▲ | CER10TY 6 days ago | |||||||
Personally, I'd expect Claude Code not to have such far-reaching access across my filesystem if it only asks me for permission to work and run things within a given project. | ||||||||
▲ | zingababba 5 days ago | parent | next [-] | |||||||
Apparently they were using --dangerously-skip-permissions, --yolo, --trust-all-tools etc. The Wiz post has some more details - https://www.wiz.io/blog/s1ngularity-supply-chain-attack | ||||||||
| ||||||||
▲ | echelon 5 days ago | parent | prev [-] | |||||||
This confusion is even more call for a response from these companies. I don't understand why HN is trying to laugh at this security and simultaneously flag the call for action. This is counterproductive. | ||||||||
|