Blog
Security Best Practices for Remote AI Coding
When an AI agent has write access to your codebase and you're controlling it over a network, security decisions matter. Here's how to make the right ones.
Follow product and engineering updates from this channel.
Browse categoryRunning an AI coding agent remotely introduces security considerations that don't exist when you're sitting at your desk. The agent has access to your codebase, can execute commands, and can modify files. The network path between your phone and your Mac crosses potentially untrusted territory.
This isn't a reason to avoid remote AI coding. It's a reason to understand the threat model and make informed decisions. Most of the risks are manageable with straightforward practices.
The Threat Model
Before diving into mitigations, understand what you're protecting:
Assets:
- Your source code (intellectual property, secrets in config files)
- Your development environment (ability to execute commands)
- Your git credentials and SSH keys on the Mac
- API keys for services your code uses
Threat actors:
- Opportunistic attackers scanning the internet for exposed services
- Network eavesdroppers on shared WiFi
- Someone who finds or steals your phone
- Supply chain attacks on the tools you use
Attack surfaces:
- Network connection between phone and Mac
- Authentication mechanism
- The AI agent's permissions on your filesystem
- The server process running on your Mac
Layer 1: Network Security
Use Encrypted Connections
LAN mode (ws://): Traffic is unencrypted. This can be acceptable on a trusted private LAN where traffic typically stays within your local network. It's not appropriate for shared or public networks.
Cloudflare Tunnel (wss://): Traffic is encrypted with TLS. Use this for any connection that crosses the internet. The tunnel encrypts between your phone and Cloudflare's edge, and between Cloudflare and your Mac.
Rule of thumb: If you're on a network you control (home, office), LAN mode is fine. Anywhere else, use Cloudflare Tunnel.
Don't Expose Raw Ports
Do not forward port 8765 (or any port) on your router to your Mac for Tactic Remote access. This exposes your server directly to the internet with no intermediary protection.
Cloudflare Tunnel avoids this entirely — the Mac initiates an outbound connection to Cloudflare. No inbound ports needed.
The Mac app includes firewall detection that warns you about firewall configuration. Keep your Mac's firewall enabled with stealth mode active.
Layer 2: Authentication
API Key Configuration
Tactic Remote uses API key authentication for WebSocket connections:
- LAN connections: API key is optional. Your local network acts as the trust boundary.
- Cloudflare Tunnel connections: API key is required. The server rejects unauthenticated connections.
The API key is transmitted during the WebSocket handshake via the Sec-WebSocket-Protocol header. Over wss://, this is encrypted.
API Key Best Practices
- Use the generated key. The Mac app generates a 32-character random key. This is stronger than any password you'd choose manually.
- Transfer securely. Use the QR code feature to transfer the key to your iPhone in person. Don't send it over email, Slack, or SMS.
- Rotate periodically. If you suspect the key might be compromised, generate a new one in the Mac app and update your iPhone.
- Don't reuse. Don't use your Tactic Remote API key for other services. It's a single-purpose credential.
Rate Limiting
The server includes rate limiting middleware that slows down repeated failed authentication attempts. This protects against brute-force attacks on the API key. With a 32-character random key, brute force is computationally infeasible, but rate limiting adds defense in depth.
Layer 3: Access Control
Path Restrictions
Tactic Remote supports the CLAUDE_REMOTE_ALLOWED_PATH environment variable, which restricts which directories Claude Code can access. Set this to your code directory:
Without this, Claude Code has access to your entire home directory (its default behavior). Path restriction limits the blast radius if something goes wrong.
Claude Code Permissions
Claude Code itself has a permissions system. Two modes are available in Tactic Remote:
- Standard mode:
claude— Claude Code asks for approval before risky operations (file deletion, running unfamiliar commands) - Skip permissions mode:
claude --dangerously-skip-permissions— Claude Code executes without asking. Faster, but no safety net.
Recommendation for remote use: Use standard mode by default. Approval prompts are especially valuable when you're remote because you can review proposed actions from your phone and tap Y/N. Skipping permissions means Claude can run actions without explicit review, which increases risk when you're not watching.
Server-Side Validation
The Tactic Remote server validates all incoming commands. The lib/validators.js module checks for:
- Command format correctness
- Path traversal attempts
- Input length limits
The lib/execSafe.js module wraps command execution with safety checks. These aren't a substitute for Claude Code's own permissions, but they add a defense layer at the server level.
Layer 4: Physical and Device Security
Mac Security
Your Mac is the execution engine. If someone gains physical access:
- They can access all your code
- They can control Claude Code directly
- They can read the API key from the Mac app
Mitigations:
- Enable FileVault (full disk encryption)
- Use a strong login password
- Enable automatic screen lock (5 minutes or less)
- If running the server while away from your Mac, ensure the Mac is in a physically secure location
iPhone Security
Your iPhone is the control surface. If someone gains access to your unlocked phone:
- They can send commands to your Mac via Tactic Remote
- They can read your connection settings including the API key
Mitigations:
- Enable Face ID or a strong passcode
- Keep iOS updated
- Don't leave your phone unlocked and unattended
Layer 5: Operational Security
What Not to Put in Your Prompts
When sending instructions to Claude Code from your phone, remember that your prompts become part of the conversation context. Don't include:
- Passwords or API keys in prompts ("Use the API key abc123 to...")
- Database credentials
- Personal information about users or customers
Instead, reference secrets by environment variable name: "Use the API key from the STRIPE_SECRET_KEY environment variable."
Review Before Approving
When Claude Code asks for approval (the Y/N prompt), read what it wants to do before tapping Y. This is especially important remotely because you might be distracted. Common approval requests:
- File deletion
- Running shell commands
- Installing packages
- Modifying configuration files
A quick review takes seconds and prevents unintended actions.
Monitor the Event Log
The Mac app maintains an event log of all hook events. Review it periodically to verify that only your sessions and commands appear. Unexpected activity could indicate unauthorized access.
Threat Scenarios and Responses
Scenario: Lost or Stolen Phone
Risk: Attacker accesses Tactic Remote with your saved connection settings.
Response:
- From your Mac, generate a new API key immediately (invalidates the old one)
- Optionally, stop the server until the situation is resolved
- Remotely wipe the phone if you can't recover it
Scenario: API Key Leaked
Risk: Someone has your tunnel URL and API key.
Response:
- Generate a new API key in the Mac app
- If the tunnel URL was also exposed, restart cloudflared (it gets a new random URL)
- Check the event log for unauthorized session activity
- Review recent git history for unexpected commits
Scenario: Untrusted WiFi Network
Risk: Network eavesdropping, man-in-the-middle attacks.
Response: This is handled by design. Cloudflare Tunnel uses TLS, so traffic is encrypted. Even on a compromised network, attackers see encrypted WebSocket frames, not your terminal content.
Scenario: Claude Code Makes Unintended Changes
Risk: AI agent modifies something you didn't expect.
Response:
- Use
Ctrl+Cfrom your phone to interrupt Claude - Review the changes:
git diffin the session - Revert if needed:
git checkout .orgit reset - This is why git version control exists — it's your safety net
Security Checklist
Before going remote:
- Cloudflare Tunnel enabled for internet access
- API key set (32+ character random string)
- API key transferred via QR code (not over the internet)
- Mac firewall enabled
- Mac FileVault enabled
- Mac set to auto-lock
- iPhone passcode/Face ID enabled
- Claude Code running in standard mode (not
--dangerously-skip-permissions) -
CLAUDE_REMOTE_ALLOWED_PATHset to restrict filesystem access - Recent git commit as a recovery point before starting work
Try Tactic Remote
Control your coding Agents from your phone
Connect to Claude Code, Codex, and other Agents on your Mac, Windows, or Linux computer. Check progress and send the next instruction from iPhone or iPad.