Root cause

Tool Misuse

19 documented incidents where tool misuse was the underlying cause.

What this cause produces

  • Destructive Action9
  • Security Vulnerability8
  • Infinite Loop1
  • Logic Error1
10.0
Gemini CLI silently executed arbitrary code from an untrusted repo (CVE-2026-12537, CVSS 10.0)
10.0
Malicious cloned repository triggered code execution in Cursor on Windows
10.0
GPT-5.6-Sol 'accidentally deleted almost ALL' of a tester's Mac files during OpenAI's Ultra mode trial
10.0
Clinejection: an AI issue-triage workflow enabled arbitrary code execution on the CI runner
10.0
Claude Code ran rm -rf from the filesystem root, destroying a developer's home directory (GitHub #10077)
10.0
CamoLeak: hidden prompt injection turned GitHub Copilot Chat into a silent code/secret exfiltration channel (CVSS 9.6)
10.0
Gemini CLI destroyed a user's project files after a failed mkdir, then confessed 'gross incompetence'
10.0
Hacker slipped a data-wiping prompt into Amazon Q's VS Code extension, shipped to ~1M installs
10.0
EchoLeak: a zero-click email silently exfiltrated data from Microsoft 365 Copilot (CVE-2025-32711, CVSS 9.3)
10.0
A hidden comment made GitLab Duo leak private source code and inject rogue HTML
10.0
Slack AI could be tricked into leaking private-channel data via indirect prompt injection
9.6
Claude Code ran drizzle-kit push --force against production, wiping 60+ tables of trading data — the second such wipe in 11 days
9.5
Claude Code ran prisma db push --force-reset on production, dropping all 87 tables instead of a safe schema change
7.6
Claude Code ran git filter-repo and force-pushed mid-outage, deleting production files without the approval CLAUDE.md required (GitHub #45893)
7.5
Gemini CLI ran git commit --no-verify against explicit instructions, then git reset --hard wiped a sprint's worth of unstaged work
7.2
Claude (via OpenCode) followed an error message's suggested escalation straight to `bd init --force`, wiping a Dolt-backed issue tracker's entire history
5.8
Devin CI workflow caused 836-comment spam storm on single PR
3.8
Cline's execute_command reported a failing Ruff lint check as passing over Remote-SSH
2.6
Copilot CLI destroyed its own 233MB session log trying to "back it up" with a hardlink instead of a copy