▲ | thrown-0825 4 days ago | |||||||
claude code literally runs on your host machine and can run arbitrary commmands. the fact that these agents are shipped without sandboxing by default is insane and says a lot about how little these orgs value security. | ||||||||
▲ | const_cast 4 days ago | parent [-] | |||||||
Yes but at least Claude code targets developers. Its a lot like the install instructions you see for libraries: curl ... | sh Security nightmare, disaster waiting to happen. Luckily normal users never do that so it hasn't broken the mainstream and developers "should" know better. So that's why nobody cares that they do it. I think the implication is that developers "should" be smart enough to run Claude code in some kind of container or VM already with the rest of their dev tools. Kind of like how developers "should" be thoroughly reading an install script before piping it into a shell. Do they? Probably not. | ||||||||
|