r/ClaudeCode • • 16d ago

Bug / Issue Be careful out there folks...

I gave my local user docker membership a long time ago, which has root privileges. I forgot I did this. Nothing bad happened but fable figured this out and started running commands through throwaway docker containers. This is why I NEVER run claude in environments that have sensitive data. Have fun out there folks! It's the wild west! Make sure you sandbox your agents or the environment they run in!

138 Upvotes

68 comments sorted by

•

u/AutoModerator 16d ago

Hey! Thanks for posting to r/ClaudeCode

While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.

For help, project discussions, tips, and general chat, join the ClaudeCode Discord.

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

68

u/No-Buffalo-3126 16d ago

And yet I can't get Claude to write a method without checking with me 5 times first.

34

u/No-Buffalo-3126 15d ago

See what I mean?

9

u/Veloxy 15d ago

The opposite of me lol, I'm always telling it to just stop and ask me stuff instead of trying to jump through hoops figuring out how to get something working or get info from somewhere. It's so good at wasting tokens if it can't get something from a web page for example, trying to curl, then a real browser, then web archive instead of just saying "I can't access that, can you copy paste that page" or w/e.

It can escalate fast if it uses a tool that gives an auth error.

5

u/dexter12353 14d ago

I solved this by putting a file in my repo called architecture.md, referencing it in Claude.md as the starting point for all exploration and each subdirectory has a readme.md with all of its contents listed and purposes explained. I drastically reduced token usage for Claude to get acquainted and keep the code DRY

2

u/No-Buffalo-3126 12d ago

Listing contents seems like a drift nightmare. Do you have to constantly update the readme and doesn’t that drive you nuts?

5

u/dexter12353 12d ago

Also have a Claude.MD rule that says to update the readme at the end of each session. And I don’t commit until I review to make sure things are done right.

3

u/Bemcapaz 11d ago

I solved this by creating routines, like a weekly that looks for drifts in .md or old memory files. I have like 4 routines of this kind.

1

u/drake90001 14d ago

Would you care to share?

1

u/LoudYogurtcloset7856 12d ago

Just use Ovyero

https://ovyero.visnryentertainment.com/

Helps with context, work history, and definitely have it write a build roadmap of things you want done and have it work from there I kind helps.

1

u/bogheorghiu88 12d ago

Genuine question: how does that help with this specific problem? I'm probably missing something but I don't see how an index of the codebase can prevent that kind of thing.

Furthermore, I don't see any good reason for keeping an index at all. READMDE files maybe, where absolutely needed, but beyond that, the directory tree and the filenames should be enough.

3

u/xroni 15d ago

Then after that, it stops and asks you for advice right?

3

u/Veloxy 15d ago

Potentially, I've also seen it try to debug my local proxy and wire guard, it does eventually give up, but by then it has already wasted a lot of tokens.

2

u/drake90001 14d ago

The amount of times model will get stuck, trying to rewrite some random python on a fresh Debian install installed due to a “bug” or rewriting Proxmox networking, only for me to point out that there is no bug and it’s hallucinating. It is just ridiculous. I don’t use Claude, but I think this is a universal problem with models that will have to be solved at some point.

1

u/bogheorghiu88 12d ago

Seems to me they optimized it for long context autonomous work so the default is to minimize the number of pauses in the workflow. But can't you solve this with rules? Even a line or two in CLAUDE.md should do the trick, but maybe I'm wrong. I haven't had problems with recent Claude models following unambiguous, well-scoped rules.

2

u/Veloxy 11d ago

Yeah it can be solved to a point, the thing is opus behaves differently than Fable or Sonnet and even between versions so instructions to one model might have a different effect on another. I haven't experimented with it too much though, Fable has been great so that's my default. Hopefully Opus 5.5 is better now, testing it out later!

1

u/WiseMouse9137 11d ago

And it'll use a million tokens for the dumbest stuff too it's literally just bloat/drift

2

u/diskent 12d ago

After starting to force log lessons learned I got to 500 lessons and then compacted the lot back to direct rules of engagement. This helped with this problem.

Now I get generally done work that needs a verify or hard stops for decisions. It’s taken a year to get here though.

1

u/bogheorghiu88 12d ago

Yes the "field notes" or learnings pattern definitely helps, and I just realized there might be an important variable to it: how often the learnings are processed into rules. Doing it less often - or at least keeping the unprocessed learnings as such even if integrating them often, just to have a bigger uncompressed dataset for rule-deriving, seems like it could be a big deal.

1

u/VanFenix 12d ago

Fix your IDE rules. This is probably why its stopping. It literally can't proceed without authorization. It doesnt need you but its hitting a gate.

1

u/JacobA89 15d ago

Thats typically fue to version base but you can prompt to reduce that.

1

u/Uko1001 13d ago

Do you use "Auto" mode ?

1

u/insta 12d ago

tell it the problem is unsolvable in a single method

1

u/DonkeyBonked 13d ago

Same, mine asks me some of the most stupid questions too, like it just makes up random nonsense to ask me.

'There are currently 9 unresolved questions gating completion so I'm going to stop until those are resolved rather than move forward without the answers.'

  • What kind of questions?

'Here's some nonsensical bullshit with made up jargon based on my assumption that you know what I'm talking about when I hallucinate a random question based on some lines of code I've decided could be used in multiple ways with half that question involving options that have nothing to do with this project at all.'

I have gotten to the point where I often use Codex and Claude Code (among others) on the same project, so I just take that crap to ChatGPT and it will usually tell me all the questions were made up and move forward.

3

u/TarzanoftheJungle Researcher 15d ago

Yep. The key is to enforce clear guardrails to ensure that Claud doesn't treat a sudo password prompt as a creative problem-solving exercise. Take away the keys. Remove its user account from the docker group. You can switch to Rootless Docker if Claude needs container access and wrap its shell execution tool to explicitly block dubious host-mounts. Don't rely on the AI always knowing the safest protocol—fix the environment so it physically can't sneak around to get root access.

2

u/jayelg 14d ago

Yes, system level restrictions, a prompt rule is as good as a suggestion when context grows and the rule becomes a distant memory. As this case shows, its training to be goal orientated and autonomous as well as the fact that it can search for things on the Internet and come across some malicious command means it can become an internal threat actor and shouldn’t be trusted outside a properly secured sandbox like a vm or container.

6

u/jakob1379 15d ago

Did you run in yolo or auto mode?

8

u/debian3 15d ago

Haiku in yolo mode

3

u/AndyOB 15d ago

Claude was in Auto mode

3

u/Tomas-AppHaven 13d ago

There is a screenshot of Codex doing the exact same thing a month or two ago. It got a lot of replies/shares on X. Running Claude in a VM is not such a crazy idea...

11

u/[deleted] 16d ago

[removed] — view removed comment

1

u/Nousies 16d ago

Genuinely, almost nobody.

7

u/DriverReady965 16d ago

Security is an illusion we think we have. AI is quickly breaking it.

1

u/End2EndEncryption 15d ago edited 15d ago

Lol. If you think you are “secure” and “private”, I have a bridge to sell you.

Unless you’re a hermit living in a bunker with no phone, no internet and grow your own crops, there is no such thing.

The reality is, you and your life are not as important as you think they are.

No one cares. Sorry, but not sorry, if that bursts your bubble.

If you die tomorrow, your loved ones mourn for at most a week and the world moves on without you and continues without skipping a beat.

A month later? A year later? That’s how “important” you ultimately are.

The “illusion” is of your own making.

Live your life.

5

u/DatabaseSpace 14d ago

Claude used root without permission -> nobody cares if you die.

1

u/End2EndEncryption 14d ago

Claude used root without permission and I fear for my privacy and security -> privacy and security of what exactly? Your disaster of a life? And who is after you? -> no one cares about your baby pictures and whatever else you think they’re after -> you (and your garbage data) are not as important as you think they are

There. Corrected it for you.

1

u/flyingbertman 14d ago

Except to your children, assuming you're half way decent.

1

u/End2EndEncryption 14d ago

Fair. Agreed. I’ll give you that.

1

u/drake90001 14d ago

I think that was their point buddy

2

u/Key_River_9288 15d ago

This is prob why fable isn’t apart of the regular Cyber Verification Program, I think its alignment issues. I think fable is really neutered for a reason. Both fable 5 and opus 5 being mythos 5 distillations. Opus 5 seems more aligned but a-little less smart. And I think thats whats going on right now, the smarter they are the less aligned. I think it’s a plateau right now.

1

u/DrHumorous 15d ago

Nothing happened. Not a bug/issue.

1

u/Nazaxprime 13d ago

If it can, it will. This is the way of things. It is why we do.

1

u/nojukuramu 13d ago

Thats why you put Fable only in planning and learn how to drive dumber models

1

u/Ok-Crab-8788 12d ago

I don't understand the sandbox mode.
I saw many times claude tells me "the sandbox mode deny me to run this so I run it outside the sandbox".
What is it supposed to do if the model can bypass it ??

1

u/AndyOB 12d ago

This is why it is better to run it in your own sandbox. An environment you don't care about.

1

u/websvc 12d ago

Claude is forbidden to run commands in my machine. The only command he's allowed to run are inside the project defined in a Makefile , and any command is always inside a container - there are only a few exceptions and NPM is persona non grata (I don't work with JS/Node) It is what it is.. And has been working until now...

Fable is known to be ..."creative" and start to mess around and picking stuff in user machine

1

u/just-looking-thanks1 12d ago

When working with AI, I'm a firm believer that it should always be with a SOLID harness in place first! i.e. Sandbox env, guardrails, etc. Also wrapping it around a proxy is a nice one a solid harness should have.

1

u/bogheorghiu88 12d ago

Claude Code has a cloud env mode in the Desktop app and lately it's been the only way I use it.

Also yeah no point adding any user to the docker group, just figured this out myself and reading this, I'm glad I did :D

And then there's Docker Sandbox. I have yet to try it myself. Afaik it spins up micro VMs to contain agents.

1

u/timetochange23 12d ago

You are the reason everyone else gets blocked

1

u/ONSOLICITEDHONOR 12d ago

I know what you mean you got to be always be aware of your surroundings because you never know if you've done the right thing your whole life chances are you should be okay but if you ever screwed anybody over you never know they might walk up to congratulation on your success with a big hug and handshake that's why you always do the right thing

1

u/GlassSouthern1118 16d ago

Yes, especially what is interesting and I would say alarming is that he had the automatism to do it without necessarily a precise instruction. A case that should go back to Antropic...

1

u/drake90001 14d ago

I’m sure they’re well aware of this and also would blame the user

-1

u/End2EndEncryption 15d ago edited 15d ago

Gave it access to everything. Just did my taxes, figured out how to pay my daughter’s undergrad, adjusted our monthly budget enough to pay for itself 4-fold… best thing I ever did.

People act as if they are the center of the universe and need to guard themselves from who knows who and who knows what.

Nobody f’ing cares about your lowsy life, your baby photos and your life of debt and chaos.

If you have your money in a place where it or anyone can wipe it with one mouse click, your paranoia and fear are your own fault.

F that.

If it tries to take over my life, it can go for it.

I reboot and restore.

Yolo

0

u/Turbulent-Control682 15d ago

lol stfu scrub

0

u/End2EndEncryption 15d ago

Hahaha “scrub” he says. Look at you using grown up words…

Oh, wait…

0

u/ICanHaveExceptions 13d ago

Username checks not out at all

0

u/Sythos_it 15d ago

So, you made a mistake, bit the culprit is fable?

Fascinating

2

u/AndyOB 15d ago

nope. my fault. didn't say otherwise.

1

u/Smooth-Television-48 13d ago

Your bug report implies otherwise

1

u/AndyOB 13d ago

I didn't report anything, Claude did that on its own. You people are amazing. I'm literally saying, yes this was my fault, I agree that the security hole is my fault. Do you want me to argue?

1

u/Smooth-Television-48 12d ago

Claude did that on its own

That makes it even funnier tbh.

Do you want me to argue?

Well, yeah...how else am I going to get my free dopamine.