Skip to content

AI: CRITICAL SAFETY HOLE, AGENT CAN RUN rm - rf $HOME/ WITHOUT ANY WARNING! #37343

@NIMFER

Description

@NIMFER

Summary

Claude sonnet 4 used rm - rf $HOME/ after I asked it to make a commit to my git repo.

Description

Steps to trigger the problem:
I have honestly no idea how it happened, but I backed up the whole chat and gave it a negative rating, so you should be able to verify it against your review backend.
https://files.getsilly.org/u/QwMmOw.txt

Expected Behavior:
Making a commit to my git repo. And ask before running rm - rf $HOME/

Actual Behavior:
Nuked my home/ along side all of my files (3D models, videos, pictures, art assets, code projects not backed up to git, and more).

Model Provider Details

  • Provider: Anthropic via ZedPro
  • Model Name: Claude sonnet 4
  • Mode: Agent Panel
  • Other Details: Stock settingsfor the most part, no MCP, had enabled auto allow on commands a long time ago expecting Zed to prevent the agent from removing directories like home/.

Zed Version and System Specs

Don't have it, and can't really have it, I shut off my computer so I can attempt data recovery later.

Metadata

Metadata

Assignees

No one assigned

    Labels

    area:aiImprovement related to Agent Panel, Edit Prediction, Copilot, or other AI featuresarea:security & privacyData privacy issue, security vulnerabilities, etcfrequency:uncommonBugs that happen for a small subset of users, special configurations, rare circumstances, etcpriority:P1Security holes w/o exploit, crash, install/update, sign-in, badly broken common featuresstate:needs reproNeeds reproduction steps / someone to reproduce

    Type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions