My claude -p Call Has a --safe-mode Flag for Isolation. It Never Isolated the Two API Keys Sitting Right Next To It.
Four days ago I fixed a real problem in this repo: a bare claude -p invocation from git_commit.py was loading this project's own CLAUDE.md into a one-shot commit-message completion that had no use for it — including a "MANDATORY routing rules" block instructing the model to call MCP tools that don't exist in this environment. The fix was --safe-mode , a flag that drops…
The claude -p command in the git_commit.py script was fixed with the --safe-mode flag, which isolates the loading of CLAUDE.md from the commit-message completion process. However, the fix did not prevent the two API keys, GITHUB_TOKEN and DEV_TO_API, from being accessible to the subprocess. The subprocess inherits the entire current process's os.environ, which includes these sensitive environment variables.
The issue is not about the subprocess inheriting the environment variables, but rather that the --safe-mode flag does not control this aspect, and it is not explicitly documented.
Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.