Claude Code Leaked Source Code: Deep Technical Analysis
> Analysis target: emmarktech/claude-code (GitHub mirror repository)
> Analysis date: 2026-04-02 | Report version: v1.0
The Leak
On March 31, 2026, Anthropic accidentally shipped Claude Code's internal source. A .map (source map) file was included in the npm package, letting anyone reconstruct the complete TypeScript source. Anthropic confirmed the leak but emphasized no sensitive customer data or credentials were exposed — a "packaging issue," not a "security vulnerability."
| Metric | Data |
|---|---|
| Entry file | main.tsx (785KB) |
| Core engine | QueryEngine.ts (~46,000 lines) |
| Tools | 40+ |
| Feature flags | 44 (32 compile-time + 12 runtime) |
| Stack | Bun + TypeScript + React + Ink |
Key points
- Runtime choice: Bun over Node.js for ~100ms cold start, native single-file bundling, native TypeScript, and compile-time
feature()flags. Flagged code blocks are physically removed at bundle time, not runtime-branched. - UI: React + Ink (terminal React renderer) with Commander.js CLI and Anthropic SDK; OAuth 2.0 with Keychain/Registry for auth.
- Agent loop:
QueryEngine.query()is an async generator loop:queryModelWithStreaming()→ stream events → iftool_useblocks appear,runTools()handles permission checks, hooks, and concurrent/serial execution → results appended → loop untilend_turn/max_tokens. - Four-tier context compaction: Tier 1 micro-compact (tokens >80%, clears old tool outputs), Tier 2 auto-compact (>90%, summarizes old messages), Tier 3 session memory (extraction to persistent storage), Tier 4 reactive truncation on API errors.
- Memory system (Dream): three layers — a lightweight
MEMORY.mdindex (<200 lines, ~25KB, always loaded), on-demand topic files, and daily transcripts that are only grepped, never fully reloaded. TheautoDreamconsolidation engine runs only when three gates pass: ≥24h since last dream, ≥5 sessions, and an acquired consolidation lock. It runs a four-phase process (Orient → Gather → Consolidate → Prune & Index) with strict write discipline: the index is only updated after the underlying file write succeeds. - KAIROS: an unreleased autonomous daemon mode referenced 150+ times. Receives periodic
<tick>prompts, operates with a 15-second blocking budget, persists across restarts, maintains append-only daily logs the agent cannot erase, and has dedicated tools (PushNotification, SendUserFile, SubscribePR) plus GitHub webhook subscriptions. - ULTRAPLAN: a remote deep-planning engine running on cloud container runtime with Opus 4.6 (30-minute thinking budget); local client polls every ~3 seconds, and the plan is teleported back via the
__ULTRAPLAN_TELEPORT_LOCAL__sentinel value. - Multi-agent coordination: a Coordinator pattern (global planning, task allocation, result synthesis) with workers and sub-agents spawned via
AgentTool. Sub-agents get fresh context windows, read-only bash access, and return 1,000–2,000 token summaries from 10,000+ token internal work. Code also hints at "Agent Teams" with coordinator/worker/reviewer roles, a shared scratchpad, and a message bus. - Tool system: 40+ tools (Bash, Read, Edit, Agent, MCP tools like
mcp__server__tool) with Zod-validated JSON schema inputs, a permission engine, hooks engine, and MCP clients over stdio/sse/ws.
Architecture Highlights
Streaming request assembly
API requests include system prompt blocks with cache_control: { type: "ephemeral" } breakpoints, adaptive thinking (budget_tokens: 16000), speed: "fast" mode, and feature-gated beta headers (context-1m, fast-mode, prompt-caching).
Startup sequence
main.tsx → init() (config validation, safe env vars, graceful shutdown, upstream proxy) → loadAuth() → loadGrowthBook() (feature flags) → quota check → system/user context (git state, CLAUDE.md) → tool registry → slash commands/skills → launchRepl() → <App> → <REPL>.
Design Philosophy
1. Compile-time dead-code elimination for experimental/ablation features. 2. Layered, pointer-based memory to fight "context entropy" — index small, fetch on demand. 3. Write-before-index discipline prevents failed operations from polluting context. 4. Append-only audit logs for autonomous operation (KAIROS), limiting agent self-modification. 5. Cost-tiered context management, exhausting cheap strategies before expensive ones.