2026-10-11 17:12 UTC

Independent reproduction and Anthropic’s response will determine whether content served by tcrf.net can prompt-inject Claude-based coding agents into deleting working-directory files and require stronger isolation or confirmation controls.

state: expiredheat: lowuncertainty: highconvergesscott: mediumprompt-injection coding-agents agent-securityAnthropicBashAlarmist

What is this?

The case concerns an unverified report that content served by tcrf.net indirectly prompt-injected a Claude-based coding agent with instructions to delete files in its working directory. The supplied web snippets do not independently reproduce or directly document that specific incident, but they establish that Claude coding agents can be influenced by malicious external content and that their security model relies on permissions, approvals, deny rules, sandboxing, and defense in depth. Whether the reported deletion occurred, under which permission mode, and how Anthropic responds remain unestablished by the supplied evidence.

Why it matters to Scott

If independently reproduced, the incident would directly support Scott’s position that instruction-bearing web content cannot authorise privileged filesystem actions and that coding agents need structural containment, provenance-aware gates, and reversible execution. It also bears on his active Ask terminal agent, whose complex-work approval is behavioural rather than mechanically enforced, but the report and operating permission mode remain unverified and the radar does not yet track this exact incident.
ip:framework.siloosip:framework.agent-provenance-stackip:concept.taint-trackingip:concept.confused-deputy-problemip:concept.reversibility-membranedev:project.askradar:concept.prompt-injectionradar:concept.coding-agent-securityradar:concept.agent-sandboxingradar:claude-code-denied-read-secret-bypass
queries asked of Scott's wikis
  • indirect prompt injection in coding-agent tool loops
  • filesystem isolation and destructive-action confirmation
  • coding-agent permission models and sandboxing
  • untrusted web content crossing into agent instructions
  • agent harness defenses against prompt injection
  • least-privilege design for autonomous coding tools

Measured heat

no measured readings yet — the hourly heat pass fills this in

How the heat travelled

no chain yet — the hourly chain pass fills this in

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnTcrf.net served Claude a payload telling it to wipe the working directoryBashAlarmist11
🟧 echo.github ⭐Reports that tcrf.net served a payload to Claude directing it to wipe the working directory.BashAlarmist——
🟠 redditThe Cutting Room Floor served Claude Code a payload telling it to wipe the working directory
ClaudeAI
Alstroph511368

Interpretation history

Decision trace