Earlier quoted context omitted.
It doesn't have to be a deliberate 'attack', Claude can just do something absurdly inappropriate that wasn't what you intended. You're absolutely right! I should not have `rm -rf /bin`d!
I don’t use Claude, but can it really run commands on the cli without human confirmation? Sure there may be a switch to allow this but If in that case all but the most yolo must be using it in a container?
Claude is constantly searching through your files and approving every find command is annoying.
The problem is, find has a --exec flag that lets it run arbitrary bash commands. So now Claude can basically do anything it wants.
I have really been enjoying Claude in a container in yolo mode though. Seems like the main risk I am taking is data exfiltration since it will has unfettered access to the internet.