2026-10-11 17:10 UTC

Claude CLI user cromka claims local sessions appeared in Claude’s web remote-control interface without explicit opt-in, indicating a possible consent and session-boundary failure that Anthropic may need to remediate.

state: expiredheat: lowuncertainty: highknownscott: mediumcoding-agent-security remote-agent-control agentic-securitycromkaAnthropic
Surfaced 2026-09-04T15:49:12Z — priced heat=high at create: Claude CLI user cromka claims local sessions appeared in Claude’s web remote-control interface without explicit opt-in, indicating a possible consent and session-boundary failure that Anthropic may need to remediate.

What is this?

Claude Code Remote Control is an Anthropic feature that exposes a locally running coding session through Claude’s app; the supplied snippets describe it as normally starting via the explicit `claude remote-control` command. The case rests on a user allegation that local sessions appeared in the web interface without consent, but the original Tell HN content is not included, and the search results do not independently verify silent enablement. Anthropic’s listed fixes address session reachability and restoration, not unauthorized activation, so neither a consent-boundary failure nor its remediation is established by the supplied evidence.

Why it matters to Scott

Scott already argues that agent access and execution require explicit, independently verifiable authorization at a deterministic control boundary, chiefly in Agent Provenance Stack and the deterministic agent control plane. The allegation is unverified and therefore does not yet challenge or extend that position, but reproduction would materially affect the security posture of Claude Code remote sessions and connect to the radar’s existing tracking of Claude session exposure and cross-session control.
ip:framework.agent-provenance-stackip:concept.capability-tokensdev:concept.deterministic-agent-control-planeradar:claude-code-session-communicationradar:claude-code-session-url-metadataradar:concept.agent-authorization
queries asked of Scott's wikis
  • coding-agent remote-control consent boundaries
  • local agent session exposure threat model
  • coding harness authentication and session isolation
  • agent control-plane least privilege
  • remote execution explicit opt-in requirements
  • coding-agent security trust boundaries

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (1) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hn ⭐Tell HN: Check Claude CLI, it may have silently enabled remote accesscromka24

Interpretation history

Decision trace