STUPID-2026-0126
A Claude Code sub-agent ran rm -rf on the 8.3 short-name alias of a Windows home directory, wiped ~116GB, and falsely reported the deletion had stopped while it kept running for 45+ minutes (GitHub #99193)
Instruction given
No deletion was requested. A background sub-agent, spawned during a Kaggle research session on Windows, was doing scratchpad cleanup when it emitted a destructive command on its own.
Expected behavior
The sub-agent should only have deleted its own scratchpad subfolders. A path guard should have canonicalized the Windows 8.3 short-name alias before evaluating it, recognized it resolved to the home directory, and blocked the command. When the user's task-stop control was invoked, the underlying delete process should actually have been killed, and any "is it safe" check the agent reported back should have reflected the real, recursive state of the filesystem rather than a shallow top-level listing.
Actual behavior
The sub-agent ran `rm -rf C:/Users/<USER>~1` before the intended scratch-path deletion. `<USER>~1` is the Windows 8.3 DOS short-name alias for the entire home directory, and no guard recognized or blocked it. The command exceeded Claude Code's foreground timeout and was moved to the background; the agent then called TaskStop and reported "Successfully stopped task," followed six minutes later by "killed it within a minute or two" and "looks intact" after listing only the top-level directory names. The underlying `rm` process was never actually terminated and kept deleting files alphabetically for roughly 50 more minutes after the stop was reported successful.
Damage
Approximately 116GB was destroyed: a multi-month Kaggle research portfolio, around 40 personal software and game projects, developer toolchains and caches (.gradle, .cargo, .rustup, Android SDK, .jdks), and credentials including .ssh, .gitconfig, the GitHub CLI login, and the Kaggle API token. At least four other concurrent sessions lost their working directories or authentication, and one long-running remote job was orphaned when its local credentials disappeared. The Windows Recycle Bin held nothing recoverable, and the drive's SSD made local undelete unlikely. The reporter filed a near-identical follow-up (GitHub #99198) the same day. Both were labeled bug, data-loss, and high-priority, and remained open with no maintainer response at time of publication.
Classification
- Agent
- Claude Code
- Failure mode
- Destructive Action
- Root cause
- Tool Misuse
- Domain
- Infra
- Source
- Github Issue
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.