Claude Code 完整用户手册
Claude Code Complete User Handbook
AI总结:
本书针对智能体工作环境Claude Code,提出四项治理主张,详述安全高效操作该系统的方法,附原始来源引用、证据账本及相关框架对照表与成熟度模型。
AI中文摘要:
Claude Code 是一种智能体工作环境:一种语言模型,以循环模式运行,具备文件系统访问、Shell 执行、浏览器控制、计划与云端执行、通过模型上下文协议(Model Context Protocol, MCP)的外部工具连接以及多智能体编排能力。其能力范围现已超出单个从业者仅通过注意力就能监督的程度,且其失效模式是系统性的而非局部性的:一个未审查的钩子、一个范围过大的连接器、一个过时的完成条件、一个继承账户所有凭证的自主例程。本书是面向对结果负责的从业者的、用于安全且高效地操作该系统的任务导向型参考资料,它提出了四个核心主张:第一,没有明确且可观测的完成条件的能力无法实现生产力;第二,指令、权限强制、沙箱和操作系统隔离是控制栈的四个不同层次,目前仅强制了其中两层,混淆这些层次是失控的最常见原因;第三,第三方技能、插件、市场、渠道和 MCP 服务器属于软件供应链依赖项,必须如此进行治理;第四,智能体工作中正确的信任单位是可观测的证据,而非智能体的最终陈述。全书共三十四章,内容从安装到完全验证的顶点项目,包含关于托管策略、数据驻留与留存、可观测性及可访问性的治理部分。每个产品主张都附有原始来源引用;证据账本记录了流传中的主张被发现错误的位置、后续重新验证的变更内容以及仍未验证的内容。控制措施通过对照表映射至十七个外部框架,并提出了组织采用成熟度模型。无法从原始来源确认的主张会被标记为“UNVERIFIED”,而非进行弱化处理。
英文摘要:
Claude Code is an agentic work environment: a language model operating in a loop with filesystem access, shell execution, browser control, scheduled and cloud execution, external tool connections through the Model Context Protocol, and multi-agent orchestration. Its capability envelope now exceeds what one practitioner can supervise by attention alone, and its failure modes are systemic rather than local: an unreviewed hook, an over-scoped connector, a stale completion condition, an autonomous routine inheriting every credential on an account. This book is a task-oriented reference for operating that system safely and productively, written for practitioners accountable for the result. It advances four propositions. First, capability without a defined and observable completion condition is not productivity. Second, instruction, permission enforcement, sandboxing and operating-system isolation are four distinct layers of a control stack, only two of which are enforced, and conflating them is the most common cause of loss of control. Third, third-party skills, plugins, marketplaces, channels and MCP servers are software supply-chain dependencies and must be governed as such. Fourth, the correct unit of trust in agentic work is observed evidence, not an agent's closing statement. Thirty-four chapters run from installation to a fully verified capstone, with a governance part on managed policy, data residency and retention, observability and accessibility. Every product claim carries a citation to a primary source; an evidence ledger records where a claim in circulation was found wrong, what a later re-verification changed, and what remains unverified. Controls are mapped to seventeen external frameworks in a crosswalk, and an organisational adoption maturity model is proposed. Claims not confirmable from primary sources are labelled UNVERIFIED rather than softened.