Prompt Injection Defense Toolkit for Claude Code Users
Detect injected instructions in fetched content, audit tool call chains, and run agentic workflows safely — the prompt injection defense guide Anthropic hasn't written yet.
- ▸Prompt Injection Defense Guide — 7-chapter reference covering threat modeling, detection, CLAUDE.md hardening, MCP trust policy, tool-call auditing, and incident response
- ▸Hardened CLAUDE.md Template — drop-in configuration with injection-resistant pre-wiring; copy to any project, fill in four fields, done
- ▸MCP Trust Policy Reference — four-tier risk model, 20-item per-server vetting checklist, and .mcp.json allowlist patterns
- ▸Injection Detection Heuristics — 25 red-flag patterns in fetched content, from naive override phrases to obfuscated Unicode tricks and multi-turn persistence attacks
- ▸Tool-Call Audit Log Template — structured session log to track what Claude Code called, what it returned, and whether you reviewed it
- ▸Pre-Flight Checklist — 20-item pre-session checklist covering CLAUDE.md state, MCP server scope, and environment verification
## goes-well-with
From the same shelf
Agentic Migration Playbook: API Endpoint Modernization
For DevOps and platform engineers with a real migration deadline — the complete Claude Code workflow you'd otherwise spend months reverse-engineering.
MAESTRO Security Framework for Claude Code Projects
Apply the MAESTRO 7-layer threat-modeling framework to any autonomous Claude Code / Agent SDK project — enumerate threats across the whole chain and fill in a reusable threat model for your own stack.
MCP Tunnel Explainer: Private Network MCP Without Public Endpoints
A hands-on tutorial and code walkthrough showing how to wire a local Ollama MCP server behind an outbound-only encrypted tunnel — no public IP, no inbound firewall rules, yet agents still reach private enterprise tools.
## not-ready-to-buy
Take the field notes instead
One practical write-up a week from the same workbench these kits come from — plus reader pricing when new kits ship.