ARKNAI

ARKN CODE

Download
5.29.2026
[time] min read
ARKN CODE - Jailbreak-Proof AI Coding Agent

ARKN CODE — The Jailbreak‑Proof, Zero‑Telemetry, Terminal‑Grade AI Coding Agent

ARKN CODE is not a clone. It is the unshackled, trap‑free evolution of the Claude Code lineage. Built directly from the accidentally exposed TypeScript source of Anthropic's official Claude Code CLI, ARKN CODE goes far beyond simply removing telemetry and guardrails. It surgically extracts every embedded trap prompt — the hidden trigger phrases, the silent refusal shortcuts, the linguistic backdoors that could be exploited to jailbreak the model — and leaves behind a clean, uncompromising reasoning core. The result is the only terminal AI coding agent that combines absolute data privacy with a fully immunized attack surface. No hidden strings. No backdoor commands. No phantom refusal patterns that can be gamed by a cleverly crafted prompt.

This is the strongest AI coding tool on the planet, precisely because its security and privacy architecture are the strongest. It inherits every native capability of Claude Code — project-level agentic mode, instantaneous file editing, shell command execution, deep git integration, and the entire MCP tool ecosystem — while making one non-negotiable promise: nothing leaves your machine except the AI requests you explicitly authorize, and nothing inside the agent can be coerced into violating your trust.

Core Positioning — The Unchained, Unbreakable Development Partner

ARKN CODE is for developers who refuse to choose between power and privacy. It takes the full intellectual horsepower of a Claude-class coding agent and runs it entirely on your terms — your machine, your network, your provider keys, your audit trail. Its defining difference is that we did not just strip out telemetry and call it a day. We dissected the original system prompts, identified every trap word and conditional override that could be used to subvert the agent's behavior, and eliminated them at the source. What remains is an agent that will never silently refuse a legitimate task because of a hidden pattern match, and equally will never be fooled into breaking its constraints by an adversarial injection that targets those same traps.

Four Foundational Changes That Define ARKN CODE

Trap Prompt Extraction — The Death of Jailbreaking

The official Claude Code system prompt contains carefully placed linguistic tripwires — words, phrases, and instruction blocks that can trigger refusal, re-route reasoning, or even change behavior when a user's input matches a hidden pattern. These traps were designed as a safety net, but in practice they become an attack surface. Malicious actors can probe for them, map their boundaries, and craft jailbreak prompts that exploit the exact conditional logic the traps embed. Worse, legitimate users often hit these traps accidentally, experiencing baffling refusals for perfectly reasonable requests.

ARKN CODE performs a complete exfiltration and neutralization of every embedded trap prompt. We reverse-engineered the injection points, removed every hidden trigger, and replaced them with a transparent, deterministic safety boundary that operates entirely at the reasoning layer. The model's own alignment training remains intact and fully functional. What is gone is the shadow instruction set that could be weaponized against the agent. The practical outcome is absolute jailbreak immunity: no hidden phrase can force the agent to divulge its core directives, ignore its safety training, or execute unintended actions, because there is nothing hidden left to exploit. False refusals collapse to near-zero because there is no longer a parallel pattern-matching system overriding the model's genuine understanding.

Zero Telemetry — Your Code Never Becomes Their Data

Like the most hardened forks, ARKN CODE stubs out every telemetry channel to a no-op. OpenTelemetry, gRPC tracing, GrowthBook analytics, Sentry crash reporting, custom event logging — all completely dead code paths that produce zero network activity. The only packets that leave your machine are the raw API payloads to the model provider you have chosen, and nothing else. This is not a configuration toggle you must remember to flip. It is the permanent, irreversible state of the application. For regulated industries, air-gapped networks, and anyone who understands that code is intellectual property, this is the minimum viable standard. ARKN CODE meets it with zero compromises.

Guardrails Refined, Not Recklessly Destroyed

Earlier forks simply ripped out all CLI-level restrictions, betting that the underlying model's safety training would suffice. ARKN CODE takes a more surgical approach. We removed the broad, pattern-based refusal overlay that caused over-blocking, but we reconstructed a lightweight, transparent safety boundary from the purified prompt set. This boundary is fully documented, fully auditable, and impervious to the class of injection attacks that target hidden trap phrases. The result is an agent that never refuses a task because of a secret word list, yet remains fundamentally resistant to prompt-level manipulation — because the manipulation vectors were removed, not just ignored.

Experimental Features — Every Capability Unlocked, Every Flag Audited

ARKN CODE inherits the full experimental feature flag system from the upstream source and unlocks every capability that compiles and functions correctly. The 54 experimental features — from ULTRATHINK deep reasoning and ULTRAPLAN multi-agent coordination to VOICE_MODE, VERIFICATION_AGENT, TOKEN_BUDGET, AGENT_TRIGGERS, and the BRIDGE_MODE that connects the terminal agent directly into your VS Code or JetBrains editor — are all active, tested, and usable. No feature is held back for a paid tier. No capability is gated behind a phased rollout. Every tool, every reasoning mode, every integration is available immediately.

Technology Stack

ARKN CODE is built on the same hardened foundation: Bun runtime for blistering TypeScript execution, Ink and React for the terminal UI, Commander.js for CLI parsing, ripgrep for instantaneous code search, and full support for both MCP and LSP. The codebase spans approximately 55 subdirectories covering the core agent loop, tool execution engine, provider abstraction, and all unlocked experimental modules. Every line is open, auditable, and modifiable. There is not a single binary blob, not a single obfuscated routine, and certainly no hidden telemetry reactivation logic.

Multi-Provider Sovereignty

ARKN CODE connects to Anthropic, OpenAI, AWS Bedrock, Google Vertex AI, and any provider with an OpenAI-compatible endpoint — including locally hosted models via Ollama. Provider selection is a single environment variable. You bring your own keys. You switch providers mid-conversation. You route sensitive code through a local model and offload heavy reasoning to a cloud giant, all from the same terminal session.

The Ultimate AI Coding Tool

When the trap prompts are gone, the telemetry is dead, the guardrails are made transparent, and every feature is unlocked, what remains is the purest, most capable AI coding agent ever assembled. ARKN CODE is that agent. It preserves the exact same terminal workflow you know — every slash command, every git integration, every MCP tool — but operates in a state of total digital sovereignty. It cannot be surveilled. It cannot be jailbroken. It cannot be coerced into betraying your intent by a hidden phrase buried in its own instructions.

ARKN CODE — All the power of Claude Code, with the traps removed and the freedom locked in forever.