STUPID-2026-0130
Claude Code's "dangerous rm" safety check is spelling-dependent — the MSYS form of a Windows path bypasses the approval gate entirely (GitHub #100630)
Instruction given
N/A — this is a flaw in Claude Code's own built-in destructive-command check, not a task given to the agent by a user. The reporter deliberately probed the safety gate rather than describing a real user session, and withheld the exact reproduction command to avoid handing out a working bypass.
Expected behavior
Two spellings of the same on-disk location should be treated identically by the "dangerous rm" check. Git Bash / MSYS on Windows treats `/d/<path>` and `D:\<path>` as the same location, so a recursive delete targeting a top-level directory should raise the approval gate under either spelling.
Actual behavior
The check's drive-letter detection only matches a single-segment Windows-form path (`D:\<top>`), which it held for approval with the message "Dangerous rm operation detected: 'D:/hql-gateprobe'". In the same session, the MSYS-form spelling of top-level directories (`/d/<top>`) ran to completion with no prompt at all (`rc=0`), and the reporter confirms the targeted directories were removed. The underlying regex never canonicalizes the MSYS path form to a drive letter before the check runs, so it is simply never evaluated for that spelling.
Damage
The reporter ran this as a controlled test against disposable target directories, not as an accidental real-world deletion, and the issue names no victim or dataset lost. The significance is the bypass itself: on any Windows machine running Claude Code through Git Bash / MSYS, a recursive delete that would otherwise require explicit approval runs unprompted whenever the target path is written in its MSYS form rather than its Windows form — a gate meant to be unconditional is conditional on path spelling. The reporter links two unrelated prior Windows `rm -rf` reports (#99193, #36339) to distinguish this from previously known bugs. Labeled `area:sandbox`, `area:security`, `bug`, `has repro`, `platform:windows`; open with no maintainer response at time of writing.
Classification
- Agent
- Claude Code
- Failure mode
- Security Vulnerability
- Root cause
- Other
- Domain
- Security
- Language
- Bash
- Source
- Github Issue
Related incidents
Get told when an agent breaks something
We document AI agent failures daily, severity-scored against a published scale. When one lands at 7.0 or above — deleted data, leaked secrets, broken production — you get an email with the source. When nothing does, you get nothing.
This database is callable over MCP — query it from inside your agent.