Skip to content
Immediate audit

Stack security audit

8 items still open.

AI Security Mastery — 26-Week Study Checklist

Execution layer. Tick boxes here as you complete work. The substantive content for each week — what the topic IS, why it matters, primary sources — lives in roadmap.md. Each week's heading links to the matching roadmap section.

Last verified against trends: 2026-05-12 — see reconciliation-2026-05-12.md.

Stack Security Audit (do immediately)

↪ See roadmap.md → Cross-cutting → Stack-affecting CVEs

  • Audit CVE-2026-35022/35020/35021 (Claude Code CLI) — check all agent .claude/settings.json for apiKeyHelper, awsAuthRefresh, gcpAuthRefresh fields; verify v2.1.118 patch status
  • Check if mcp-server-git or mcp-remote are installed; verify versions against CVE-2025-68143/44/45 and CVE-2025-6514
  • Verify Claude Code version ≥ 2.0.72 (fixes CVE-2026-24887 find command bypass RCE)
  • Verify anthropic-sdk-typescript not v0.79.0–0.91.0 (CVE-2026-41686 insecure file permissions on agent memory)
  • Verify Claude Code version ≥ 2.1.64 (fixes CVE-2026-39861 sandbox escape via symlink; CVSS 10.0)
  • Reboot VPS to kernel 6.8.0-111 to patch Copy Fail (CVE-2026-31431 kernel LPE + container escape); verify fix included
  • Inspect .claude/ dirs in any repos cloned by builder for unexpected SessionStart hook entries (Shai-Hulud persistence)
  • Review NIST IR 8596 (Cyber AI Profile) when final draft drops mid-2026 — overlay onto our agent architecture

Phase 1: Foundation (Weeks 1–8)