# liuup/claude-code-analysis: Static Analysis of the Leaked Claude Code TypeScript Source

> claude-code-analysis is a documentation repository containing static analysis of the Claude Code TypeScript source code that became publicly available in March 2026, when Anthropic published the npm package without removing source map files. The repository covers architecture, security, memory systems, tool call mechanisms, and comparisons with competing coding agents.

**liuup/claude-code-analysis** — 🤖 The analysis of Claude Code

- Repository: https://github.com/liuup/claude-code-analysis
- Stars: 3,964 · Forks: 2,068
- Language: TypeScript
- License: not declared
- Published: 2026-09-23 · Updated: 2026-09-23 · Language: en
- Canonical page: https://hysenlabs.com/projects/liuup-claude-code-analysis

## How the Source Code Became Available

On March 31, 2026, a security researcher published a post on X noting that the Claude Code package on npm retained its TypeScript source map files. Source maps are developer tools that map compiled JavaScript back to the original TypeScript source. Anthropic had not removed them before publishing. The result was that the complete TypeScript source for Claude Code, consisting of 1,902 source files and 513,237 lines of code, was accessible to anyone who downloaded the npm package.

liuup/claude-code-analysis is a documentation project that collects static analysis of those files. The repository README states it is intended for academic research and technical study. All rights to the Claude Code source remain with Anthropic. The README explicitly prohibits commercial use of the repository's content and prohibits using it to circumvent Claude Code's security mechanisms.

## Repository Structure and What Each Directory Contains

The repository has a flat top-level layout:

```text
claude-code-analysis/
├── README.md                        # 本说明文档（总索引）
├── analysis/                        # 分析文档主目录
├── src.zip                          # 源代码压缩包
└── src/                             # 源代码（仅供分析跳转引用）
```

The analysis/ directory is the main content. It contains eighteen chapters and six component-focused sub-documents organized into nine thematic parts. The src.zip file and src/ directory contain the leaked source code itself, included so that analysis documents can reference specific file paths and line numbers directly.

The README states that all analysis is based on static reading of src/, not on running the software. The repository authors note they did not execute the code.

## Architecture and Entry Point Analysis

The analysis begins with Claude Code's overall architecture and its startup path. The repository includes a diagram of the major components as they appear in the source tree:

```text
+---------------------------+
| CLI / 多入口               |
| entrypoints/cli.tsx       |
| main.tsx                  |
+---------------------------+
            |
            v
+---------------------------+
| 初始化与运行环境             |
| init.ts / setup.ts        |
+---------------------------+
```

The analysis identifies the main entry point as entrypoints/cli.tsx and main.tsx, with init.ts and setup.ts handling environment initialization. From there, the system branches into a command-and-control layer (commands.ts, PromptInput) and a TUI and REPL workbench (App, REPL, Messages, PromptInput components).

This architecture description is based on file names and directory structure rather than runtime observation. The analysis does not make claims about behavior that cannot be traced to specific source locations.

## Security Analysis: Data Collection, Risks, and Mitigations

Chapter 2 of the analysis examines three aspects of Claude Code's security posture. The first is user information collection: which data enters the system and how it flows. The second is code-level security risks in the source itself. The third is the defensive measures built into the system.

The README summarizes the main findings at a high level. On privacy, the analysis identifies three categories of outbound data flow: model context interactions (what is sent to Anthropic's API), local persistent storage (what is written to disk), and external component communications (what goes to MCP servers or other remote services).

On defensive measures, the analysis notes that the system uses a local Sandbox for isolating file system operations and a Tool Permission system for controlling which tool calls are allowed. Chapter 7 covers the Sandbox in detail, examining the specific mechanisms used to prevent local environment damage from agent actions. None of the security claims in the analysis are based on running the code; all are drawn from static source reading.

## Memory, Tool Calls, MCP, and Multi-Agent Mechanisms

The third part of the analysis, spanning chapters 3 through 11, covers the core runtime mechanisms. Chapter 3 examines Agent Memory: a multi-tier storage system including session-level context and a compression mechanism for long sessions. Chapter 5 covers the Tool Call mechanism, tracing how the agent decides which tools to call and how results are returned to the model. Chapter 6 covers MCP (Model Context Protocol) integration.

The analysis of multi-agent behavior in Chapter 10 is notable. Claude Code was not publicly documented as supporting multi-agent workflows at the time the analysis was published. The chapter examines the source code evidence for how multiple agent instances coordinate.

Chapter 11 covers Session Storage, Transcript handling, and the resume mechanism that allows a session to continue after interruption. The analysis traces how session state is serialized to disk and how the resume path reconstructs context.

## Component Breakdown and Competitor Comparison

Part 6 of the repository, spanning six component documents, breaks down the TUI console implemented in src/components/. The analysis identifies the component hierarchy, the main interaction chain (App to REPL to Messages to PromptInput), and the platform control surface. Component document 5 goes to function-level detail for core components.

Part 7 compares Claude Code with Codex, Gemini CLI, Aider, and Cursor. The analysis focuses on architectural and feature differences as visible in the source, not on user-facing benchmarks. The README names these comparisons as one of the nine topics the analysis covers.

The repository also includes a chapter on hidden commands, feature flags, and developer-facing artifacts found in the source, and a chapter examining negative keyword detection and frustration signal mechanisms.

## Maintenance Status and Legal Context

The last push to liuup/claude-code-analysis was on 2026-04-02. The repository has not been updated since. No license is declared in the repository metadata.

The README includes a detailed disclaimer. It states that the repository contains only secondary analysis of publicly available information. It prohibits commercial use and prohibits using the content to bypass Claude Code security mechanisms. It offers to remove content if Anthropic requests it through a GitHub issue.

Readers should be aware that the source code in src/ and src.zip reflects the state of Claude Code as it existed in the npm package at the time of the leak. Subsequent versions of Claude Code would differ from what the analysis describes.

## Conclusion

This repository is useful for engineers and researchers who want to understand how a production coding agent is actually built, rather than how its documentation says it works. The analysis covers architecture, security surface, memory layering, and component breakdown at a level of detail that marketing documentation does not reach. It is not useful as a how-to guide for building on top of Claude Code, and it does not contain the Claude Code binaries themselves. Readers wanting current official documentation should use Anthropic's published resources. The last push was on 2026-04-02, and the repository has not been updated since the initial analysis period.

## FAQ

### What exactly is in the liuup/claude-code-analysis repository?

The repository contains static analysis documentation organized in eighteen chapters covering Claude Code's architecture, security, memory, tool calls, MCP integration, sandbox, multi-agent behavior, and UI components. It also includes the leaked source code in src.zip and src/ for reference.

### Is it legal to read or use liuup/claude-code-analysis?

The repository README states the content is intended for academic research and technical study, prohibits commercial use, and notes that all rights to the Claude Code source remain with Anthropic. Readers should review the full disclaimer in the README and Anthropic's terms of service before use.

### Does the analysis cover the current version of Claude Code?

No. The analysis is based on the source code state from the March 2026 npm package. The last push to the repository was on 2026-04-02, and subsequent Claude Code releases are not covered.

## Sources

- [Issues](https://github.com/liuup/claude-code-analysis/issues)
- [liuup/claude-code-analysis on GitHub](https://github.com/liuup/claude-code-analysis)
- [README](https://github.com/liuup/claude-code-analysis/blob/main/README.md)

---

Hysen Labs editorial analysis, written from the project's own repository and release notes. Cite the canonical page: https://hysenlabs.com/projects/liuup-claude-code-analysis
