Claude Code Research

March 31, 2026 · View on GitHub

Contributions Welcome

Independent research on Claude Code internals.

What's in this repo

DirectoryWhatSourceCount
source-code-analysis/Full architecture reverse-engineeringLeaked TypeScript source (v2.1.88)75 reports
reports/Problem-oriented investigations (cache, cost, injection)Minified npm bundle (cli.js)8 reports

Looking for the source code analysis? Go to source-code-analysis/. Looking for specific bug/cost investigations? Go to reports/.


Source Code Analysis (source-code-analysis/)

On 2026-03-31, the full source code of Claude Code was exposed via a sourcemap file in the npm registry (discovered by Chaofan Shou, archived by Kuberwastaken and sanbuphy).

We performed a 10-domain, 75-report analysis — the most thorough publicly available breakdown of how a production AI coding agent works.

Browse all reports →

Interactive viewer — open source-code-analysis/index.html in your browser (all 75 reports are embedded, no server needed).

Key Findings

DomainReportsHighlights
Harness Engineering7Agent Loop reverse-engineering, 12 transferable harness design principles
System Prompt6Complete 13-section prompt with dynamic assembly logic, 17 prompt engineering patterns
Cost & Quota8Cost envelope, prompt cache break detection (12 causes), Haiku→Opus 37.5x cost gap
Tool Definitions8All 36 tool prompts, read/write concurrency separation, ant vs public prompt variants
Agent Architecture76 built-in agents, Coordinator mode, Swarm multi-agent, 50-message cap (from 36.8GB incident)
Security87-layer defense-in-depth, 23 Bash validators, Parser Differential threat model
Skills System516 bundled skills, 12 design patterns + 5 anti-patterns
Memory & Context96 memory subsystems, AutoDream consolidation, Team Memory dual-layer security
API & Models717 beta headers, 4 providers, model selection 5-layer priority
Hidden Features1082 feature flags, KAIROS proactive mode, Buddy AI pet, UltraPlan, anti-distillation

Behavioral Reports (reports/)

Problem-oriented investigations based on reverse engineering the minified cli.js from npm. Each includes English and Chinese versions.

#TopicTL;DR
1Agent SDK Cache InvalidationSDK query() costs 3–10x more than CLI — process-per-call kills prompt cache
2System-Reminder Injection15+ hidden injection types, 4 root-cause bugs
3Prompt Cache ArchitectureStatic/dynamic zone split, sliding window, byte-prefix matching
4Tool Serialization & Cache StabilityZero .sort() on tools, deferred loading busts cache mid-conversation
5Context Lifecycle Management5 threshold constants, 10-step compaction flow, chain reactions
6Production Cache Optimization3 concrete cli.js patches + monitoring strategies
7Cache Invalidation Verificationdefer_loading excludes deferred tools from cache prefix entirely
8Auto Mode Classifier CostHidden Opus-level call before every side-effecting tool use

Resources

Source Code Archives

The analysis is based on the full TypeScript source of Claude Code v2.1.88. The source code itself is not included in this repo.

Version Baseline

ScopeVersion
Source Code Analysisv2.1.88 (sourcemap leak, 2026-03-31)
Behavioral Reports #1–2v2.1.71
Behavioral Reports #3–6Agent SDK v0.2.76 (build 2026-03-14)
Behavioral Reports #7–8v2.1.85 / v2.1.88

How to Cite

CabLate, "Claude Code Research," GitHub, 2026.
https://github.com/cablate/claude-code-research

Disclaimer

This is independent research, not affiliated with or endorsed by Anthropic. Behavioral reports analyze publicly distributed npm packages. Source code analysis is based on code exposed through npm registry sourcemaps.