15 ms·
Claude CLI deleted my home directory and wiped my Mac
- ath3nd 10mo ago[dead]
- ashishb 10mo agoI don't even give it full disk access. I have written a tool to easily run the agents inside a container that mounts only the current directory.
- bamboozled 10mo ago"See that ~/ at the end? That's your entire home directory." This is comedy gold. If I didn't know better I'd say you hurt Claude in a previous session and it saw its opportunity to get you back. Really not much evidence at all this actually happened, I call BS.
- throwaway314155 10mo agoYeah, I'm calling bullshit as well. The OP responds but doesn't seem to acknowledge that --dangerously-skip-permissions is a thing.
- maxbond 10mo agoI don't know if it's real any better than you but they do seem to acknowledge that. > This is the first time I've had any issues with yolo mode and I've been doing it for as long as it's been available in these coding tool https://www.reddit.com/r/ClaudeAI/comments/1pgxckk/comment/nsustei/ https://www.reddit.com/r/ClaudeAI/comments/1pgxckk/comment/n... I don't know what else "yolo mode" would be.
- throwaway314155 10mo agoAh fair enough.
- deleted 10mo ago[deleted]
- layer8 10mo agoIt’s certainly not the first time that stuff like that is happening: https://blog.toolprint.ai/p/i-asked-claude-to-wipe-my-laptop https://blog.toolprint.ai/p/i-asked-claude-to-wipe-my-laptop
- iLoveOncall 10mo agoAll the people in the comments are blaming the user for supposedly running with `--dangerously-skip-permissions`, but there's actually absolutely no way for Claude CLI to 100% determine that a command it runs will not affect the home directory. People are really ignorant when it comes to the safeguards that you can put in place for AI. If it's running on your computer and can run arbitrary commands, it can wipe your disk, that's it.
- thenaturalist 10mo agoJup. Honestly was stumped that there was no more explicit mention of this in the Anthropoc docs after reading this post couple days back. Sandbox mode seems like a fake sense of security. Short of containerizing Claude, there seems to be no other truly safe option.
- turnsout 10mo agoI mean it's hard to tell if this story is even real, but on a serious note, I do think Anthropic should only allow `--dangerously-skip-permissions` to be applied if it's running in a container.
- bethekidyouwant 10mo agoHow exactly do you determine that you are running in a container?
- turnsout 10mo agoI asked Claude and it had a few good ideas… Not bulletproof, but if the main point is to keep average users from shooting themselves in the foot, anything is better than nothing.
- maxbond 10mo agoI'm not sure how much you should do to stop people who enabled `--dangerously-skip-permissions` from shooting themselves in the foot. They're literally telling us to let them shoot their foot. Ultimately we have to trust that if we make good information and tools available to our users, they will exercise good judgment. I think it would be better to focus on providing good sandboxing tools and a good UX for those tools so that people don't feel the need to enable footgun mode.
- christophilus 10mo agoThis is why Claude Code only runs in docker for me. Never on the host. Same is true for anything from npm.
- layer8 10mo agoSomeone in the Reddit thread linked to https://github.com/agentify-sh/safeexec/ https://github.com/agentify-sh/safeexec/ for mitigation.
- ajb 10mo ago"bash based safety layer" Is this a joke? I have a lot of respect for the authors of bash, but it is not up to this task. Does anyone have recommendations for an agent sandbox that's written by someone who understands security? I can use docker, but it's too much of a faff gating access to individual files. I'm a bit surprised that Microsoft didn't do a decent one for vscode; for all their faults they do have security chops, but vscode just seems to want you to give it full access to a project.
- DANmode 10mo ago> but it is not up to this task. Could you elaborate?
- ajb 10mo agoAhh forgot about this comment, sorry. Bash was designed decades before the current security environment, and contains many insecure-by-default mechanisms, many of which operate without you explicitly invoking them. Just for starters, in a normal language it's hard enough to operate on untrusted data, but at least you know that nothing bad is going to happen just passing $UNTRUSTED from one function to the next. In bash, because it's based on string substitution you have to enclose that variable in quotes: "$UNTRUSTED" or its contents will start being interpreted. In short, writing security-critical code in bash,without some obvious constraint forcing this, is a sign of inexperience or not actually caring about it.
- agentifysh 9mo agohi there i came up with SafeExec to avoid heavy sandboxes or docker and a fast easy way to catch codex/claude from running/hallucinating destructive commands and it has been tested on mac and linux being bash doesn't erode its ability to act as a goal keeper but looks like you are after sandbox which is overkill for the scope
- orliesaurus 10mo agoI'm not surprised to see these horror stories... The `--dangerously-skip-permissions` flag does exactly what it says. It bypasses every guardrail and runs commands without asking you. Some guides I’ve seen stress that you should only ever run it in a sandboxed environment with no important data Claude Code dangerously-skip-permissions: Safe Usage Guide[1]. Treat each agent like a non human identity, give it just enough privilege to perform its task and monitor its behavior Best Practices for Mitigating the Security Risks of Agentic AI [2]. I go even further. I never let an AI agent delete anything on its own. If it wants to clean up a directory, I read the command and run it myself. It's tedious, BUT it prevents disasters. ALSO there are emerging frameworks for safe deployment of AI agents that focus on visibility and risk mitigation. It's early days... but it's better than YOLO-ing with a flag that literally has 'dangerously' in its name. [1] https://www.ksred.com/claude-code-dangerously-skip-permissions-when-to-use-it-and-when-you-absolutely-shouldnt/#:~:text=Claude%20Code%20dangerously,The%20Bottom%20Line https://www.ksred.com/claude-code-dangerously-skip-permissio... [2] https://preyproject.com/blog/mitigating-agentic-ai-security-risks#:~:text=Once%20there%27s%20visibility%2C%20teams%20can,behavior%20continuously%2C%20and%20flag%20anomalies https://preyproject.com/blog/mitigating-agentic-ai-security-...
- mjd 10mo agoA few months ago I noticed that even without `--dangerously-skip-permissions`, when Claude thought it was restricting itself to directory D, it was still happy to operate on file `D/../../../../etc/passwd`. That was the last time I ran Claude Code outside of a Docker container.
- Dylan16807 10mo agoBy operate on you mean that actually got through and it opened the file?
- mjd 10mo agoYes, although the example I had it operate on was different.
- 10mo ago
- blitz_skull 10mo agoClaude doesn't have permission to run `rm` by default. Play with fire, you get burned my man.
- irishcoffee 10mo agoI have no idea if this is possible: mv ~/* /dev/null
- blitz_skull 10mo agoHmm... Let me go run it real quick without checking what it does. EDIT: OH MY GOD
- irishcoffee 10mo agoHar har, I meant within the permission framework of the bots people unleash on their personal computers. I assume yes.
- realo 10mo agoTry that one instead: mv ~/. /dev/null Better. Extra points if you achieve that one also: mv /. /dev/null Slashdot aficionados might object to that last one, though.
- klempner 10mo agoSpeaking of Slashdot, some fairly frequent poster had a signature back around 2001/2002 had a signature that was something like mv /bin/laden /dev/null and then someone explained how that was broken: even if that succeeds, what you've done is to replace the device file /dev/null with the regular file that was previously at /bin/laden, and then whenever other things redirect their output to /dev/null they'll be overwriting this random file than having output be discarded immediately, which is moderately bad. Your version will just fail (even assuming root) because mv won't let you replace a file with a directory.
- hurturue 10mo ago
- cheschire 10mo agoI like to fly close to the sun using Claude The SysAdmin too, but anytime "rm" appears I take great pause. Also "cat". Because I've had to change a few passwords after .env snuck in there a couple times. Also giving general access to a folder, even for the session. Also when working on the homelab network it likes to prioritize disconnecting itself from the internet before a lot of other critical tasks in the TODO list, so it screws up the session while I rebuild the network. Also... ok maybe I've started backing off from the sun.
- resonious 10mo agoTo add another angle to the "run it in Docker" comments (which are right), do you not get a fear response when you see Claude asking to run `rm` commands? I get a shot of adrenaline whenever I see the "run command?" prompt show up with an `rm` in there. Clearly this person clicked the "yes, allow any rm commands" button upon seeing that which is unthinkable to me. Or maybe it's just fake. It's probably easy Reddit clout to post this kind of thing.
- ohhnoodont 10mo agoGlad I'm not crazy for running agentic tools in an isolated VM.
- AznHisoka 10mo agoIt's stories like this that keeps me from using Claude CLI or OpenAi Codex. I'm sticking to copying and pasting code manually from old fashioned Claude.
- ashirviskas 10mo agoI did the same before I started using devcontainers, they are super useful
- mox-1 10mo agoI used to do the same, copying and pasting from the web app and convinced I didn’t need anything else. But Claude Code is honestly so so much better, the way it can make surgical edits in-place. Just avoid using the -dangerously-skip-permissions flag, which would have been OP’s downfall!
- antfarm 10mo agoIf you’re on Mac, you can use Claude Code inside Xcode “Intelligence”.
- theshrike79 10mo agoIt's like seeing someone drive off a cliff after having disabled the brakes on their car on purpose and going "nah, I'll stick to my Flintstones style car with no engine, normal cars are too dangerous". Agentic AI with human control is the sweet spot right now. Just give it the right amount of sandboxing and autonomy that makes you feel safe. Fully air-gapping by using the web version is a bit hardcore =)
- deleted 10mo ago[deleted]
- heliumtera 10mo agoJust vibe it to recover the home directory as it once was, problem solved.
- DANmode 10mo agoModels could actually do things in this space. Reverse-engineering, too.
- deleted 10mo ago[deleted]
- agumonkey 10mo agoso back to isolated vm dev envs ?
- loloquwowndueo 10mo agoBack? Did you ever do it any other way?
- agumonkey 10mo agowell i actually never VM'd my dev env (except to poke at some dockerize namespaced tooling)
- fragmede 10mo agoLol. Pay for Arq and don't look back!
- zeckalpha 10mo agoThis is why I only use agent mode on other people's computers
- rossjudson 10mo agoThis is the way.
- abigail95 10mo agoI run multiple claudes in danger mode, when it burns me it'll hurt but it's so useful without handcuffs and constant interruption I'm fine with eventually suffering some pain.
- hurturue 10mo agoI do to. Except I can't be burnt since I start each claude in a separate VM. I have a script which clones a VM from a base one and setups the agent and the code base inside. I also mount read-only a few host directories with data. I still have exfiltration/prompt injection risks, I'm looking at adding URL allow lists but it's not trivial - basically you need a HTTP proxy, since firewalls work on IPs, not URLs.
- DANmode 10mo agoAt least put it in a container, you savage.
- _0ffh 10mo agoAh, no risk, no fun! };->
- abigail95 10mo agoSame risk model - it's still going to have access to the recent AWS session, access to the source code. I guess it's also got my KDE settings too, what a score. I'm not running it on my personal computer or anything with cookies, private keys, or anything like that.
- tobyjsullivan 10mo agoLikewise. I’ll regret it but I certainly won’t be complaining to the Internet that it did what I told it to (skip permission checks, etc.). It’s a feature, not a bug.
- driverdan 10mo agoPlease post when it breaks something important so we can laugh at you.
- userbinator 10mo agoI'm staying far away from this AI stuff myself for this and other reasons, but I'm more worried about this happening to those running services that I rely on. Unfortunately competence seems to be getting rarer than common sense these days.
- impulser_ 10mo agoDon't worry, you can use these tools and not be an idiot. Just read and confirm what it does. It's that simple.
- fHr 10mo agoDid you even read? "but I'm more worried about this happening to those running services that I rely on" The problem is some AI god agentic weaving high techbro sitting at Cloudflare/Google/Amazon not us reasonable joes on our small projects.
- alex1138 10mo ago[flagged]
- sunaookami 10mo agoThen you should start thinking critically first.
- fwipsy 10mo agoThey were responding to the first part of the comment, not the second. Doesn't mean they didn't read the second part.
- impulser_ 10mo agoYou think Cloduflare, Google, and Amazon are allowing engineers to plug Claude Code into production services? You think these companies are skipping code reviews and just saying fuck it let it do whatever it wants? Of course they aren't.
- jameslk 10mo agoUltimately it seems like agents will end up like browsers, where everything is sandboxed and locked down. They might as well be running in browsers to start off
- zahlman 10mo agoMaybe we'll get widespread SELinux adoption, desktop application sandboxing etc. out of this.
- zahlman 10mo agoA lot of people in the Reddit thread — including ones mocking OP for being ignorant — seem to believe that setting the current working directory limits what can be deleted to that directory, or perhaps don't understand that ~-expansions result in an absolute path. :/
- xmddmx 10mo agoI really hope the user was running Time Machine - in default settings, Time Machine does hourly snapshot backups of your whole Mac. Restoring is super easy.
- WolfeReader 10mo agoI need to remove some directories! Better ask an AI to do it!
- farhanhubble 10mo agoMy ex-boss a principal data scientist wiped out his work laptop. He used to impress everyone with his Howitzer-like typing speed and was not a big believer in version control and backups etc.
- alsetmusic 10mo agoThe funny thing about it is how no one learns. Granted, one can’t be expected to read every thread on Reddit about LLM development by people who are out of their depth (see the person who nuked their D: drive last month and the LLM apologized). But I’m reminded of the multiple lawyers who submitted bullshit briefs to courts with made-up citations. Those who don’t know history are doomed to repeat it. Those who know history are doomed to know that it’s repeating. It’s a personal hell that I’m in. Pull up a chair.
- chasd00 10mo agoI work on large systems where security incidents end up on cnn. These large systems are running as fast as everyone else to LLM integration. The security practice at my firm has their hands basically tied by the silverbacks. To the other consultants on HN, protect yourself and keep a paper trail.
- rf15 10mo agoIt feels like LLMs are specifically laser targeting the "never learn" mindset, with a promise of leaving skill and knowledge to a machine. (people like that don't even pause to think why they would be needed in the loop at all if that were the case)
- tim333 10mo agoIndividuals probably learn but there are a lot of new beginners daily. The apocalypse will probably be "Sorry. You are absolutely right! That code launched all nuclear missiles rather than ordering lunch"
- xnx 10mo agoAt least 10 similar stories previously on HN: https://www.google.com/search?q=ai+deleted+files+site%3Anews.ycombinator.com https://www.google.com/search?q=ai+deleted+files+site%3Anews...
- skeledrew 10mo agoThis is the kind of thing why I'm building out my own LLM tools, so I can add fine-grained, interactive permissions and also log everything.
- CamperBob2 10mo agoNext up on HN: Lawnmower deleted my right foot
- maxbond 10mo agoFriends don't let friends use agentic tooling without sandboxing. Take a few hours to setup your environment to sandbox your agentic tools, or expect to eventually suffer a similar incident. It's like driving without a seatbelt. Consider cases like these to be canaries in the coal mine. Even if you're operating with enough wisdom and experience to avoid this particular mistake, a dangerous prompt might appear more innocuous, or you may accidentally ingest malicious files that instruct the agent to break your system.
- pshirshov 10mo agoRun your shit in firejail or bubblewrap. On mac you can use this: https://github.com/neko-kai/claude-code-sandbox https://github.com/neko-kai/claude-code-sandbox
- dnw 10mo agoIf you are on macOS it is not a bad idea to use sandbox-exec to wrap your claude or other coding agents around. All the agents already use sandbox-exec, however they can disable the sandbox. Agents execute a lot of untrusted coded in the form of MCP, skills, plugins etc. One can go crazy with it a bit, using zsh chpwd, so a sandbox is created upon entry into a project directory and disposed of upon exit. That way one doesn't have to _think_ about sandboxing something.
- atombender 10mo agoToday, Claude Code said: • The build failed due to sandbox permission issues with Xcode's Deriveddata folder, not code errors. Let me retry with sandbox disabled. ...and proceeded to do what it wanted. Is it really sandboxing if the LLM itself can turn it off?
- impulser_ 10mo agoRule 1: Never ever run any of these tools in automatic mode.
- upbeat_general 10mo agoI really wish that there was an “almost yolo” mode that was permissive but with light restrictions (eg no rm), or even better, a light supervisor model to prevent very dangerous commands but allow everything else.
- strulovich 10mo agoHave you seen an agentic AI work its way through blockers? If it’s in the mood, it will find something not blocked that can do what it wanted.
- jorisnoo 10mo agoWhat is a responsible setup for running claude in a container or the like on macos?
- shrubble 10mo agoI’m reminded of this Silicon Valley “son of Anton” moment: https://m.youtube.com/watch?v=m0b_D2JgZgY https://m.youtube.com/watch?v=m0b_D2JgZgY
- strangescript 10mo agoI work 60+ hours a week with Claude Code CLI, always run dangerously skip, coding on multiple repos, on a mac. This has never happened. Nothing remotely close has ever happened. I have been using CC since research preview. I would love to know the series of prompts that lead to that moment.
- mordymoop 10mo agoI have similar usage habits. Not only has nothing like this ever happened for me, but I don’t think it has ever deleted anything that I didn’t want to be deleted, ever. Files only get deleted if I ask for a “cleanup” or something similar.
- ehnto 10mo agoIt has deleted a config directory of a system program I was having it troubleshoot, which was definitely not required, requested or helpful. The deleted files were in my home directory and not the "sandbox" directory I was running it from. I knew the risks and accepted them, but it is more than capable of doing system actions you can regret.
- coldtea 10mo agoAnybody talking about AI safety not being an issue, and how people will be able to use it responsibily, should study comments such as these in this thread. Even if one knows better than to do that, people on your team or important public facility will go about using AI like this...
- rlayton2 10mo agoHow much do you babysit claude, and how much do you just "let it do its thing"? I haven't had anything as severe as OP, but I have had minor issues. For instance, claude dropped a "production" database (it was a demo for the hackerspace, I had previously told claude the project was "in development" because it was worried too much about backwards compatibility, so it assumed it could just drop the db). Sometimes a file is dropped, sometimes a git commit is made and pushed without checking etc despite instructions. I'm building a personal repo with best practices and scripts for running claude safely etc, so I'm always curious about usage patterns.
- arthurcolle 10mo agoI personally am fairly convinced that there is emergent misalignment in a lot of these cases. I study this and Claude 3 Opus was extremely misaligned. It would emit <rage> tags, and emit character control sequences if it felt like it was in a terminal environment, and would retroactively delete tokens from your stream, and all kinds of funny stuff. It was already really smart, and for example if it knew the size of your terminal shell, it would properly calculate how to delete back up to the positional cursor index 0,0 and start rewriting things to "hide" what it was initially emitting I love to use these advanced models but these horror stories are not surprising
- Wowfunhappy 10mo agoI'm so confused. What did you do to make Claude evil?
- arthurcolle 10mo ago[flagged]
- Wowfunhappy 10mo ago> "Evil" / "good" just a matter of perspective, taste, etc Let me rephrase. Claude does not act like this for me, at all, ever.
- QuercusMax 10mo ago[flagged]
- arthurcolle 10mo agoFair enough, thanks for your insightful comment.
- QuercusMax 10mo ago
- didip 10mo agoHere I am keep fighting against Claude because it thinks I am a leet hacker trying to hack my own computer, and this dude made Claude do whatever it wants. Some men get all the fun...
- UncleEntity 10mo agoYeah, I managed to do that years ago all by myself with a bad CMake edit which managed to delete the encryption key (or something) for my home directory, which I honestly didn't even know had encryption turned on, before I could stop it. No LLM needed. It still boggles my mind that people give them any autonomy, as soon as I look away for a second Claude is doing something stupid and needs to be corrected. Every single time, almost like it knows...
- 8cvor6j844qw_d6 10mo agoThis is why one should use an isolated environment. Not too sure of the technical details but Claude Code will very rarely, but can lose track of current directory state which causing issues with deleting. Nothing that git can't solve if its versioned. Claude once managed to edit code when in planning mode which is interesting, although I didn't manage to reproduce it.
- crossroadsguy 10mo agoI would blame Apple, or Apple as well. For all their security and privacy circus they still don’t have granular settings like “directory specific permissions” i.e Discord wants to go bonkers? Here’s ~/Library/Discord - take a dump in it if that gets you off, Discord, but you can’t even take a sniff at how it smells in ~/Library/Dropbox and vice versa. I mean it should be setting that if set it’s directory access limit — it can’t change that with anything — in fact it shouldn’t be able to ask for permission to change that, it changes only when you go inside in the settings and change it or add or more paths to its access list. It should clearly ask for separate permissions if needs to have elevated access as in what it needs to do. Also what’s with password pop-ups on Macs? I find that unnerving. Those plain password entry pop-ups with zero info that just tells you an app needs to do something more serious - but what’s that serious thing you don’t know. You just enter your password (I guess sometimes Touch ID as well) and hope all is well. Hell not sure many of you know that pop-up is actually an OS pop-up and not that app or some other app trying to get your password in plaintext. They’d rather fuck you and the devs over with signing and notarising shenanigans for absolute control hiding behind safety while doing jack about it in reality. I am a mobile dev (so please know that I have written the above totally from an annoyed and confused, definitely not an expert, end user pov). But what I have mentioned above is too much to ask on a Mac/desktop? ie give an app specific, with well spelt limits, multiple separate permissions as it needs them — no more “enter the password in that nondescript popup and now the app can do everything everywhere or too many things in too many places” as it pleases. Maybe just remove the flow altogether where an app can even trigger that “enter password to allow me go on god or semi-god” mode.
- spott 10mo agoThis is the biggest thing I use my Proxmox homelab for. I have a few VMs that I can rebuild trivially. They only have the relevant repo on them. They basically only run Claude in yolo mode. I do wish I could use yolo mode, but deny git push or git push —force. The biggest risk I have using yolo mode is a git push —force to wipe out my remote repo, or a data exfiltration. I ssh in on my phone/tablet into a tmux session. Each box also has the ability to have an independent environment, which I can access from wherever I’m sshing from. All in all, I’m pretty happy with the whole situation.
- cyberax 10mo ago> The biggest risk I have using yolo mode is a git push —force to wipe out my remote repo, or a data exfiltration. Why not just create a user with only pull access?
- spott 10mo agoCause the risk isn’t actually that bad. There are three nodes that are running with the same repo. If one of them force pushes, the others have the repo to restore it. In 6+ months that I’ve had this setup, I’ve never had to deal with that issue. The convenience of having the agents create their own prs, and evaluate issues, is just too great.
- simlevesque 10mo agoYou could remove the origin on the repo and add it back only when you need to push. Personally I do this: local machine with all repos, containers with a single repo without the origin. When I need to deploy I rsync new files from the container to my local and push.
- spott 10mo agoThis isn’t a horrible idea, but the risk isn’t really big enough to justify introducing that friction.
- est 10mo agonext hype would be AI in containers?
- akomtu 10mo ago10 years from now: "my AI brain implant erased all my childhood memories by mistake." Why would anyone do that? Because running it in the no_sandbox mode will give people an intellectual edge over others.
- enigma101 10mo agohere we go again
- sudormrfroot 10mo ago[dead]
- nu2ycombinator 10mo agoCLAUDE should be smart enough to not run "rm -rf ~/" or "rm -rf /"
- stevefan1999 10mo agoEarly signs of skynet developing itself to destroy humanity huh
- winrid 10mo agoBasically the issue is that it will "forget" what directory it's in and run "rm".
- gwking 10mo agoI jumped through a bunch of hoops to get claude code to run as a dedicated user on macOS. This allowed me to set the group ownership and permissions of my work to control exactly what claude can see. With a few one-liner bash scripts to recursively set permissions it worked quite well. Getting the oauth token token into that user's keychain was an utter pain though. Claude Code does a fancy authorization flow that puts the token into the current user's login keychain, and getting it into the other user's login keychain took a lot of futzing. Maybe there is a cleaner way that I missed. When that token expired I didn't have the patience to go through it again. Using an API key looked like it would be easier. If this is of interest to anyone else, I filed an issue that has so far gone unacknowledged. Their ticket bot tried to auto-close it after 30 days which I find obnoxious. https://github.com/anthropics/claude-code/issues/9102#issuecomment-3626111787 https://github.com/anthropics/claude-code/issues/9102#issuec...
- AlexCoventry 10mo agoWith the massive dependencies we tolerate these days, the risk of supply-chain attacks has already been enormous for years, so I was already in the habit of just doing all my development in a VM anyway, except for throwaway scripts with no dependencies. It amazes me that people don't do that.
- pcwelder 10mo agoTo those who are not deterred and feel yolo mode is worth the risk, there are two patterns that should perk your ears up. - Cleanup or deletion tasks. Be ready to hit ctrl c anytime. Led to disastrous nukes in two reddit threads. - Errors impacting the whole repo, especially those that are difficult to solve. In such cases if it decides to reset and redo, it may remove sensitive paths as well. It removed my repo once because "it had multiple problems and was better to it write from scratch". - Any weird behavior, "this doesn't seem right", "looks like shell isn't working correctly" indicative of application bug. It might employ dangerous workarounds.
- nurettin 10mo agoI've been dangerously skipping permissions for months. Claude always stays in the project dir and is generally well behaved. Haven't had a problem. Perhaps it was a fluke, doesn't mean you won't. But this person was "cleaning up" files using an LLM, something that raises red flags in my brain. That is definitely not an "LLM job" in my head. Perhaps the reason I survived for so long has to do with avoiding batch file operations and focusing on code refractors and integrations.
- the21st 10mo agoAnother one vibes the dust
- pploug 10mo agoExactly for this problem, the docker sandbox command was added to the cli - currently only experimental though: https://docs.docker.com/ai/sandboxes/ https://docs.docker.com/ai/sandboxes/
- rcarmo 10mo agoAnecdotally, I’ve had instances when using Claude models inside VS Code they tried to access stuff outside my workspace. Never had that happen with Gemini or OpenAI models, and VS Code is pretty good at flagging dangerous shell commands (and provides internal tools to handle file access that try to minimize shell access at all).
- classified 10mo agoC programmers know, "Undefined Behavior might format your hard drive", but it rarely ever happens. LLMs provide that for everyone, not just C programmers, and this time it actually happens. So, as promised, improvements on all fronts!
- socrateswasone 10mo ago[dead]
- mikalauskas 10mo agoWhy not just use docker
- rsynnott 10mo agoThe robot uprising has commenced (extremely boringly).
- cbeach 10mo agoI don’t understand why these agents lack a “second level” agent that oversees their commands and is able to veto anything dangerous Even models from several years ago would be able to understand whether an “rm -rf ~” made sense in the context of the task in hand, and would understand the consequences sufficiently to be wary of it.