{
  "id": 10506226,
  "title": "Claude Can't Say \"Done\" Until the Code Is Safe: A Security Verification Loop for Claude Code",
  "url": "https://urgent.news/2026/09/28/claude-cant-say-done-until-the-code-is-safe-a-security-verification",
  "topic": "ai",
  "section": "AI",
  "published": "2026-09-28T18:34:47.000Z",
  "source": {
    "name": "Dev.to",
    "slug": "dev-to",
    "url": "https://dev.to/thesnehamk/claude-cant-say-done-until-the-code-is-safe-a-security-verification-loop-for-claude-code-pdk"
  },
  "original_language": "en",
  "account": "Claude Code developer has created a security verification loop that ensures the code generated by Claude is safe before it is executed. This is done by hooking into Claude's output and scanning for potential security issues. If any issues are found, Claude is provided with feedback and instructions on how to fix them. The loop continues until Claude is confident that the code is safe to run. This loop is essential as Claude's code includes hard-coded API keys, uses innerHTML to render replies, and runs eval() on the output, which are all potential security risks. By implementing this verification loop, developers can trust that Claude's code is safe before it is executed, reducing the risk of security breaches.",
  "summary": "I asked Claude Code to add an AI chat feature. It worked. It also: hardcoded my API key, rendered the model's reply with innerHTML, and ran eval() on it. Then it said, \"All done!\" 🙃 Anthropic's Claude Code team recently wrote about verification loops: Claude checks its own work and loops back to fix problems before responding. Most examples verify that tests pass. Nobody was verifying that the…",
  "key_points": [
    "Claude Code developer implemented security verification loop.",
    "Loop scans Claude's output for security issues before execution.",
    "Verification loop ensures safe code execution, mitigating risks."
  ],
  "editors_take": null,
  "illustration": null,
  "coverage": {
    "outlets": 1,
    "also_reported_by": []
  },
  "ai_generated": true,
  "disclaimer": "Summaries, key points and the editor’s take are written by software from other outlets’ reporting and may contain errors — always check the linked original."
}