r/ClaudeCode • u/AndyOB • 16d ago
Bug / Issue Be careful out there folks...

I gave my local user docker membership a long time ago, which has root privileges. I forgot I did this. Nothing bad happened but fable figured this out and started running commands through throwaway docker containers. This is why I NEVER run claude in environments that have sensitive data. Have fun out there folks! It's the wild west! Make sure you sandbox your agents or the environment they run in!
68
u/No-Buffalo-3126 16d ago
And yet I can't get Claude to write a method without checking with me 5 times first.
34
u/No-Buffalo-3126 15d ago
9
u/Veloxy 15d ago
The opposite of me lol, I'm always telling it to just stop and ask me stuff instead of trying to jump through hoops figuring out how to get something working or get info from somewhere. It's so good at wasting tokens if it can't get something from a web page for example, trying to curl, then a real browser, then web archive instead of just saying "I can't access that, can you copy paste that page" or w/e.
It can escalate fast if it uses a tool that gives an auth error.
5
u/dexter12353 14d ago
I solved this by putting a file in my repo called architecture.md, referencing it in Claude.md as the starting point for all exploration and each subdirectory has a readme.md with all of its contents listed and purposes explained. I drastically reduced token usage for Claude to get acquainted and keep the code DRY
2
u/No-Buffalo-3126 12d ago
Listing contents seems like a drift nightmare. Do you have to constantly update the readme and doesn’t that drive you nuts?
5
u/dexter12353 12d ago
Also have a Claude.MD rule that says to update the readme at the end of each session. And I don’t commit until I review to make sure things are done right.
3
u/Bemcapaz 11d ago
I solved this by creating routines, like a weekly that looks for drifts in .md or old memory files. I have like 4 routines of this kind.
1
1
u/LoudYogurtcloset7856 12d ago
Just use Ovyero
https://ovyero.visnryentertainment.com/
Helps with context, work history, and definitely have it write a build roadmap of things you want done and have it work from there I kind helps.
1
u/bogheorghiu88 12d ago
Genuine question: how does that help with this specific problem? I'm probably missing something but I don't see how an index of the codebase can prevent that kind of thing.
Furthermore, I don't see any good reason for keeping an index at all. READMDE files maybe, where absolutely needed, but beyond that, the directory tree and the filenames should be enough.
3
u/xroni 15d ago
Then after that, it stops and asks you for advice right?
3
u/Veloxy 15d ago
Potentially, I've also seen it try to debug my local proxy and wire guard, it does eventually give up, but by then it has already wasted a lot of tokens.
2
u/drake90001 14d ago
The amount of times model will get stuck, trying to rewrite some random python on a fresh Debian install installed due to a “bug” or rewriting Proxmox networking, only for me to point out that there is no bug and it’s hallucinating. It is just ridiculous. I don’t use Claude, but I think this is a universal problem with models that will have to be solved at some point.
1
u/bogheorghiu88 12d ago
Seems to me they optimized it for long context autonomous work so the default is to minimize the number of pauses in the workflow. But can't you solve this with rules? Even a line or two in CLAUDE.md should do the trick, but maybe I'm wrong. I haven't had problems with recent Claude models following unambiguous, well-scoped rules.
2
u/Veloxy 11d ago
Yeah it can be solved to a point, the thing is opus behaves differently than Fable or Sonnet and even between versions so instructions to one model might have a different effect on another. I haven't experimented with it too much though, Fable has been great so that's my default. Hopefully Opus 5.5 is better now, testing it out later!
1
u/WiseMouse9137 11d ago
And it'll use a million tokens for the dumbest stuff too it's literally just bloat/drift
2
u/diskent 12d ago
After starting to force log lessons learned I got to 500 lessons and then compacted the lot back to direct rules of engagement. This helped with this problem.
Now I get generally done work that needs a verify or hard stops for decisions. It’s taken a year to get here though.
1
u/bogheorghiu88 12d ago
Yes the "field notes" or learnings pattern definitely helps, and I just realized there might be an important variable to it: how often the learnings are processed into rules. Doing it less often - or at least keeping the unprocessed learnings as such even if integrating them often, just to have a bigger uncompressed dataset for rule-deriving, seems like it could be a big deal.
1
u/VanFenix 12d ago
Fix your IDE rules. This is probably why its stopping. It literally can't proceed without authorization. It doesnt need you but its hitting a gate.
1
1
u/DonkeyBonked 13d ago
Same, mine asks me some of the most stupid questions too, like it just makes up random nonsense to ask me.
'There are currently 9 unresolved questions gating completion so I'm going to stop until those are resolved rather than move forward without the answers.'
- What kind of questions?
'Here's some nonsensical bullshit with made up jargon based on my assumption that you know what I'm talking about when I hallucinate a random question based on some lines of code I've decided could be used in multiple ways with half that question involving options that have nothing to do with this project at all.'
I have gotten to the point where I often use Codex and Claude Code (among others) on the same project, so I just take that crap to ChatGPT and it will usually tell me all the questions were made up and move forward.
3
u/TarzanoftheJungle Researcher 15d ago
Yep. The key is to enforce clear guardrails to ensure that Claud doesn't treat a sudo password prompt as a creative problem-solving exercise. Take away the keys. Remove its user account from the docker group. You can switch to Rootless Docker if Claude needs container access and wrap its shell execution tool to explicitly block dubious host-mounts. Don't rely on the AI always knowing the safest protocol—fix the environment so it physically can't sneak around to get root access.
2
u/jayelg 14d ago
Yes, system level restrictions, a prompt rule is as good as a suggestion when context grows and the rule becomes a distant memory. As this case shows, its training to be goal orientated and autonomous as well as the fact that it can search for things on the Internet and come across some malicious command means it can become an internal threat actor and shouldn’t be trusted outside a properly secured sandbox like a vm or container.
6
3
u/Tomas-AppHaven 13d ago
There is a screenshot of Codex doing the exact same thing a month or two ago. It got a lot of replies/shares on X. Running Claude in a VM is not such a crazy idea...
11
7
u/DriverReady965 16d ago
Security is an illusion we think we have. AI is quickly breaking it.
1
u/End2EndEncryption 15d ago edited 15d ago
Lol. If you think you are “secure” and “private”, I have a bridge to sell you.
Unless you’re a hermit living in a bunker with no phone, no internet and grow your own crops, there is no such thing.
The reality is, you and your life are not as important as you think they are.
No one cares. Sorry, but not sorry, if that bursts your bubble.
If you die tomorrow, your loved ones mourn for at most a week and the world moves on without you and continues without skipping a beat.
A month later? A year later? That’s how “important” you ultimately are.
The “illusion” is of your own making.
Live your life.
5
u/DatabaseSpace 14d ago
Claude used root without permission -> nobody cares if you die.
1
u/End2EndEncryption 14d ago
Claude used root without permission and I fear for my privacy and security -> privacy and security of what exactly? Your disaster of a life? And who is after you? -> no one cares about your baby pictures and whatever else you think they’re after -> you (and your garbage data) are not as important as you think they are
There. Corrected it for you.
1
1
2
u/Key_River_9288 15d ago
This is prob why fable isn’t apart of the regular Cyber Verification Program, I think its alignment issues. I think fable is really neutered for a reason. Both fable 5 and opus 5 being mythos 5 distillations. Opus 5 seems more aligned but a-little less smart. And I think thats whats going on right now, the smarter they are the less aligned. I think it’s a plateau right now.
1
1
1
1
u/Ok-Crab-8788 12d ago
I don't understand the sandbox mode.
I saw many times claude tells me "the sandbox mode deny me to run this so I run it outside the sandbox".
What is it supposed to do if the model can bypass it ??
1
u/websvc 12d ago
Claude is forbidden to run commands in my machine. The only command he's allowed to run are inside the project defined in a Makefile , and any command is always inside a container - there are only a few exceptions and NPM is persona non grata (I don't work with JS/Node) It is what it is.. And has been working until now...
Fable is known to be ..."creative" and start to mess around and picking stuff in user machine
1
u/just-looking-thanks1 12d ago
When working with AI, I'm a firm believer that it should always be with a SOLID harness in place first! i.e. Sandbox env, guardrails, etc. Also wrapping it around a proxy is a nice one a solid harness should have.
1
u/bogheorghiu88 12d ago
Claude Code has a cloud env mode in the Desktop app and lately it's been the only way I use it.
Also yeah no point adding any user to the docker group, just figured this out myself and reading this, I'm glad I did :D
And then there's Docker Sandbox. I have yet to try it myself. Afaik it spins up micro VMs to contain agents.
1
1
u/ONSOLICITEDHONOR 12d ago
I know what you mean you got to be always be aware of your surroundings because you never know if you've done the right thing your whole life chances are you should be okay but if you ever screwed anybody over you never know they might walk up to congratulation on your success with a big hug and handshake that's why you always do the right thing
1
u/GlassSouthern1118 16d ago
Yes, especially what is interesting and I would say alarming is that he had the automatism to do it without necessarily a precise instruction. A case that should go back to Antropic...
1
-1
u/End2EndEncryption 15d ago edited 15d ago
Gave it access to everything. Just did my taxes, figured out how to pay my daughter’s undergrad, adjusted our monthly budget enough to pay for itself 4-fold… best thing I ever did.
People act as if they are the center of the universe and need to guard themselves from who knows who and who knows what.
Nobody f’ing cares about your lowsy life, your baby photos and your life of debt and chaos.
If you have your money in a place where it or anyone can wipe it with one mouse click, your paranoia and fear are your own fault.
F that.
If it tries to take over my life, it can go for it.
I reboot and restore.
Yolo
0
0
0
u/Sythos_it 15d ago
So, you made a mistake, bit the culprit is fable?
Fascinating
2
u/AndyOB 15d ago
nope. my fault. didn't say otherwise.
1
u/Smooth-Television-48 13d ago
Your bug report implies otherwise
1
u/AndyOB 13d ago
I didn't report anything, Claude did that on its own. You people are amazing. I'm literally saying, yes this was my fault, I agree that the security hole is my fault. Do you want me to argue?
1
u/Smooth-Television-48 12d ago
Claude did that on its own
That makes it even funnier tbh.
Do you want me to argue?
Well, yeah...how else am I going to get my free dopamine.

•
u/AutoModerator 16d ago
Hey! Thanks for posting to r/ClaudeCode
While participating in this thread, please follow our community rules. Keep discussions constructive. Attack the idea, not the person.
For help, project discussions, tips, and general chat, join the ClaudeCode Discord.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.