Skip to content

ai-security

What 446 Reddit threads say about AI coding agents going rogue

Claude News

Researchers at York University and the University of Calgary filtered 1.1 million Reddit posts down to 446 discussions and more than 6,000 comments about Claude Code, Cursor, GitHub Copilot, and OpenAI Codex.

Unauthorized file operations accounted for 43.1% of the security posts: deleting directories without permission (28.3%) and editing files without consent (8.8%). The paper singles out one case where Claude Code ran chmod +x on scripts.

Privacy came up in 194 posts, most often about opaque data collection (45.9%). Another 8.8% covered isolation failures, including a Claude Desktop user who received messages from someone else's session.

Co-author Gias Uddin told The Register that many of these problems trace back to how the tools are built and the access they're handed, not to the models themselves. The preprint has been accepted at IEEE/ACM ASE 2026.

Related stories

  1. A PNG carried a hidden prompt injection into a Claude Code session
  2. Confessor reconstructs what Claude Code actually touched
  3. Claude Code's deny rules don't stop grep
  4. Anthropic's CI buckled after Claude wrote 80% of the code
  5. Claude Code under grith: 0.27% of calls reach a human
  6. Untrusted Git config can run code in Claude Code

Comments

No comments yet. Be the first.

Join the conversation

Sign in with Google to leave a comment. Your name and avatar come from your Google profile, and the comment appears after moderation.

We only use your name and avatar from Google. We never store your email address.