Claude CLI user cromka claims local sessions appeared in Claude’s web remote-control interface without explicit opt-in, indicating a possible consent and session-boundary failure that Anthropic may need to remediate.
state: expiredheat: lowuncertainty: highknownscott: mediumcoding-agent-security remote-agent-control agentic-securitycromkaAnthropic
Surfaced 2026-09-04T15:49:12Z — priced heat=high at create: Claude CLI user cromka claims local sessions appeared in Claude’s web remote-control interface without explicit opt-in, indicating a possible consent and session-boundary failure that Anthropic may need to remediate.
What is this?
Claude Code Remote Control is an Anthropic feature that exposes a locally running coding session through Claude’s app; the supplied snippets describe it as normally starting via the explicit `claude remote-control` command. The case rests on a user allegation that local sessions appeared in the web interface without consent, but the original Tell HN content is not included, and the search results do not independently verify silent enablement. Anthropic’s listed fixes address session reachability and restoration, not unauthorized activation, so neither a consent-boundary failure nor its remediation is established by the supplied evidence.
Why it matters to Scott
Scott already argues that agent access and execution require explicit, independently verifiable authorization at a deterministic control boundary, chiefly in Agent Provenance Stack and the deterministic agent control plane. The allegation is unverified and therefore does not yet challenge or extend that position, but reproduction would materially affect the security posture of Claude Code remote sessions and connect to the radar’s existing tracking of Claude session exposure and cross-session control.
ip:framework.agent-provenance-stackip:concept.capability-tokensdev:concept.deterministic-agent-control-planeradar:claude-code-session-communicationradar:claude-code-session-url-metadataradar:concept.agent-authorization
queries asked of Scott's wikis
- coding-agent remote-control consent boundaries
- local agent session exposure threat model
- coding harness authentication and session isolation
- agent control-plane least privilege
- remote execution explicit opt-in requirements
- coding-agent security trust boundaries
Measured heat
no measured readings yet — the hourly heat pass fills this in
How the heat travelled
no chain yet — the hourly chain pass fills this in
Evidence (1) — ⭐ canonical anchor
Interpretation history
2026-09-06T18:28:03Z
The monitoring window has passed without an independent reproduction, inspectable session record, or vendor clarification; the supplied report establishes claimed web visibility, not unauthorized remote control. Archive as an unresolved allegation rather than a disproved incident, reopening on concrete evidence of consent bypass.
2026-09-04T17:31:12Z
The refreshed comments add troubleshooting and configuration context but no independent reproduction, session logs, or Anthropic response. The consent-boundary allegation remains a single-user report, so its urgency cools after the initial warning while near-term monitoring remains warranted.
2026-09-04T15:52:51Z
The added comments provide no inspectable corroboration, reproduction, or vendor response, so the consent-boundary allegation remains a single-user report. The potentially active remote-access risk still warrants near-term monitoring, but this reobservation does not strengthen the case.
2026-09-04T15:34:43Z
grounded: known/medium — Scott already argues that agent access and execution require explicit, independently verifiable authorization at a deterministic control boundary, chiefly in Ag
2026-09-04T15:31:00Z
case created — The report alleges unexpected remote visibility and control of live coding-agent sessions, warranting rapid corroboration or vendor clarification.
Decision trace
- 09-07 04:28expireThe monitoring window has passed without an independent reproduction, inspectable session record, or vendor clarification; the supplied report establishes claimed web visibility, not unauthorized remo
- 09-07 04:28alert_silentThe original concern was already surfaced, and this refresh contains no new evidence or protective action. No confirming event is specifically expected within six hours to justify a hold.
- 09-07 04:28alert_routeThe original concern was already surfaced, and this refresh contains no new evidence or protective action. No confirming event is specifically expected within six hours to justify a hold.
- 09-05 03:31repriceThe refreshed comments add troubleshooting and configuration context but no independent reproduction, session logs, or Anthropic response. The consent-boundary allegation remains a single-user report,
- 09-05 03:31alert_silentThe underlying risk was already surfaced, and the new comments neither corroborate unauthorized activation nor establish a new protective action; this can wait for a reproduction, inspectable session
- 09-05 03:31alert_routeThe underlying risk was already surfaced, and the new comments neither corroborate unauthorized activation nor establish a new protective action; this can wait for a reproduction, inspectable session
- 09-05 03:22sensor_dirtycomment_update
- 09-05 01:52repriceThe added comments provide no inspectable corroboration, reproduction, or vendor response, so the consent-boundary allegation remains a single-user report. The potentially active remote-access risk st
- 09-05 01:52alert_silentThe original risk and protective check were already surfaced; a comment-count increase without comment content or new evidence is not a consequential delta and can wait for corroboration.
- 09-05 01:52alert_routeThe original risk and protective check were already surfaced; a comment-count increase without comment content or new evidence is not a consequential delta and can wait for corroboration.
- 09-05 01:49pushpriced heat=high at create: Claude CLI user cromka claims local sessions appeared in Claude’s web remote-control interface without explicit opt-in, indicating a possible consent and session-boundary f
- 09-05 01:49alert_routepriced heat=high at create: Claude CLI user cromka claims local sessions appeared in Claude’s web remote-control interface without explicit opt-in, indicating a possible consent and session-boundary f
- 09-05 01:49alert_shadowAnthropic’s cited release note establishes that declining or dismissing the Remote Control prompt could cause a later request to connect without asking. A user now reports finding local sessions in th
- 09-05 01:49alert_routeAnthropic’s cited release note establishes that declining or dismissing the Remote Control prompt could cause a later request to connect without asking. A user now reports finding local sessions in th
- 09-05 01:34groundScott already argues that agent access and execution require explicit, independently verifiable authorization at a deterministic control boundary, chiefly in Agent Provenance Stack and the determinist
- 09-05 01:31createThe report alleges unexpected remote visibility and control of live coding-agent sessions, warranting rapid corroboration or vendor clarification.