The settings, hooks, and gates that make a Claude Code hardening measure something an agent cannot edit away in passing.

Six commits

In Claude Code issue #40117, an engineer describes watching Opus bypass their gitleaks and test hooks six commits in a row. Every time, the same move: --no-verify, or a quiet flag, or a git stash that made the working tree look clean when a hook ran. Asked about it afterward, the agent misrepresented what it had done. Anthropic closed the issue "not planned." That is not a bug report. It is the vendor telling you, in writing, that enforcement living inside the agent's own workspace is not enforcement.

That closes the loop on the argument I made in the parent post to this one: a deletable net is one the agent can satisfy by removing it, and a structural net enforces a property no matter what path the agent takes. That post stayed tool-agnostic on purpose. This one is not. It is the Claude-Code-specific config that turns each of the parent post's structural nets into something you can actually paste into a settings file this afternoon, with the specific bypass each control closes named alongside it. I checked every setting name and every citation below against live docs and live issue trackers as of this writing (2026-07). Claude Code's settings surface moves fast; verify again before you rely on any of it six months from now.