probing-claude-codelisted
Install: claude install-skill flxxxxddd/claude-account-manager
# Probing Claude Code
This project encodes Claude Code's private behaviour, so every claim about that
behaviour must come from the shipped binary or a live `claude`, never from memory.
## Find the binary
```bash
readlink -f "$(command -v claude)" # → ~/.local/share/claude/versions/<version>
```
It is a Bun single-file executable: the JavaScript is embedded as plain strings.
## Read it
```bash
B=$(readlink -f "$(command -v claude)")
strings -a "$B" | grep -oE ".{200}CLAUDE_SECURESTORAGE_CONFIG_DIR.{200}" | head
```
Anchor on an identifier and widen the window until whole functions appear. Useful
anchors: `CLAUDE_CONFIG_DIR`, `-credentials`, `find-generic-password`, `/api/oauth/`,
`refresh_token`.
Two cautions:
- Very wide `grep -oE` windows hit ugrep's complexity limit. Narrow the window or
anchor on a longer literal instead.
- **Absence is evidence.** `add-generic-password` appearing nowhere is what established
that Claude Code never writes the keychain through the CLI — which is why the macOS
backend writes the file.
## Confirm against a running claude
Reading the binary produces a hypothesis. This is the proof:
```bash
CLAUDE_SECURESTORAGE_CONFIG_DIR=/tmp/probe claude auth status # expect loggedIn:false
claude auth status # unchanged
```
`claude auth status --json` prints `loggedIn`, `email`, `orgId` and `subscriptionType` —
enough to tell which credential slot Claude Code actually resolved. Establish pre