Model or dataset
jarmuine/claude-code avatar
jarmuine/claude-code

A leaked Claude Code source snapshot, mirrored for supply-chain research

Fork of instructkr/claude-code

2,311 stars5,904 forksTypeScriptLicense varies

At a glance

What is it?
Around 1,900 TypeScript files and 512,000 lines recovered from an npm source map, useful as an architecture reference and as a study in how a package gets exposed.
Who is it for?
This repository is not a project you adopt, it is a reading. What it offers is an unusually clear view of how a commercial coding agent is decomposed: roughly 140 Ink components, about 40 tools, about 50 slash commands, and a service layer that keeps API, OAuth, LSP, MCP, plugins, compaction and analytics in separate modules.
Can I use it commercially?
Not without permission. GitHub finds no licence file in the repository, and without a licence all rights are reserved by default: you may read the code but not reuse it. Check the README, or ask the authors, before using it.
Is it still maintained?
Activity is slowing. The repository last received commits 6 months ago.
What is it written in?
Mainly TypeScript, according to GitHub's language statistics.

Answers come from the project's GitHub data, last synced on September 28, 2026, and from our analysis. They are not legal advice.

Editorial analysis

What the mirror actually contains and what it does not

The repository holds a mirrored `src/` snapshot and nothing else. The tree confirms it: a README and a `src/` directory, no build system, no tests, no package manifest. So there is nothing here to install and nothing here to run. The value is entirely in reading it as a description of how the product works.

The stated scale is about 1,900 files and more than 512,000 lines of TypeScript, running on Bun with a React and Ink terminal interface. That number is worth pausing on, because it is the same order of magnitude as a mid-sized application, not a script. It is also the scale argument in the original incident: an artifact that large should never reach users with source maps pointing at unobfuscated sources.

How the source map got exposed in the first place

The README credits Chaofan Shou, who posted on 2026-03-31 that Claude Code source had been leaked via a map file in the npm registry. The mechanism is the ordinary failure mode of source maps: the published map referenced unobfuscated TypeScript hosted in a storage bucket, and the whole `src/` tree became publicly downloadable.

This is the actual lesson, and it is worth stating more directly than the README does. Shipping a source map to production is fine when it points at minified output that matches what you ship. It becomes a source disclosure the moment the map is paired with the original file names, the original module boundaries and untransformed sources in a reachable bucket. A build pipeline needs a check for that, not a policy document.

The tool registry is where an agentic CLI is actually designed

Every capability is a self-contained module under `src/tools/`, and each one defines its input schema, its permission model and its execution logic. The inventory explains a lot about the product. `BashTool` runs shell commands. `FileReadTool` handles images, PDFs and notebooks, not just text. `GrepTool` is ripgrep based and `GlobTool` does pattern matching. `AgentTool` spawns subagents and `SendMessageTool` passes messages between them, with `TeamCreateTool` and `TeamDeleteTool` managing team agents.

The rest of the list is the part that distinguishes a serious agentic CLI. `EnterPlanModeTool` and `ExitPlanModeTool` gate work behind a plan. `EnterWorktreeTool` and `ExitWorktreeTool` isolate a run in a git worktree. `SkillTool` and `MCPTool` are the extension points, `ToolSearchTool` defers loading tools until they are needed, and `CronCreateTool` sets up scheduled triggers. `SleepTool`, described as proactive mode wait, is the sort of primitive that only exists because the model asked for it.

Top-level files are equally telling. `main.tsx` is the Commander.js entry point, `cost-tracker.ts` handles token cost, `QueryEngine.ts` is the LLM query engine, and `context.ts` collects system and user context.

Commands, services and the IDE bridge as separate concerns

About 50 slash commands live under `src/commands/`. Some are obvious plumbing such as `/login`, `/config`, `/theme` and `/diff`. Others are product decisions: `/compact` compresses conversation context, `/context` visualizes what is in the window, `/cost` reports usage, `/resume` restores an earlier session, and `/share` hands a session off. `/desktop` and `/mobile` are handoffs to companion apps, and `/doctor` is environment diagnostics, which tells you the team expects the environment to be a common failure source.

The service layer is where external dependency handling is isolated. `api/` is the Anthropic client, `oauth/` the authentication flow, `lsp/` the language server manager, `mcp/` MCP server connection and management, `plugins/` the plugin loader, and `compact/` the context compression work. Alongside them sit `analytics/` backed by GrowthBase feature flags, `policyLimits/` for organization policy, `remoteManagedSettings/`, `teamMemorySync/`, and a `tokenEstimation.ts` that suggests token counting is estimated rather than exact.

Then there is `bridge/`, a bidirectional layer connecting IDE extensions in VS Code and JetBrains, plus `coordinator/` for multi-agent work and `server/` for server mode. Roughly 140 Ink components in `components/` are the visible side of all this, which is a useful reminder of how much of a terminal application is presentation.

Reading the directory list as a feature inventory

A few directories are pure product surface. `skills/` is the skill system, `vim/` is vim mode with `keybindings/` for configuration, `voice/` is voice input, `remote/` is remote sessions, `memdir/` is a persistent memory directory, and `migrations/` plus `schemas/` with Zod handle config evolution and validation. `outputStyles/` controls styling, `query/` is the query pipeline, `upstreamproxy/` handles proxy configuration, `buddy/` is described as a companion sprite, and `native-ts/` holds native utilities.

That list is the honest summary of what a coding agent has become: not just a model call in a loop but a session manager, an extension host, an editor bridge, a scheduled task runner and a multi-agent coordinator sharing one context window.

Two honest caveats. The repository carries no license field in its metadata, and the README states plainly that it does not claim ownership of the original code and is not an official Anthropic repository. The maintainer describes themself as a university student studying supply-chain exposure and agentic tooling architecture, and the last push was 2026-03-31. Read it as a research artifact; do not assume the code is free to redistribute.

Editorial conclusion

This repository is not a project you adopt, it is a reading. What it offers is an unusually clear view of how a commercial coding agent is decomposed: roughly 140 Ink components, about 40 tools, about 50 slash commands, and a service layer that keeps API, OAuth, LSP, MCP, plugins, compaction and analytics in separate modules. If you are building something similar, the tool registry and the permission model are the two places worth your attention, because that is where an agentic CLI actually earns or loses trust. Two limits are worth stating plainly. The code is a point-in-time mirror, so it already lags the shipping product, and it carries no license field in the repository metadata, which leaves redistribution rights genuinely unclear. Read it for architecture and for the packaging failure it documents, and treat any use of the code itself as something to settle separately.

Frequently asked questions

How was the Claude Code source code exposed?

A source map published in the npm distribution referenced unobfuscated TypeScript sources hosted in a storage bucket, making the whole src tree publicly downloadable. Chaofan Shou publicly flagged it on 2026-03-31.

How large is this source snapshot?

The README describes roughly 1,900 files and more than 512,000 lines of TypeScript, running on Bun with a React and Ink terminal interface. It is a mirror only, with no build system, so there is nothing to install.

Is this an official Anthropic repository?

No. The README states it does not claim ownership of the original code and is not an official Anthropic repository. It is maintained for educational, defensive security and supply-chain research, and no license is recorded in the repository metadata.

Can I use this code in my own project?

Treat that as unresolved. The repository is a mirror of leaked code with no license field, so redistribution rights are unclear. It is reasonable to read it as an architecture reference, which is the stated purpose, but shipping any of the code would need a separate legal answer.

Official sources

  1. Issues
  2. jarmuine/claude-code on GitHub
  3. README
Add this badge to your README

If you maintain this project, the badge below links readers to this analysis and shows its maintenance status from the daily GitHub snapshot. Paste the markdown into your README; add ?metric=license or ?metric=stars to the image URL for a different field.

Add this badge to your README

markdown
[![Hysen Labs](https://hysenlabs.com/badge/jarmuine-claude-code.svg)](https://hysenlabs.com/projects/jarmuine-claude-code)