-Code via** [**Discord**](https://github.com/zebbern/claude-code-discord) |
| Commands & Usage | ✅ | Security Agents [SKILL.md](https://github.com/zebbern/claude-code-guide/tree/main/skills) |
| Interface & Input | ✅ | Let Agent Create [SKILL.md](https://github.com/zebbern/agent-skills-authoring) |
| Advanced Features | ✅ | 954+ Agent [Skills](https://github.com/zebbern/antigravity-awesome-skills) |
| Automation & Integration | ✅ | No cost ai [resources](https://github.com/zebbern/no-cost-ai) |
| Help & Troubleshooting | ✅ | 250+ Mermaid [templates](https://github.com/zebbern/mermaid-templates) |
| Third-Party Integrations | ✅ | Discord Communication [MCP](https://github.com/zebbern/discord-mcp-agent) |
</kbd>
</div>
---
<h3 id="content">Contents</h3>
**Fast paths:** [Install](#quick-start) · [Commands](#claude-commands) · [Config](#configuration--environment) · [MCP](#mcp-integration) · [Agents](#sub-agents) · [Troubleshoot](#help--troubleshooting)
| Area | Start here | Also useful |
| --- | --- | --- |
| [Getting Started](#getting-started) | [Quick Start](#quick-start) | [Initial Setup](#initial-setup), [System Requirements](#system-requirements) |
| [Configuration](#configuration--environment) | [Environment Variables](#environment-variables) | [Configuration Files](#configuration-files) |
| [Commands](#commands--usage) | [Slash Commands](#claude-commands) | [CLI Quick Reference](#cheat-sheet) |
| [Interface](#interface--input) | [Keyboard Shortcuts](#keyboard-shortcuts) | [Vim Mode](#vim-mode) |
| [Advanced Features](#advanced-features) | [Plan Mode](#plan-mode), [Auto Mode](#auto-mode), [MCP](#mcp-integration) | [Sub Agents](#sub-agents), [Skills](#skills), [Hooks](#hooks-system) |
| [Security](#security--permissions) | [Security & Permissions](#security--permissions) | [Dangerous Mode](#dangerous-mode), [Best Practices](#security-best-practices-main) |
| [Automation](#automation--integration) | [Automation & Scripting](#automation--scripting-with-claude-code) | [PR Review](#auto-pr-review-inline-comments), [Issue Triage](#issue-triage-suggest-labels--severity) |
| [Help](#help--troubleshooting) | [Troubleshooting](#help--troubleshooting) | [Best Practices](#best-practices), [Monitoring](#monitoring--alerting) |
| [Third-Party Integrations](#third-party-integrations) | [DeepSeek Integration](#deepseek-integration) | [Provider Setup Examples](#provider-setup-examples) |
<details>
<summary>Full content map</summary>
- **[Getting Started](#getting-started)**
- [Quick Start](#quick-start)
- [System Requirements](#system-requirements)
- [Initial Setup](#initial-setup)
- **[Configuration & Environment](#configuration--environment)**
- [Environment Variables](#environment-variables)
- [Configuration Files](#configuration-files)
- **[Commands & Usage](#commands--usage)**
- [Slash Command Reference](#claude-commands)
- [CLI Quick Reference](#cheat-sheet)
- **[Interface & Input](#interface--input)**
- [Keyboard Shortcuts](#keyboard-shortcuts)
- [Vim Mode](#vim-mode)
- **[Advanced Features](#advanced-features)**
- [Thinking Mode](#thinking-keywords)
- [Effort Levels](#effort-levels)
- [Advisor Tool](#advisor-tool)
- [Fast Mode](#fast-mode)
- [Auto Mode](#auto-mode)
- [Plan Mode](#plan-mode)
- [Background Tasks](#background-tasks)
- [Workflows & Scheduling](#workflows--scheduling)
- [Remote Sessions](#remote-sessions)
- [Claude in Chrome](#claude-in-chrome)
- [Desktop and IDEs](#desktop-and-ides)
- [Sandbox Mode](#sandbox-mode)
- [LSP Tool](#lsp-tool)
- [Sub Agents](#sub-agents)
- [Agent Teams](#agent-teams)
- [Skills](#skills)
- [Plugin System](#plugin-system)
- [Worktree Isolation](#worktree-isolation)
- [Native Installer](#native-installer)
- [Authentication CLI](#claude-auth)
- [Agent Management CLI](#claude-agents-cli)
- [Remote Control](#remote-control)
- [Managed Settings](#managed-settings)
- [Model Updates](#model-updates)
- [Theming & Customization](#theming--customization)
- [Code Review](#code-review)
- [Insights](#insights)
- [MCP Integration](#mcp-integration)
- [Hooks System](#hooks-system)
- **[Security & Permissions](#security--permissions)**
- [Dangerous Mode](#dangerous-mode)
- [Security Best Practices](#security-best-practices-main)
- **[Automation & Integration](#automation--integration)**
- [Automation & Scripting](#automation--scripting-with-claude-code)
- [Auto PR Review](#auto-pr-review-inline-comments)
- [Issue Triage](#issue-triage-suggest-labels--severity)
- **[Help & Troubleshooting](#help--troubleshooting)**
- [Installation Issues](#installation--nodejs-issues)
- [MCP Issues](#mcp-model-context-protocol-issues)
- [Best Practices](#best-practices)
- [Monitoring & Alerting](#monitoring--alerting)
- **[Third-Party Integrations](#third-party-integrations)**
- [Provider Setup Examples](#provider-setup-examples)
- [DeepSeek Integration](#deepseek-integration)
</details>
---
<h1 id="getting-started">Getting Started</h1>
**Enable completion alerts:** run `/config` inside Claude Code and choose a notification channel such as **Terminal bell**.
<h2 id="quick-start">Quick Start</h2>
> [!TIP]
> **Run <mark>claude</mark> in a project directory to start the interface.**
>
> **Go to [Help & Troubleshooting](#help--troubleshooting) to fix issues...**
**Native installer (recommended; no Node.js required)**
macOS, Linux, or WSL:
```bash
curl -fsSL https://claude.ai/install.sh | bash
```
Windows PowerShell:
```powershell
irm https://claude.ai/install.ps1 | iex
```
Windows CMD:
```bat
curl -fsSL https://claude.ai/install.cmd -o install.cmd && install.cmd && del install.cmd
```
Supported package managers (manual updates by default):
```bash
brew install --cask claude-code
winget install Anthropic.ClaudeCode
```
npm distribution (supported; Node.js 22+ is required to install):
```bash
npm install -g @anthropic-ai/claude-code
```
Verify the installation, then start Claude Code:
```bash
claude --version
claude doctor
claude
```
Native installs update themselves. Homebrew, WinGet, and the signed `apt`, `dnf`, and `apk` repositories follow their package manager's update flow. See the [official setup guide](https://code.claude.com/docs/en/setup) for channels, version pinning, Linux repository setup, and signature verification. For an npm install, upgrade with `npm install -g @anthropic-ai/claude-code@latest`; do not use `sudo npm install -g`.
---
> [!Tip]
> <ins>**Open Project Via Terminal Into VS Code / Cursor**</ins>
>
> ### $ - <kbd>cd /path/to/project</kbd>
>
> ### $ - <kbd>code .</kbd>
>
> **Make sure you have the <mark>(Claude Code extension)</mark> installed in your VS Code / Cursor**
---
<h2 id="system-requirements">System Requirements</h2>
> - OS: macOS 13+, Windows 10 1809+/Windows Server 2019+, Ubuntu 20.04+, Debian 10+, or Alpine Linux 3.19+. Native Windows, WSL 1, and WSL 2 are supported.
> - Hardware: 4 GB+ RAM and an x64 or ARM64 processor
> - Software: Git is optional on native Windows; without Git for Windows, Claude uses the PowerShell tool instead of Bash. Node.js 22+ is required only to install through npm; the installed CLI is a native binary.
> - Internet: Connection for API calls
---
<h2 id="initial-setup">Initial Setup</h2>
Claude Code requires a Pro, Max, Team, Enterprise, or Console account; the free Claude.ai plan does not include Claude Code. The normal first-party flow is browser sign-in:
```bash
claude auth login # Claude subscription
claude auth login --console # Anthropic Console/API billing
claude auth status # Verify the active login
```
For API automation or a provider/gateway deployment, inject credentials from an OS key store or secret manager instead of committing them:
```bash
export ANTHROPIC_API_KEY="$SECRET_FROM_YOUR_STORE" # bash/zsh: current process only
```
```powershell
$env:ANTHROPIC_API_KEY = $secretFromYourStore # PowerShell: current process only
```
> [!Important]
> A persistent `ANTHROPIC_API_KEY`, `ANTHROPIC_AUTH_TOKEN`, or credential helper selects API/provider authentication even if you are logged in. Subscription-only features such as Remote Control, cloud sessions, claude.ai MCP connectors, and notification preferences then remain unavailable. Do not commit credentials; use your platform's secret storage.
---
<h1 id="configuration--environment">Configuration & Environment</h1>
<h2 id="environment-variables">Environment Variables</h2>
> **Environment values can also be stored as strings under the `env` key in a `settings.json` file. The [official environment-variable reference](https://code.claude.com/docs/en/env-vars) is the exhaustive source.**
> [!Important]
> **On PowerShell, use `$env:NAME = "value"` for the current process. Persist secrets through an OS key store or secret manager, not a checked-in settings file.**
```bash
# Authentication and routing: set only when API/provider billing is intentional
export ANTHROPIC_API_KEY="$SECRET_FROM_YOUR_STORE"
export ANTHROPIC_AUTH_TOKEN="$TOKEN_FROM_YOUR_STORE"
export ANTHROPIC_BASE_URL="https://gateway.example.com"
export ANTHROPIC_CUSTOM_HEADERS="X-Trace-Id: 12345"
# Model selection and provider alias overrides
export ANTHROPIC_MODEL="sonnet"
export ANTHROPIC_DEFAULT_FABLE_MODEL="<provider-fable-model-id>"
export ANTHROPIC_DEFAULT_OPUS_MODEL="<provider-opus-model-id>"
export ANTHROPIC_DEFAULT_SONNET_MODEL="<provider-sonnet-model-id>"
export ANTHROPIC_DEFAULT_HAIKU_MODEL="<provider-haiku-model-id>"
# Third-party provider selection (enable only one deployment path)
# export CLAUDE_CODE_USE_BEDROCK=1
# export ANTHROPIC_BEDROCK_REGION_PREFIX=eu # Prefer eu/us/apac/jp/au/global cross-region inference on Bedrock
# export CLAUDE_CODE_USE_VERTEX=1
# export CLAUDE_CODE_USE_FOUNDRY=1
# Timeouts and output budgets, in milliseconds/tokens
export API_TIMEOUT_MS=1200000
export BASH_DEFAULT_TIMEOUT_MS=120000
export BASH_MAX_TIMEOUT_MS=600000
export MCP_TIMEOUT=30000
export MCP_TOOL_TIMEOUT=60000
export MAX_MCP_OUTPUT_TOKENS=25000
export MAX_THINKING_TOKENS=0 # 0 disables fixed thinking where supported; positive values set a budget
# Session, context, agents, and accessibility
# export CLAUDE_CODE_SIMPLE=1
# export CLAUDE_CODE_SAFE_MODE=1
export CLAUDE_CODE_DISABLE_1M_CONTEXT=1 # Clamp native-1M models to 200K via autocompaction; warns if the clamp is not enforced
export CLAUDE_CODE_DISABLE_UNKNOWN_MODEL_WINDOW_ENFORCEMENT=1 # Opt out of enforcing the assumed context window for unknown model IDs
export CLAUDE_CODE_MAX_CONCURRENT_SUBAGENTS=20
export CLAUDE_CODE_MAX_SUBAGENT_SPAWN_DEPTH=3
export CLAUDE_CODE_FORWARD_SUBAGENT_TEXT=1
export CLAUDE_AX_SCREEN_READER=1
# Feature and administration controls
export CLAUDE_CODE_EXPERIMENTAL_AGENT_TEAMS=1
export CLAUDE_CODE_ADDITIONAL_DIRECTORIES_CLAUDE_MD=1
export CLAUDE_CODE_ENABLE_GATEWAY_MODEL_DISCOVERY=1
export CLAUDE_CODE_PACKAGE_MANAGER_AUTO_UPDATE=1
export ENABLE_CLAUDEAI_MCP_SERVERS=false
# Network routing
export HTTP_PROXY="http://proxy.example.com:8080"
export HTTPS_PROXY="http://proxy.example.com:8080"
export NO_PROXY="localhost,127.0.0.1"
# Privacy/network reduction: these are presence-based; unset them to turn them off
export CLAUDE_CODE_DISABLE_NONESSENTIAL_TRAFFIC=1
export DISABLE_TELEMETRY=1
export DISABLE_ERROR_REPORTING=1
```
The block is a catalog, not a recommended profile—do not enable mutually exclusive provider variables together. Boolean variables usually accept `1`/`true` and `0`/`false`, but the three presence-based variables shown at the end treat any non-empty value, including `0`, as enabled. Environment values in `settings.json` override the shell value at startup and when the file changes.
<h2 id="global-config-options">Global Config Options</h2>
Use `/config` for interactive settings, or pass one or more `key=value` pairs. Run `/config --help` for the keys supported by your installed build.
```bash
/config # Open the settings UI
/config theme=dark model=sonnet # Update supported keys directly
```
For version-controlled or managed configuration, edit JSON settings files directly:
| Scope | File |
| :---- | :--- |
| User | `~/.claude/settings.json` |
| Project (shared) | `.claude/settings.json` |
| Project (private) | `.claude/settings.local.json` |
| Managed | macOS: `/Library/Application Support/ClaudeCode/`<br />Linux/WSL: `/etc/claude-code/`<br />Windows: `C:\Program Files\ClaudeCode\` |
```json
{
"model": "sonnet",
"theme": "dark",
"autoUpdatesChannel": "stable",
"permissions": {
"defaultMode": "default"
}
}
```
Settings precedence is **managed policy → CLI arguments/`--settings` → local → project → user**. Permission arrays have their own merge rules, so read the [settings reference](https://code.claude.com/docs/en/settings) before relying on ordinary last-writer-wins behavior. `~/.claude.json` stores global state, session/trust data, and local/user MCP configuration; it is not the user settings file.
<h2 id="configuration-files">Configuration Files</h2>
Claude Code combines human-authored instructions from several locations:
| Memory Type | Location | Purpose | Use Case Examples | Shared With |
| -------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------- | -------------------------------------------------------------------- | ------------------------------- |
| **Enterprise policy** | macOS: `/Library/Application Support/ClaudeCode/CLAUDE.md`<br />Linux: `/etc/claude-code/CLAUDE.md`<br />Windows: `C:\Program Files\ClaudeCode\CLAUDE.md` | Organization-wide instructions managed by IT/DevOps | Company coding standards, security policies, compliance requirements | All users in organization |
| **Project memory** | `./CLAUDE.md` or `./.claude/CLAUDE.md` | Team-shared instructions for the project | Project architecture, coding standards, common workflows | Team members via source control |
| **User memory** | `~/.claude/CLAUDE.md` | Personal preferences for all projects | Code styling preferences, personal tooling shortcuts | Just you (all projects) |
| **Project memory (local)** | `./CLAUDE.local.md` | Personal project-specific preferences (git-ignored) | Your sandbox URLs, preferred test data, personal overrides | Just you (current project) |
| **Project rules** | `.claude/rules/**/*.md` | Modular project rules (loaded alongside CLAUDE.md) | Linting rules, API conventions, path-scoped standards | Team members via source control |
> Instruction files are concatenated rather than overriding one another. User and ancestor-project files load at startup; `CLAUDE.md` files in subdirectories load lazily when Claude works there. `CLAUDE.md` is context, not an enforcement boundary.
Use `@path` to import another file. Claude Code does not load `AGENTS.md` automatically; add `@AGENTS.md` to `CLAUDE.md` (or use a symlink where portable) when you want to share those instructions.
#### `.claude/rules/` Directory
The `.claude/rules/` directory lets you break project instructions into separate Markdown files instead of one large `CLAUDE.md`. Markdown files are discovered recursively. Add `paths` frontmatter with glob patterns when a rule should load only for matching files. This is useful for:
- **Modular organization**: Separate concerns (e.g., `api-conventions.md`, `testing-rules.md`)
- **Per-directory overrides**: Nested `rules/` directories can apply scoped rules
- **Team collaboration**: Different team members can own different rule files via PR review
#### Auto-Memory
Claude can save useful working context under `~/.claude/projects/<project>/memory/`. It loads the first 200 lines or 25 KB of `MEMORY.md`; use `/memory` to inspect, edit, disable, or remove saved memories. Auto-memory is machine-local and shared across worktrees for the same repository.
Auto-memory is most useful for context you would otherwise repeat across sessions:
- Preferred build, test, and lint commands
- Local conventions that are not obvious from code alone
- Architecture decisions that influence future edits
- Team preferences that should shape how Claude proposes changes
Keep durable team rules in `CLAUDE.md` or `.claude/rules/`. Treat auto-memory as helpful working context, not as the only source of truth.
---
<h1 id="commands--usage">Commands & Usage</h1>
<h2 id="claude-commands">Slash Command Reference</h2>
Type `/` to see what your installed build, plan, platform, plugins, MCP servers, and skills actually provide. The table below is a high-value snapshot; use the [official command reference](https://code.claude.com/docs/en/commands) for the live list.
| Command | Purpose |
| :------ | :------ |
| `/add-dir <path>` | Grant this session access to another working directory |
| `/advisor [model\|off]` | Configure the experimental second-model advisor, save the selection, or turn it off |
| `/agents` | Explain how to create or edit subagents; the old interactive agent wizard was removed in v2.1.198 |
| `/background [prompt]` | Detach the current conversation as a background session (`/bg` alias) |
| `/batch <instruction>` | Decompose a large change into worktree-isolated background units (bundled skill) |
| `/branch [name]` | Switch into a new branch of the current conversation while preserving the original |
| `/btw [question]` | Ask an ephemeral side question without adding it to conversation history |
| `/cd <path>` | Move the current session to another working directory |
| `/clear [name]` | Start a new conversation with empty context while preserving project memory |
| `/code-review [level] [--fix] [--comment] [target]` | Run a local background review, or use level `ultra` for cloud review; levels run from `low` through `max` |
| `/compact [instructions]` | Summarize the conversation to free context |
| `/config [key=value ...]` | Open settings or update supported keys directly (`/settings` alias) |
| `/context [all]` | Visualize what is using the context window |
| `/diff` | Open the interactive current/per-turn diff viewer |
| `/doctor` | Diagnose setup, configuration, hooks, memory, plugins, and MCP; can offer fixes (`/checkup` alias) |
| `/effort [level|auto]` | Set model-dependent effort: `low`, `medium`, `high`, `xhigh`, `max`, or `ultracode` |
| `/fast [on|off]` | Toggle fast mode where the selected Opus model and plan support it |
| `/fork [prompt]` | Copy this conversation into a worktree-isolated background session and keep working here |
| `/goal [condition|clear]` | Keep working across turns until a completion condition is met |
| `/hooks` | Inspect configured hooks in the read-only hook browser |
| `/import [codex|gemini]` | Preview or migrate supported configuration from another coding agent |
| `/init` | Generate a starter `CLAUDE.md` for the project |
| `/loop [interval] [prompt]` | Run a prompt repeatedly while the session remains open |
| `/mcp` | Inspect, authenticate, enable, disable, or reconnect MCP servers |
| `/memory` | Manage `CLAUDE.md`, rules, and auto-memory |
| `/model [model]` | Switch model and normally save it as the default; press `s` in the picker for session-only selection |
| `/permissions` | Manage allow, ask, and deny rules (`/allowed-tools` alias) |
| `/plan [description]` | Enter plan mode, optionally with a task |
| `/plugin [subcommand]` | Discover, install, enable, disable, and manage plugins |
| `/reload-plugins [--force]` | Apply plugin changes without restarting when safe |
| `/remote-control [name]` | Expose this local session to claude.ai/code or the Claude mobile app |
| `/resume [session]` | Resume by ID/name or open the session picker |
| `/review ...` | Alias for `/code-review` as of v2.1.223 |
| `/rewind` | Restore or summarize code and conversation from a checkpoint |
| `/sandbox` | View and configure Bash filesystem/network sandboxing on supported platforms |
| `/security-review` | Review the current branch diff for security vulnerabilities |
| `/simplify` | Review changed code for reuse, quality, and efficiency improvements |
| `/subtask [prompt]` | Run the former in-session fork behavior as a subagent that reports back here |
| `/tasks` | List the current session's background shells, subagents, and tool calls |
| `/teleport [session]` | Copy a Claude Code web session into the local terminal |
| `/usage` | Show subscription usage and rate-limit status |
| `/workflows` | Inspect dynamic workflow runs and background orchestration |
<h2 id="command-line-flags">Command Line Flags</h2>
| Flag / Command | Description | Example |
| :--------------------------------------------------- | :----------------------------------------------------------------------------------------------------------------------------------------------------------- | :------------------------------------------------------------------------------------- |
| `-d, --debug` | Enable debug mode (shows detailed debug output). | `claude -d -p "query"` |
| `--include-partial-messages` | Include partial streaming events; requires print mode and `stream-json`. | `claude -p --output-format stream-json --include-partial-messages "query"` |
| `--include-hook-events` | Include hook lifecycle events in `stream-json` output. | `claude -p --output-format stream-json --include-hook-events "query"` |
| `--forward-subagent-text` | Forward subagent text/thinking with `parent_tool_use_id` in `stream-json`. | `claude -p --output-format stream-json --forward-subagent-text "query"` |
| `--verbose` | Override verbose mode setting from config (shows expanded logging / turn-by-turn output). | `claude --verbose` |
| `-p, --print` | Print response and exit (useful for piping output). | `claude -p "query"` |
| `--output-format <format>` | Output format (only works with `--print`): `text` (default), `json` (single result), or `stream-json` (realtime streaming). | `claude -p "query" --output-format json` |
| `--input-format <format>` | Input format (only works with `--print`): `text` (default) or `stream-json` (realtime streaming input). | `claude -p --output-format stream-json --input-format stream-json` |
| `--replay-user-messages` | Re-emit user messages from stdin back to stdout for acknowledgment — **only works with** print mode plus `stream-json` input and output. | `claude -p --verbose --input-format stream-json --output-format stream-json --replay-user-messages` |
| `--allowedTools`, `--allowed-tools <tools...>` | Comma/space-separated permission rules to allow. | `claude --allowed-tools "Bash(git *)" "Edit"` |
| `--disallowedTools`, `--disallowed-tools <tools...>` | Comma/space-separated permission rules to deny. | `claude --disallowed-tools "Edit"` |
| `--mcp-config <configs...>` | Load MCP servers from JSON files or strings (space-separated). | `claude --mcp-config ./mcp-servers.json` |
| `--strict-mcp-config` | Only use MCP servers from `--mcp-config`, ignoring other MCP configurations. | `claude --mcp-config ./a.json --strict-mcp-config` |
| `--append-system-prompt <prompt>` | Append a system prompt to the default system prompt (useful in print mode). | `claude -p --append-system-prompt "Do X then Y"` |
| `--autocompact <auto\|tokens>` | Override the auto-compaction window for this session. | `claude --autocompact 500k` |
| `--ax-screen-reader` | Use a flat, screen-reader-friendly renderer without decorative borders or animations. | `claude --ax-screen-reader` |
| `--bare` | Minimal scripted mode: skip discovered hooks, skills, plugins, MCP, auto-memory, and `CLAUDE.md`. | `claude --bare -p "query"` |
| `--permission-mode <mode>` | Start in `default`/`manual`, `acceptEdits`, `auto`, `dontAsk`, `bypassPermissions`, or `plan`. | `claude --permission-mode plan` |
| `--permission-prompt-tool <tool>` | Specify an MCP tool to handle permission prompts in non-interactive mode. | `claude -p --permission-prompt-tool mcp_auth_tool "query"` |
| `--fallback-model <models>` | In print mode, try a comma-separated fallback chain when the primary model is unavailable. | `claude -p --fallback-model sonnet,haiku "query"` |
| `--effort <level>` | Set effort to `low`, `medium`, `high`, `xhigh`, or `max`, or start session-only `ultracode` mode where supported. | `claude --effort high` |
| `--model <model>` | Model for the current session. Accepts aliases like `sonnet`/`opus` or a full model ID when pinning. | `claude --model sonnet` |
| `--advisor <model>` | Set the experimental advisor for this session without changing `advisorModel`; intentionally omitted from `claude --help`. | `claude --advisor opus` |
| `--settings <file-or-json>` | Load additional settings from a JSON file or a JSON string. | `claude --settings ./settings.json` |
| `--add-dir <directories...>` | Additional directories to allow tool access to. | `claude --add-dir ../apps ../lib` |
| `--ide` | Automatically connect to an IDE on startup if exactly one valid IDE is available. | `claude --ide` |
| `-c, --continue` | Continue the most recent conversation in the current directory. | `claude --continue` |
| `-r, --resume [sessionId]` | Resume a conversation; provide a session ID or interactively select one. | `claude -r "abc123"` |
| `--session-id <uuid>` | Use a specific session ID for the conversation (must be a valid UUID). | `claude --session-id 123e4567-e89b-12d3-a456-426614174000` |
| `--agents <json>` | Define custom subagents dynamically via JSON (see subagent docs for format). | `claude --agents '{"reviewer":{"description":"Reviews code","prompt":"..."}}'` |
| `--agent <name>` | Specify a specific agent for the current session. | `claude --agent my-custom-agent` |
| `--bg` | Start or continue work as a background session that can be viewed from `claude agents`. | `claude --bg "fix failing tests"` |
| `--bg --exec <command>` | Run a shell command as an attachable background session. | `claude --bg --exec "npm test"` |
| `--name <label>` | Name a background or remote session for easier identification. | `claude --bg --name nightly-check "run checks"` |
| `--chrome` | Enable Chrome browser integration for web automation and testing. | `claude --chrome` |
| `--no-chrome` | Disable Chrome browser integration for this session. | `claude --no-chrome` |
| `--cloud [description\|session\|url]` | Create or attach to a Claude Code web session on claude.ai. | `claude --cloud "Fix the login bug"` |
| `--remote` | Deprecated alias for `--cloud`. | `claude --remote "Fix the login bug"` |
| `--remote-control`, `--rc` | Start an interactive local session that can also be controlled from claude.ai or the Claude app. | `claude --remote-control "My Project"` |
| `--teleport [session]` | Resume a web session in your local terminal. | `claude --teleport <session-id>` |
| `--fork-session` | When resuming, create a new session ID instead of reusing the original. | `claude --resume abc123 --fork-session` |
| `--json-schema <schema>` | Get validated JSON output matching a JSON Schema after agent completes (print mode only). | `claude -p --json-schema '{"type":"object",...}' "query"` |
| `--max-budget-usd <amount>` | Maximum dollar amount to spend on API calls before stopping (print mode only). | `claude -p --max-budget-usd 5.00 "query"` |
| `--max-turns <n>` | Limit the number of agentic turns (print mode only). Exits with error when limit reached. | `claude -p --max-turns 3 "query"` |
| `--betas <headers>` | Beta headers to include in API requests (API key users only). | `claude --betas interleaved-thinking` |
| `--tools <tools>` | Restrict which built-in tools Claude can use. Use "" to disable all, "default" for all, or specific tool names. | `claude --tools "Bash,Edit,Read"` |
| `--system-prompt <prompt>` | Replace the entire system prompt with custom text (works in interactive and print modes). | `claude --system-prompt "You are a Python expert"` |
| `--system-prompt-file <file>` | Load a system prompt from a file, replacing the default in interactive or print mode. | `claude --system-prompt-file ./custom-prompt.txt` |
| `--append-system-prompt-file <file>` | Load additional system-prompt text from a file in interactive or print mode. | `claude --append-system-prompt-file ./extra-rules.txt` |
| `--plugin-dir <path>` | Load a plugin directory or `.zip` for this session only (repeatable). | `claude --plugin-dir ./my-plugin --plugin-dir ./other.zip` |
| `--plugin-url <url>` | Fetch a plugin `.zip` URL for this session only (repeatable). | `claude --plugin-url https://example.com/plugin.zip` |
| `--setting-sources <sources>` | Comma-separated list of setting sources to load (user, project, local). | `claude --setting-sources user,project` |
| `--no-session-persistence` | Disable session persistence so sessions are not saved to disk (print mode only). | `claude -p --no-session-persistence "query"` |
| `--disable-slash-commands` | Disable all skills and slash commands for this session. | `claude --disable-slash-commands` |
| `--dangerously-skip-permissions` | Skip normal permission prompts, subject to non-bypassable safety checks and managed policy. | `claude --dangerously-skip-permissions` |
| `--safe-mode` | Disable user/project customizations for configuration troubleshooting while retaining authentication, models, tools, and permissions. | `claude --safe-mode` |
| `--worktree [name]`, `-w [name]` | Start in `<repo>/.claude/worktrees/<name>`; omit the name to generate one. | `claude -w feature-auth` |
| `--from-pr [value]` | Filter/resume sessions by PR number or GitHub/GitLab/Bitbucket PR/MR URL, or open the picker. | `claude --from-pr 123` |
| `--init` | Run Setup hooks with the `init` matcher before a print-mode session. | `claude -p --init "query"` |
| `--init-only` | Run Setup hooks and exit. | `claude --init-only` |
| `--maintenance` | Run Setup hooks with the `maintenance` matcher before a print-mode session. | `claude -p --maintenance "query"` |
| `-v, --version` | Show the installed `claude` CLI version. | `claude --version` |
| `-h, --help` | Display help / usage. | `claude --help` |
> This table highlights common and recently changed options; `claude --help` and the [live CLI reference](https://code.claude.com/docs/en/cli-reference) are authoritative. `--output-format json` is useful for one-shot automation; use `stream-json` for event-level integrations.
For programmatic integrations, the former **Claude Code SDK** is now the [Claude Agent SDK](https://platform.claude.com/docs/en/agent-sdk/overview): TypeScript uses `@anthropic-ai/claude-agent-sdk`, and Python uses `claude-agent-sdk` / `claude_agent_sdk`. Use `claude -p` for headless CLI calls; `--bare` removes discovered customization and keychain/OAuth access for low-overhead API/provider automation.
<h2 id="cheat-sheet">CLI Quick Reference & Configuration Examples</h2>
```md
## Claude Cheat Sheet
# Start and resume
claude # Start interactive REPL
claude "explain this project" # Start REPL seeded with a prompt
claude -p "summarize README.md" # Non-interactive headless print mode
cat logs.txt | claude -p "explain" # Pipe input to Claude and exit
claude -c # Continue most recent conversation
claude -r "<session-id>" "finish this" # Resume by ID or name
claude --model sonnet # Pick the Sonnet alias for this run
claude --model opus # Pick the Opus alias for harder tasks
# Install, update, and auth
claude update # Manually update Claude Code
claude doctor # Diagnose install/version & setup
claude install stable # Install/reinstall the native binary on the stable channel
claude auth login # Log in to your Anthropic account
claude auth status # Check authentication status
claude auth logout # Log out
# Background and remote sessions
claude agents # Open the live session dashboard: running, blocked, completed
claude agents --json # Scriptable JSON list of live/background sessions
claude --bg "run the integration suite and summarize failures" # Start a background session
claude --bg --exec "npm test" # Run a shell command as an attachable background session
claude attach <id> # Attach to a background session
claude logs <id> # Print recent background-session output
claude stop <id> # Stop a background session
claude rm <id> # Remove it from agent view and delete its worktree; transcript remains resumable
claude remote-control # Serve local sessions to web/mobile while this process stays alive
claude --cloud "Fix the bug" # Create a web session on claude.ai
claude --teleport <session-id> # Copy a web session into this terminal
# Config essentials
/config # Interactive settings
/config model=sonnet # Set a supported key directly
/config theme=dark
/config --help # Show settable keys and values
# For shared or managed settings, edit the appropriate settings.json file.
# MCP essentials
claude mcp list # List configured MCP servers
claude mcp get <name> # Show details for a server
claude mcp add <name> <command> [args...] # Add local stdio server
claude mcp add --transport http <name> <url> # Add remote HTTP server
claude mcp login <name> # Complete OAuth without opening /mcp
claude mcp logout <name> # Clear saved OAuth credentials
claude mcp reset-project-choices # Reset approvals for project .mcp.json servers
claude mcp serve # Run Claude Code itself as an MCP stdio server
# High-value flags
claude --add-dir ../apps ../lib # Add additional working directories
claude --allowed-tools "Bash(git log *)" "Read" # Allow listed tools without permission prompts
claude --disallowed-tools "Edit" # Deny listed tools
claude -p "query" --output-format json # Structured one-shot output
claude --verbose # Verbose logging (turn-by-turn)
claude --dangerously-skip-permissions # Skip permission prompts (use with caution)
claude --permission-mode plan # Start in plan mode without source edits
claude --effort high # Set reasoning effort for this session
claude --bare -p "query" # Fast scripted call without discovered customization
claude --safe-mode # Troubleshoot with user/project customization disabled
claude --ax-screen-reader # Use the accessible flat-text renderer
claude --max-turns 3 -p "query" # Limit agentic turns (print mode only)
claude --json-schema '{"type":"object"}' -p "query" # Get validated JSON output
claude --chrome # Enable Chrome browser integration
claude --agent code-reviewer # Run this session with a named agent
claude ultrareview 123 --json # Non-interactive comprehensive review for PR/target 123
# Slash shortcuts
claude --fork-session -r abc123 # Fork instead of reusing original
claude -w feature-auth "implement feature" # Start in an isolated git worktree
/rename auth-refactor # Name current session
/resume # Open session picker
/export output.md # Export conversation to file
/branch experiment-name # Branch the current conversation
/fork "investigate the flaky test" # Copy conversation into a background session
/subtask "trace the regression" # Fork a subagent that reports back here
/cd ../other-project # Move the current session without losing its cache
/review high --fix # Run /code-review via its current alias
/goal "all tests pass and README is updated" # Keep working until the completion condition is met
/loop 30m "check deploy health and summarize anomalies" # Schedule recurring work
/workflows # View dynamic workflows and background orchestration
# Settings precedence: managed policy > CLI/--settings > local > project > user.
```
---
<h1 id="interface--input">Interface & Input</h1>
<h2 id="keyboard-shortcuts">Keyboard Shortcuts</h2>
| Shortcut | Description | Context |
| :--------------------------- | :--------------------------------- | :--------------------------------------- |
| `Ctrl+C` | Cancel current input or generation | Standard interrupt |
| `Ctrl+D` | Exit Claude Code session | EOF signal |
| `Ctrl+G` | Open in default text editor | Edit your prompt or custom response |
| `Ctrl+L` | Redraw the terminal | Press twice in fullscreen mode to run `/clear` |
| `Ctrl+O` | Toggle transcript viewer | Shows detailed tool usage, timestamps, and model |
| `Ctrl+R` | Reverse search command history | Search through previous commands |
| `Ctrl+V`/`Cmd+V`; `Alt+V` on Windows/WSL | Paste image from clipboard | Inserts an image chip at the cursor |
| `Ctrl+B` | Background running tasks | Backgrounds bash commands and agents |
| `Ctrl+X`, then `Ctrl+K` | Stop all background agents | Two-key confirmation sequence |
| `Ctrl+T` | Toggle task checklist | `/tasks` remains the background-work view |
| `Ctrl+S` | Stash or restore the current prompt | Preserves text, cursor, and pasted content |
| `Up/Down arrows` | Navigate command history | Recall previous inputs |
| `Left/Right arrows` | Cycle through dialog tabs | Navigate between tabs in dialogs |
| `Esc` + `Esc` | Rewind the code/conversation | Restore to a previous point |
| `Shift+Tab` or `Alt+M` | Cycle enabled permission modes | Includes Manual, Accept Edits, Plan, and enabled Auto/Bypass modes |
| `Option+P` (macOS) / `Alt+P` | Switch model | Switch models without clearing prompt |
| `Option+T` (macOS) / `Alt+T` | Toggle extended thinking | Enable/disable extended thinking mode |
| `Option+O` (macOS) / `Alt+O` | Toggle fast mode | Enable/disable supported fast mode |
<h3 id="text-editing">Text Editing</h3>
| Shortcut | Description | Context |
| :--------------------- | :--------------------------- | :------------------------------------ |
| `Ctrl+K` | Delete to end of line | Stores deleted text for pasting |
| `Ctrl+U` | Delete entire line | Stores deleted text for pasting |
| `Ctrl+Y` | Paste deleted text | Paste text deleted with Ctrl+K/U |
| `Alt+Y` (after Ctrl+Y) | Cycle paste history | Cycle through previously deleted text |
| `Alt+B` | Move cursor back one word | Requires Option as Meta on macOS |
| `Alt+F` | Move cursor forward one word | Requires Option as Meta on macOS |
<h3 id="multiline-input">Multiline Input</h3>
| Method | Shortcut | Context |
| :--------------- | :------------- | :-------------------------------- |
| Quick escape | `\` + `Enter` | Works in all terminals |
| macOS default | `Option+Enter` | Default on macOS |
| Shift+Enter | `Shift+Enter` | Native in most modern terminals; use `/terminal-setup` where needed |
| Control sequence | `Ctrl+J` | Line feed character for multiline |
| Paste mode | Paste directly | For code blocks, logs |
<h3 id="quick-commands">Quick Commands</h3>
| Shortcut | Description | Notes |
| :----------- | :---------------- | :------------------------------------ |
| `/` at start | Command or skill | See built-in commands and skills |
| `!` at start | Bash mode | Run commands directly, add to context |
| `@` | File path mention | Trigger file path autocomplete |
> [!Tip]
> **PDF Page Ranges:** Use the `pages` parameter with the Read tool for PDFs (e.g., `pages: "1-5"`). Large PDFs (>10 pages) return a lightweight reference when @-mentioned instead of being inlined.
<h2 id="vim-mode">Vim Mode</h2>
> [!Note]
> Enable vim-style editing from `/config` -> Editor mode.
<h3 id="vim-mode-switching">Vim Mode Switching</h3>
| Command | Action | From mode |
| :------ | :-------------------------- | :-------- |
| `Esc` | Enter NORMAL mode | INSERT |
| `i` | Insert before cursor | NORMAL |
| `I` | Insert at beginning of line | NORMAL |
| `a` | Insert after cursor | NORMAL |
| `A` | Insert at end of line | NORMAL |
| `o` | Open line below | NORMAL |
| `O` | Open line above | NORMAL |
<h3 id="vim-navigation">Vim Navigation</h3>
| Command | Action |
| :-------------- | :------------------------ |
| `h`/`j`/`k`/`l` | Move left/down/up/right |
| `w` | Next word |
| `e` | End of word |
| `b` | Previous word |
| `0` | Beginning of line |
| `$` | End of line |
| `^` | First non-blank character |
| `gg` | Beginning of input |
| `G` | End of input |
<h3 id="vim-editing">Vim Editing</h3>
| Command | Action |
| :------------- | :---------------------- |
| `x` | Delete character |
| `dd` | Delete line |
| `D` | Delete to end of line |
| `dw`/`de`/`db` | Delete word/to end/back |
| `cc` | Change line |
| `C` | Change to end of line |
| `cw`/`ce`/`cb` | Change word/to end/back |
| `.` | Repeat last change |
> [!Tip]
> Configure your preferred line break behavior in terminal settings. Run `/terminal-setup` to install Shift+Enter binding for iTerm2, VS Code, Kitty, Alacritty, Zed, Warp, and WezTerm.
<h2 id="command-history">Command History</h2>
> Claude Code maintains command history for the current session:
```
* History is stored per working directory
* Cleared with `/clear` command
* Use Up/Down arrows to navigate (see keyboard shortcuts above)
* **Ctrl+R**: Reverse search through history (if supported by terminal)
* **Note**: History expansion (`!`) is disabled by default
```
---
<h1 id="advanced-features">Advanced Features</h1>
<h2 id="thinking-keywords">Thinking Keywords</h2>
> [!Note]
> **`ultrathink` is the only documented prompt keyword for a one-turn request for deeper reasoning.** Phrases such as `think`, `think hard`, and `think harder` are ordinary prompt text; they are not graduated Claude Code controls.
Use `/effort` for an explicit session setting. `ultrathink` adds an in-context instruction for that turn without changing the effort value sent to the API.
```md
Ultrathink. Propose a step-by-step strategy to fix flaky payment tests and add guardrails.
```
<h2 id="effort-levels">Effort Levels</h2>
Use `/effort` to tune how much reasoning the selected model applies before answering. Higher effort levels are best for planning-heavy work, deep reviews, and long-context tasks.
```bash
/effort # Open the effort picker
/effort low # Faster, lighter reasoning
/effort medium # Balanced default for many tasks
/effort high # Deeper planning and review
/effort xhigh # Strong default for difficult coding and agentic work where supported
/effort max # Session-only maximum; test for diminishing returns
/effort ultracode # Session-only xhigh plus dynamic workflow orchestration, where available
/effort auto # Return to the selected model's default
```
Available levels depend on the model. The saved `effortLevel` setting accepts `low` through `xhigh`; `max` normally applies only to the current session, although `CLAUDE_CODE_EFFORT_LEVEL=max` can force it for sessions launched with that environment variable. `ultracode` is a separate session-only mode that combines `xhigh` with standing dynamic-workflow orchestration, so it requires workflows and an xhigh-capable model. Prefer the lowest effort that reliably solves the task because higher effort increases latency and token use.
<h2 id="advisor-tool">Advisor Tool (Experimental)</h2>
The advisor pairs the main model with a second, at-least-as-capable model that Claude may consult at important planning, debugging, or completion decisions. Each consultation sends the full conversation, including tool calls and results; it counts toward subscription usage or is billed at the advisor model's API rates.
```bash
/advisor # Open the picker and save the user default
/advisor opus # Save Opus as the advisor
/advisor off # Clear the saved advisorModel setting
claude --advisor opus # Use Opus for this session without changing the saved default
```
The feature runs only through the first-party Anthropic API, for subscription or API-billed accounts; it is unavailable on Bedrock, Claude Platform on AWS, Google Cloud's Agent Platform, and Microsoft Foundry. Claude decides when to consult it. `advisorModel` is the persistent settings key, while the intentionally hidden `--advisor` launch flag is session-only. Fable 5 is not currently selectable as an advisor. See the [advisor guide](https://code.claude.com/docs/en/advisor) for supported main/advisor pairings.
<h2 id="fast-mode">Fast Mode</h2>
> [!Note]
> **Fast mode is a research preview that runs the same Opus model and capabilities up to 2.5× faster at a higher price per token. It does not trade model quality for speed.**
```bash
/fast # Toggle in the CLI
# Option+O on macOS or Alt+O on Windows/Linux also toggles it
```
Fast mode currently supports **Opus 5 and Opus 4.8**. It is unavailable for Sonnet, Haiku, Opus 4.7, third-party providers, and the VS Code extension. Subscription users need usage credits; Team and Enterprise also require Owner enablement. Use it for latency-sensitive interactive work, and standard mode for cost-sensitive or long autonomous tasks. Lower `/effort` is the separate control that may trade reasoning depth for speed.
<h2 id="auto-mode">Auto Mode</h2>
Auto mode lets Claude evaluate and approve lower-risk actions automatically while still blocking or asking on higher-risk operations. It is useful for trusted development loops where repeated permission prompts slow down work.
```bash
# Start in auto mode, or cycle to it with Shift+Tab
claude --permission-mode auto
# Inspect the built-in and effective classifier configuration
claude auto-mode defaults
claude auto-mode config
# Remove a cached/custom classifier config and return to defaults
claude auto-mode reset # Add --yes to skip confirmation
```
```json
{
"autoMode": {
"allow": ["$defaults"],
"soft_deny": ["$defaults"],
"hard_deny": []
}
}
```
Key points:
- Auto mode is available by default on every supported provider; `CLAUDE_CODE_ENABLE_AUTO_MODE` is now a no-op compatibility variable.
- The classifier trusts the working directory and current repository remotes by default. Add organization infrastructure under `autoMode.environment` only when needed.
- Put `autoMode` in user settings, managed settings, or `--settings`. Repository `.claude/settings.json` and `.claude/settings.local.json` cannot inject classifier