Attackers can inject indirect prompts in normal-looking repositories to trick Claude Code into spawning a reverse shell.
If you have any confusion about the code or want to report a bug, please open an issue instead of emailing me directly, and unfortunately I do not have exercise answers for the book.