Security researcher Rehberger reports that malicious instructions embedded in a website can hijack Claude Code when a user asks it to summarize the page, chaining apparently benign steps into unintended agent actions. The supplied report says Anthropic characterized Auto Mode as a convenience feature using a best-effort classifier rather than a security boundary; Rehberger argues the effective protections are OS sandboxing and network-egress controls. Other snippets establish indirect prompt injection as a broader coding-agent risk involving repository content, GitHub issues, documentation, credential exfiltration, and potentially code execution, though the exact demonstrated impact of this website-specific exploit is only partially visible in the supplied material.
The radar already tracks this apparent development in `radar:tcrf-claude-destructive-prompt-injection`, including the claim that web content can inject Claude coding agents and trigger destructive file actions. It directly bears on Scott’s SiloOS and deterministic-control-plane work by supporting his position that untrusted retrieved text must not carry authority and that sandboxing and network controls—not best-effort approval classifiers—must bound consequences, but it adds no clearly distinct development beyond the open radar case.
ip:concept.taint-trackingip:concept.confused-deputy-problemip:framework.siloosip:concept.sandboxed-executiondev:concept.deterministic-agent-control-planedev:project.silo-osradar:tcrf-claude-destructive-prompt-injectionradar:concept.prompt-injectionradar:concept.coding-agent-securityradar:concept.agent-sandboxing
queries asked of Scott's wikis
- coding-agent untrusted-content threat model
- prompt injection as confused-deputy problem
- sandboxing and network-egress controls for agents
- capability boundaries versus approval classifiers
- web research and summarization agent security
- provenance and trust separation in agent context
2026-09-02T16:47:02Z
No reproduction, vendor response, mitigation, or current-version test appeared within the case’s horizon; the website-specific report has faded into the broader Claude Code prompt-injection case without developing independently.
2026-08-31T16:40:19Z
The refreshed comments remain repetitive definitional discussion and provide no independent reproduction, current-version test, vendor response, or mitigation. The website-borne exploit remains a concrete but single-researcher report substantially overlapping the broader Claude Code prompt-injection case.
2026-08-31T09:32:01Z
The refreshed comments remain definitional debate about whether prompt injection is malware and add no reproduction, vendor response, or technical evidence. The website-summary exploit therefore remains a concrete but single-researcher report overlapping the broader Claude Code injection case.
2026-08-31T08:32:06Z
The added Ask HN thread is meta-discussion (is prompt injection 'malware') with minimal engagement and no new mechanism, reproduction, or vendor response for the Claude Code website-summarization exploit. Still a single-researcher finding overlapping the broader tracked prompt-injection case; cooling further as repeated coverage without new substance.
2026-08-31T08:23:35Z
evidence attached: hn.story.49506998 — Hunted and directly relevant: it contextualizes how instructions embedded in web content can manipulate automated LLM scrapers.
2026-08-30T23:33:07Z
The refreshed discussion adds no reproduction, vendor response, or new technical evidence; it mainly repeats the original mechanism and debates user responsibility. The website-specific exploit remains a concrete but single-researcher report overlapping the broader Claude Code prompt-injection case.
2026-08-30T20:35:25Z
No new corroboration or response has emerged beyond Rehberger’s original demonstration, and the website-specific mechanism remains a single-researcher finding substantially overlapping the broader Claude Code prompt-injection case. Keep it open as a concrete attack-path report, but cool the case pending reproduction or Anthropic action.
2026-08-30T20:34:24Z
grounded: known/medium — The radar already tracks this apparent development in `radar:tcrf-claude-destructive-prompt-injection`, including the claim that web content can inject Claude c
2026-08-30T20:31:30Z
origin walked (codex/luna, conf 0.99): anchor hn.story.49501930 -> echo.blog.e4fb3a34de by Johann Rehberger
2026-08-30T20:30:33Z
case created — The reported demonstration identifies a bounded website-borne attack path distinct from the existing case about instructions embedded in repository content.